1 |
I've been getting hit with similar brute force attacks...usually from Korea |
2 |
or China......anyway |
3 |
like the several options listed above I think the less fancy you secure your |
4 |
box the better.... |
5 |
really if you want to be able to log in from any number of remote clients |
6 |
like me the best thing |
7 |
to do is simply change your sshd port. I did that and it solved the problem |
8 |
rather quickly with |
9 |
little disruption to myself....I don't want to have a key with me...to log |
10 |
in with when I travel. |
11 |
An option that I considered that nobody mentioned yet is leaving port 22 |
12 |
closed completely |
13 |
and then use port knocking to open up the port for 20 seconds or so on your |
14 |
IP (however long |
15 |
you need to log onto the system). The port opens long enough for you to |
16 |
establish a connection |
17 |
and then closes automatically to any new connections, but still allows |
18 |
established traffic through. |
19 |
Clever idea and pretty simple to impliment...just google for it...I think |
20 |
there is a gentoo wiki howto |
21 |
on it as well. |
22 |
|
23 |
Adios. |
24 |
|
25 |
On 10/3/05, Christophe Garault <christophe@×××××××.org> wrote: |
26 |
> |
27 |
> Jeremy Brake a écrit : |
28 |
> |
29 |
> >Hey all, |
30 |
> > |
31 |
> >I'm looking for an app/script which can monitor for failed ssh logins, |
32 |
> >and block using IPTables for $time after $number of failed logins (an |
33 |
> >exclusion list would be handy as well) so that I can put a quick stop to |
34 |
> >these niggly brute-force ssh "attacks" I seem to be getting more and |
35 |
> >more often. |
36 |
> > |
37 |
> >Anyone have any ideas? |
38 |
> > |
39 |
> > |
40 |
> Yep: emerge fail2ban (http://sourceforge.net/projects/fail2ban). |
41 |
> It's an excellent script written in python that can monitor all |
42 |
> unsuccessfull logins (ssh, apache) |
43 |
> There's a fail2ban.conf file where you can define many options to |
44 |
> protect you from a Dos. |
45 |
> |
46 |
> >Thanks, Jeremy B |
47 |
> > |
48 |
> > |
49 |
> Have a nice day. |
50 |
> |
51 |
> -- |
52 |
> Christophe Garault |
53 |
> -- |
54 |
> gentoo-security@g.o mailing list |
55 |
> |
56 |
> |