Gentoo Archives: gentoo-security

From: Jerry Eastmanhouser <fuct.it@×××××.com>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] [OT?] automatically firewalling off IPs
Date: Mon, 31 Oct 2011 03:55:52
Message-Id: 87f1fb0a0510030129o41595461ta649c30a20d39eb9@mail.gmail.com
In Reply to: Re: [gentoo-security] [OT?] automatically firewalling off IPs by Christophe Garault
1 I've been getting hit with similar brute force attacks...usually from Korea
2 or China......anyway
3 like the several options listed above I think the less fancy you secure your
4 box the better....
5 really if you want to be able to log in from any number of remote clients
6 like me the best thing
7 to do is simply change your sshd port. I did that and it solved the problem
8 rather quickly with
9 little disruption to myself....I don't want to have a key with me...to log
10 in with when I travel.
11 An option that I considered that nobody mentioned yet is leaving port 22
12 closed completely
13 and then use port knocking to open up the port for 20 seconds or so on your
14 IP (however long
15 you need to log onto the system). The port opens long enough for you to
16 establish a connection
17 and then closes automatically to any new connections, but still allows
18 established traffic through.
19 Clever idea and pretty simple to impliment...just google for it...I think
20 there is a gentoo wiki howto
21 on it as well.
22
23 Adios.
24
25 On 10/3/05, Christophe Garault <christophe@×××××××.org> wrote:
26 >
27 > Jeremy Brake a écrit :
28 >
29 > >Hey all,
30 > >
31 > >I'm looking for an app/script which can monitor for failed ssh logins,
32 > >and block using IPTables for $time after $number of failed logins (an
33 > >exclusion list would be handy as well) so that I can put a quick stop to
34 > >these niggly brute-force ssh "attacks" I seem to be getting more and
35 > >more often.
36 > >
37 > >Anyone have any ideas?
38 > >
39 > >
40 > Yep: emerge fail2ban (http://sourceforge.net/projects/fail2ban).
41 > It's an excellent script written in python that can monitor all
42 > unsuccessfull logins (ssh, apache)
43 > There's a fail2ban.conf file where you can define many options to
44 > protect you from a Dos.
45 >
46 > >Thanks, Jeremy B
47 > >
48 > >
49 > Have a nice day.
50 >
51 > --
52 > Christophe Garault
53 > --
54 > gentoo-security@g.o mailing list
55 >
56 >