/srv/irclogs.ubuntu.com/2022/08/03/#ubuntu-server.txt

Blohshoerheks, Hi there, PSAD is for incoming but we got issue of outgoing port scans problem10:40
lotuspsychjeBlohsh: mayve scan your whole system with lynis, see if you can find any troubles from inside10:42
lotuspsychje!info lynis10:42
ubottulynis (3.0.7-1, jammy): security auditing tool for Unix based systems. In component universe, is optional. Built by lynis. Size 222 kB / 1,612 kB10:42
Blohshlotuspsychje, users abuse port 80 and 443, blocking it is making things worse like wget, ping and api not working. 10:47
Blohshhttps://i.imgur.com/DpAdQMF.png10:48
tewardBlohsh: this is where you start auditing what processes are running, lock down access to the server, and run things like lynis to identify irregularities.  and consider nuking and rebuilding from scratch.13:39
lotuspsychje+1 teward 14:07
Blohshteward, it is a dedicated server used for providing nat vps14:09
tewardand?14:10
Blohsh"nuking and rebuilding"14:10
Blohshwill remove all servers?14:10
tewardso your system runs many VPSes is what you are saying and they are nat'd through this box?14:11
Blohshyup14:11
tewardthen its time for you as an MSP (managed service provider) to audit all then VPSes and ID which one is doing the port scanning and terminate the services for ToS violation14:12
tewardthe same investigative process applies regardless of the server use case14:12
Blohshthat is the problem we are unable to identify which user is doing that.14:12
tewardso its time to start logging network traffic14:13
tewardand then id trends that correspond to the abuse reports14:13
tewardif no users trigger any notices and lynis on the host reports nothing unusual then you have a larger problem on your hands14:14
tewardone that this channel wont be able to help solve14:14
tewardthe problem of network auditing is NOT a new one.  and things like ptrg and such *can* be set on the internal network to detect scans - incoming to host gateway port before being nat'd out is an 'incoming' sca 14:15
tewardpsad* too14:15
teward*yawns, then seeks coffee*14:15
Blohshteward, psad is for incoming not outgoing14:16
Blohshthe problem i have is of outgoing14:17
tewardincoming and outgoing is relative14:17
tewardto the directionality of the network port14:17
Blohshoutgoing makes server locked14:17
tewardi need coffee if i am going to continue this conversation back in a few14:18
Blohshteward, https://i.imgur.com/DpAdQMF.png14:19
tewardBlohsh: start then by explaining the networn setup on $HOST.  Are your VPSes directly bridged to the internet uplink or do they have separate private IP mappings internally?14:21
tewardBlohsh: i dont care for hetzners logs right noe14:21
tewardheads up i do network security for a living so this kind of thing is something i encounter regularly and havr advanced experience on so unless i ask for hetzners logs which you already posted previously i dont need them14:22
ahasenackrbasak: I'm doing an nfs-utils SRU for another bug, and was wondering if I should include this fix with it: https://bugs.launchpad.net/ubuntu/+source/nfs-utils/+bug/198009514:37
ubottuLaunchpad bug 1980095 in nfs-utils (Ubuntu) "libnfsidmap built without hardening flags" [Undecided, Fix Released]14:37
ahasenackwdyt?14:37
ahasenackI'll also ask security, but they will probably say "yes" :)14:38
tewardBlohsh: also keep in mind I do MSP stuff as well - I run servers for clients on VMs with mappings for /28s inbound and outbound - I have one public IP assigned to each internal system when it goes out the door, dedicated for those specific VMs.  Along with network traffic logs, I can ID what a system is doing and isn't doing at a glance.  If your system has only one IP and numerous internal IPs then I don't know how you're doing VPS.14:43
tewardBlohsh: if you're doing multiple public IPs to multiple VPSes internally then you should ideally have a 1:1 mapping of public IP to VPS14:43
tewardand that's how you ID traffic behavior for a specific user14:44
tewardif you're not doing that you need to adapt and configure your system accordingly - and `psad` is for 'incoming' scans, but if the VPSes have to talk to the Gateway (your main server first) before going out the door then you configure the iptables, etc. logs properly so that traffic from the *internal* interface at your gateway gets pointed at psad, and then psad sees 'incoming' traffic on that port and then can ID scans.14:44
rbasakahasenack: remind me which bug you were talking about updating the apparmor profile for please? Because bug 1703821 is in the queue for Bionic.16:38
ubottuBug 1703821 in apparmor (Ubuntu Bionic) "Dovecot and Apparmor complains at operation file_inherit" [Undecided, New] https://launchpad.net/bugs/170382116:38
ahasenackrbasak: that's not the one we were talking about16:40
ahasenackah, you mean to add the fix to this one16:40
rbasakWas your case for Bionic?16:40
ahasenackchecking16:41
ahasenackrbasak: no, jammy: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/197987916:41
ubottuLaunchpad bug 1979879 in samba (Ubuntu Jammy) "Apparmor profile in 22.04 jammy - fails to start when printing enabled" [Undecided, Triaged]16:41
rbasakOK so no benefit in merging them.16:41
ahasenackand jammy only, yeah16:41
rbasakThis one's in complain mode only AIUI16:43
ahasenackthe one I linked? Yes, after you install apparmor-profiles, you get samba in complain mode, so no failures, just log noise16:45
rbasakThis one too I think. I've asked for further justification in the log.16:49
rbasakin the bug16:49
=== nuccitheboss1 is now known as nuccitheboss

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!