1 |
Philipp Kern wrote: |
2 |
> On Tue, 2004-11-09 at 15:43, William Yang wrote: |
3 |
> |
4 |
>>There's an awful lot of "intrusion prevention" or "active response IDS" |
5 |
>>[and insert your favorite en-vogue terminology] out there in the market, |
6 |
>>and people buy it. |
7 |
> |
8 |
> |
9 |
> Yes. But the software you mentioned doesn't block your own hosts as a |
10 |
> simple shellscript would do. That's what the original poster wanted... a |
11 |
> more or less ``simple'' script to parse /var/log/secure and block the |
12 |
> IPs using iptables. |
13 |
|
14 |
Uhm... I suppose I read the request a little less literally. It seems |
15 |
pretty clear -- at least to me -- that the original poster's idea is to |
16 |
limit ssh port probing using the features of the kernel-level firewall. |
17 |
"Simple" seems to be a somewhat relative term here. I take simple to |
18 |
be "the smallest amount of logic needed to accomplish the goal with the |
19 |
fewest adverse effects" rather than "the smallest amount of logic possible." |
20 |
|
21 |
-Bill |
22 |
-- |
23 |
William Yang |
24 |
wyang@××××.net |
25 |
|
26 |
-- |
27 |
gentoo-security@g.o mailing list |