Security monitoring

Galdorf

Well-Known Member
Reaction score
502
Location
Ontario, Canada
I have a centos web server running centos 6.7 ,ispconfig,apache, fail2ban is there some software that i can use to watch failed logins real time from any port ftp,mail,ssh ect.
I would like to have all logs in one place it is a pain having to go through all logs in different programs.
Nagios looks interesting but is there a module that tracks failed logins?.
 
Last edited:
After weeks of scouring the web i finally found what i was looking for you would think it would be more common.
http://resources.infosecinstitute.com/web-server-security-2/
Atomic Secured Linux looks interesting exactly what i was looking for anyone know of any others?.

Seems hackers really want to get into my web server somehow they caused fail2ban to crash multiple times caught them trying to brute force but they never got in due to very long secure passwords.
SSH is locked to one ip that is internal only, no root access also keep a watch on any file changes or suspicious traffic so far nothing.
Trying to find a list of proxies to lock out because that is what hackers really use also i have changed the location of the admin panel for wordpress quite some time goes by before they scan for the url and try again going to set it for internal ip access only since i never bother accessing external.
 
Last edited:
I finally found a firewall that has everything needed to secure a server CSF
Makes locking down a server a breeze it is much better than plain iptables or bastille.
 
You can pay configserver team to install CSF, LFD, mailscanner, some other crap... I think its like $100. Well, well worth it if you have clients on your own VPS. I have a VPS with WHM and had the configserver team set it up and optimize... it's a great suite of tools. That combined with the pro support from StableHost who provides the VPS... and I don't have to worry about my own short comings!
 
Back
Top