<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #856: Blocked IP?</title>
    <link>http://localhost:8080/trac/ticket/856</link>
    <description>&lt;p&gt;
Hi Chris
&lt;/p&gt;
&lt;p&gt;
I was trying to SSH into the site and got my password wrong a couple of times.
&lt;/p&gt;
&lt;p&gt;
Shortly afterwards the site appeared to be unavailable from this location.
&lt;/p&gt;
&lt;p&gt;
It seems fine in pingdom/proxy servers.
&lt;/p&gt;
&lt;p&gt;
My guess is something like fail2ban or similar has added this IP to a blacklist?
&lt;/p&gt;
&lt;p&gt;
I wouldn't be too bothered except it's Ade's address and I think he probably wants access..
&lt;/p&gt;
&lt;p&gt;
Could you check the logs if there is a blacklist and remove 146.198.11.57
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/856</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Tue, 02 Jun 2015 13:21:27 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/856#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/856#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Yes that IP is blocked, I got this email earlier:
&lt;/p&gt;
&lt;pre class="wiki"&gt;Date: Tue,  2 Jun 2015 13:30:54 +0100 (BST)
From: root@puffin.webarch.net
To: chris@webarchitects.co.uk
Subject: lfd on puffin.webarch.net: blocked 146.198.11.57 (GB/United Kingdom/57.11.198.146.dyn.plus.net)
Time:     Tue Jun  2 13:30:54 2015 +0100
IP:       146.198.11.57 (GB/United Kingdom/57.11.198.146.dyn.plus.net)
Failures: 5 (sshd)
Interval: 300 seconds
Blocked:  Permanent Block
Log entries:
Jun  2 13:29:35 puffin sshd[22620]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=146.198.11.57  user=sam
Jun  2 13:29:37 puffin sshd[22620]: Failed password for sam from 146.198.11.57 port 63849 ssh2
Jun  2 13:29:50 puffin sshd[22620]: Failed password for sam from 146.198.11.57 port 63849 ssh2
Jun  2 13:30:22 puffin sshd[22620]: Failed password for sam from 146.198.11.57 port 63849 ssh2
Jun  2 13:30:53 puffin sshd[25538]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=146.198.11.57  user=sam
&lt;/pre&gt;&lt;p&gt;
So following the documentation, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer#Falsepositives"&gt;PuffinServer#Falsepositives&lt;/a&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;csf -dr 146.198.11.57
  Removing rule...
  DROP  all opt -- in !lo out *  146.198.11.57  -&amp;gt; 0.0.0.0/0
  LOGDROPOUT  all opt -- in * out !lo  0.0.0.0/0  -&amp;gt; 146.198.11.57
csf -g 146.198.11.57
  Chain            num   pkts bytes target     prot opt in     out     source               destination
  No matches found for 146.198.11.57 in iptables
&lt;/pre&gt;&lt;p&gt;
So you should be OK now but I'd urge you to use ssh keys rather than passwords, email me your public key(s) if you are unable to login to add them. Also please use a passphrase on any ssh keys and also keep them and back them up only on encrypted filesystems.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>