Skip to content

About

Brute force attack investigation and mitigation using Kali Linux, Hydra, Wireshark and iptables — IIT Madras AI Cybersecurity Project

Topics

Resources

Stars

2 stars

Watchers

0 watching

Forks

Latest commit

 

History

6 Commits

Folders and files

Repository files navigation

🔐 Brute Force Attack Analysis and

Mitigation Using Kali Linux

Status Platform Institute Tools


👤 Author

Kamalpreet Singh AI-Powered Cybersecurity Mastery — IIT Madras GitHub


📌 Overview

This project investigates and mitigates brute force attack patterns across system and network layers using Kali Linux.

Completed as part of IIT Madras AI-Powered Cybersecurity Mastery Program Course 2 — Designing Secure Systems Networks and Devices.


🏢 Real World Scenario

Company: SecureCore Technologies

A mid-sized enterprise detected surge in failed login attempts on critical servers. Despite active security systems deeper log analysis revealed ongoing brute force attacks targeting weak credentials and misconfigured policies.


🎯 Objective

Investigate and mitigate brute force attack patterns by:

  • Analyzing system logs
  • Auditing user accounts
  • Reviewing firewall rules
  • Analyzing encrypted files
  • Identifying unauthorized access

🛠️ Tools Used

Tool Purpose
Kali Linux Investigation platform
Hydra Brute force simulation
Wireshark Packet analysis
iptables Firewall inspection
rsyslog Log capture
GPG Encryption analysis
ent Entropy analysis

✅ Tasks Completed

Task 1 — Baseline System Check

Established system baseline including OS version kernel network configuration running services and disk usage.

Commands:

sudo apt update && sudo apt upgrade -y
uname -a
ip addr
ss -tulpn
df -h
free -h

Task 2 — User Account Audit

Investigated accounts and permissions to identify weak credentials and unauthorized access points.

Key Findings:

  • postgres had interactive bash shell
  • kali-trusted had NOPASSWD sudo access
  • No unauthorized UID 0 accounts
  • No passwordless accounts detected

Task 3 — Firewall Analysis

Examined firewall configuration open ports and active network connections.

Critical Finding: All iptables chains set to ACCEPT with zero filtering rules active. Completely open firewall detected.


Task 4 — SSH Brute Force Detection & Mitigation

This task demonstrates a full before-and-after analysis of an SSH brute force attack, showing the system's vulnerability without protection and the effectiveness of Fail2Ban as a mitigation control.


🔴 Before Mitigation

The SSH service was started with no brute-force protection in place. Hydra was used to launch a dictionary attack using the rockyou.txt wordlist. With nothing blocking repeated attempts, thousands of password tries were sent continuously to the SSH service.

Step 1 — Start SSH Service

sudo service ssh start
sudo service ssh status

SSH service started successfully and is confirmed active on port 22.

Figure 1: SSH service started and confirmed active on port 22

Screenshot 2026-05-22 190909

Step 2 — Launch Hydra Brute-Force Attack (No Protection)

hydra -l red -P /usr/share/wordlists/rockyou.txt ssh://127.0.0.1 -t 4 -V

Hydra launched 14,344,399 login attempts using 4 parallel threads. With no Fail2Ban active, every attempt reached the SSH service without being blocked or throttled.

Figure 2: Hydra sending unrestricted brute-force attempts — no protection active

Screenshot 2026-05-22 191027

Step 3 — Failed Attempts Logged in auth.log

grep "Failed password" /var/log/auth.log | tail -20

The auth.log file recorded a continuous stream of failed password attempts from 127.0.0.1 every 1–3 seconds, confirming the attack was reaching the SSH service with no intervention.

Figure 3: auth.log showing rapid failed SSH login attempts with no banning

Screenshot 2026-05-22 191235

🟢 Applying Mitigation — Installing and Configuring Fail2Ban

Step 4 — Install Fail2Ban

sudo apt install fail2ban -y

Fail2Ban installed successfully along with its dependency python3-systemd.

Figure 4: Fail2Ban installed via apt package manager Screenshot 2026-05-22 191609


Step 5 — Configure the SSH Jail

The Fail2Ban SSH jail was configured with the following settings:

[sshd]
enabled = true
port = 22
filter = sshd
logpath = /var/log/auth.log
maxretry = 3
bantime = 600
findtime = 600
backend = auto
ignoreself = false

Setting ignoreself = false ensures the loopback address (127.0.0.1) is not exempt from banning, which is critical for this local simulation.

Figure 5: Fail2Ban SSH jail configuration in nano

Screenshot 2026-05-22 200558

Step 6 — Start Fail2Ban and Verify Baseline Status

sudo service fail2ban start
sudo service fail2ban status
sudo fail2ban-client status sshd

Fail2Ban started successfully and confirmed active. The initial jail status showed zero failed attempts and no banned IPs, confirming a clean baseline before re-running the attack.

Figure 6: Fail2Ban service active and running

Screenshot 2026-05-22 191710

Figure 7: Fail2Ban sshd jail showing 0 failed attempts and empty banned IP list

Screenshot 2026-05-22 191852

✅ After Mitigation

Step 7 — Re-run Hydra Attack — Blocked and IP Banned

hydra -l red -P /usr/share/wordlists/rockyou.txt ssh://127.0.0.1 -t 4 -V
sudo fail2ban-client status sshd

When Hydra was launched again, it immediately received a Connection refused error instead of attempting passwords. The Fail2Ban jail status confirmed 13 total failed attempts, 1 currently banned IP, and 127.0.0.1 in the banned IP list. The mitigation was fully effective.

Figure 8: Hydra blocked with Connection refused; Fail2Ban showing 127.0.0.1 banned after 13 failed attempts

Screenshot 2026-05-22 200223

Simulation Summary:

Before Fail2Ban After Fail2Ban
Hydra result Unlimited attempts Connection refused
auth.log Flooded with failures Attack stopped
Banned IPs None 127.0.0.1
Total failed attempts Thousands 13 (then blocked)
Protection ❌ None ✅ Active

Task 5 — Entropy Analysis

Scanned for encrypted files using entropy analysis to detect hidden data.

Results:

File Entropy Conclusion
normal.txt 3.6 bits/byte Plain text
secret.txt.gpg 6.24 bits/byte Encrypted

Task 6 — Log Analysis

Deep analysis of authentication logs to uncover complete attack picture.

Findings:

  • 20 failed attempts recorded
  • Attack every 1-3 seconds
  • Confirms automated tool
  • No successful login
  • Started 14/05/2026 at 20:30

Task 7 — Wireshark Analysis

Analyzed two packet capture files to detect network intrusion attempts.

File 1 — NmapScanANDDoS.pcapng:

  • Nmap SYN stealth scan detected
  • Fingerprint Win=1024 MSS=1460
  • SYN flood DoS identified
  • Attacker: 192.168.12.131

File 2 — MITM.pcapng:

  • ARP cache poisoning detected
  • Man in middle attack confirmed
  • ICMP redirects identified

🔍 Security Findings

Finding Risk Mitigated
Open firewall Critical ✅ Yes
postgres bash shell High ✅ Yes
kali-trusted NOPASSWD High ✅ Yes
SSH brute force High ✅ Yes
ARP poisoning Critical ✅ Detected
Nmap SYN scan Medium ✅ Detected

🛡️ Mitigations Applied

Firewall

sudo iptables -A INPUT -m state \
--state ESTABLISHED,RELATED -j ACCEPT

sudo iptables -A INPUT -p tcp \
--dport 22 -s 192.168.64.0/24 -j ACCEPT

sudo iptables -P INPUT DROP

sudo iptables-save > \
/etc/iptables/rules.v4

SSH Hardening

sudo apt install fail2ban -y
sudo service fail2ban start

# Set MaxAuthTries 3
# Set PermitRootLogin no
# Set PasswordAuthentication no
sudo service ssh restart

File Security

chmod 700 /home/red/.ssh
chmod 700 /home/red/.gnupg
md5sum /home/red/* > baseline.txt

💻 Lab Environment

Component Detail
Platform VMware Workstation Pro
OS Kali Linux
RAM 8GB
CPU 2 Cores
Network NAT Mode

📸 Screenshots

Task 1 — Baseline Check

Screenshot 2026-05-11 195128 Screenshot 2026-05-11 211816 Screenshot 2026-05-11 212032 Screenshot 2026-05-11 214711 Screenshot 2026-05-11 214732 Screenshot 2026-05-11 221404 Screenshot 2026-05-12 190614

Task 2 — User Audit

Screenshot 2026-05-13 201001 Screenshot 2026-05-13 201601 Screenshot 2026-05-13 201947 Screenshot 2026-05-13 202740 Screenshot 2026-05-13 203207 Screenshot 2026-05-13 203227 Screenshot 2026-05-13 204810 Screenshot 2026-05-13 204831 Screenshot 2026-05-13 205711 Screenshot 2026-05-13 205930 Screenshot 2026-05-13 210559 Screenshot 2026-05-13 210636 Screenshot 2026-05-13 211156 Screenshot 2026-05-13 211342 Screenshot 2026-05-13 211355 Screenshot 2026-05-13 211848 Screenshot 2026-05-13 211920 Screenshot 2026-05-13 212133 Screenshot 2026-05-13 212953

Task 3 — Firewall

Screenshot 2026-05-14 185731 Screenshot 2026-05-14 185916 Screenshot 2026-05-14 185940 Screenshot 2026-05-14 190007 Screenshot 2026-05-14 190038 Screenshot 2026-05-14 190046 Screenshot 2026-05-14 190115 Screenshot 2026-05-14 190144

Task 4 — Brute Force & Fail2Ban Mitigation

Before Mitigation

Figure 1: SSH service started and confirmed active on port 22 SSH service started

Figure 2: Hydra sending unrestricted brute-force attempts — no protection active Hydra attack no protection

Figure 3: auth.log showing rapid failed SSH login attempts with no banning auth log failed attempts

Applying Mitigation

Figure 4: Fail2Ban installed via apt package manager Fail2Ban install

Figure 5: Fail2Ban service active and running Fail2Ban running

Figure 6: Fail2Ban sshd jail showing 0 failed attempts and empty banned IP list Fail2Ban baseline status

Figure 7: Fail2Ban SSH jail configuration in nano Fail2Ban config

After Mitigation

Figure 8: Hydra blocked with Connection refused; Fail2Ban showing 127.0.0.1 banned after 13 failed attempts After mitigation Hydra blocked


Original Task 4 Screenshots:

Screenshot 2026-05-14 202125 Screenshot 2026-05-14 202149 Screenshot 2026-05-14 202221 Screenshot 2026-05-14 202519 Screenshot 2026-05-14 202603 Screenshot 2026-05-14 202739 Screenshot 2026-05-14 202852 Screenshot 2026-05-14 202939 Screenshot 2026-05-14 203056 Screenshot 2026-05-14 203125 Screenshot 2026-05-14 203148 Screenshot 2026-05-14 203212 Screenshot 2026-05-14 203236 Screenshot 2026-05-14 203410

Task 5 — Entropy

Screenshot 2026-05-15 071843 Screenshot 2026-05-15 072156 Screenshot 2026-05-15 072212 Screenshot 2026-05-15 072359 Screenshot 2026-05-15 072723 Screenshot 2026-05-15 072802 Screenshot 2026-05-15 072847 Screenshot 2026-05-15 073015 Screenshot 2026-05-15 073108

Task 6 — Log Analysis

Screenshot 2026-05-15 140722 Screenshot 2026-05-15 140747 Screenshot 2026-05-15 140813 Screenshot 2026-05-15 140845 Screenshot 2026-05-15 140915

Task 7 — Wireshark

Screenshot 2026-05-15 152440 Screenshot 2026-05-15 152523 Screenshot 2026-05-15 152603 Screenshot 2026-05-15 152641 Screenshot 2026-05-15 152713 Screenshot 2026-05-15 152744 Screenshot 2026-05-15 152817 Screenshot 2026-05-15 152837

📚 What I Learned

  • How brute force attacks work in real time
  • Detecting attacks through log analysis
  • Hardening SSH and firewall configurations
  • Using entropy to identify encrypted data
  • How ARP poisoning enables MITM attacks
  • How Nmap SYN scans fingerprint targets
  • Applying practical mitigation techniques

🎓 Certification

Program: AI-Powered Cybersecurity Mastery Institute: IIT Madras Course: Designing Secure Systems Networks and Devices Status: Completed ✅


📬 Connect

GitHub: kamal301096


Completed in isolated lab environment for educational purposes only

About

Brute force attack investigation and mitigation using Kali Linux, Hydra, Wireshark and iptables — IIT Madras AI Cybersecurity Project

Topics

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors