Exploiting Fail2ban "portscan" permablocks over HTTP for denial-of-service 0 ▲ Dan Q 1 hour ago · 5 min read1068 words · Tech · hide · 0 comments I was in a forum thread with Loebas last week, who implied that webhosts might routinely firewall (e.g. via Fail2ban) IP addresses that engage in port-scanning against them. While Loebas is technically right that such a thing that can technically be done by an adaptive firewall (here's an example for Fail2ban) or e.g. in response to a honeypot hit, I'd argue that it's not a widespread practice... because this approach to security can easily do more harm than good. Blocking based on port-scanning being "bad behaviour" is exceptionally rare amongst hosting companies because it can be exploited as a denial-of-service attack against a site's legitimate users! But rather than ask you to take my word on it, I figured I'd demonstrate: This is probably something top-of-mind for Loebas, who recently added a honeypot to their forum1: look at all these hidden traps!2 Protecting Bob's favourite website By way of example, let's imagine Alice is attempting to lock Bob out of Bob's favourite… No comments yet. Log in to reply on the Fediverse. Comments will appear here.