Gentoo Archives: gentoo-security

From: William Yang <wyang@××××.net>
To: Philipp Kern <phil@××××××××.de>
Cc: Sjan Evardsson <sjan_e@×××××××××××××.edu>, "Brian G. Peterson" <brian@×××××××××.com>, gentoo-security@l.g.o
Subject: Re: [gentoo-security] RE: help blocking automated ssh scanning attack script
Date: Tue, 09 Nov 2004 20:52:44
Message-Id: 41912E1C.8000201@gcfn.net
In Reply to: Re: [gentoo-security] RE: help blocking automated ssh scanning attack script by Philipp Kern
1 Philipp Kern wrote:
2 > On Tue, 2004-11-09 at 15:43, William Yang wrote:
3 >
4 >>There's an awful lot of "intrusion prevention" or "active response IDS"
5 >>[and insert your favorite en-vogue terminology] out there in the market,
6 >>and people buy it.
7 >
8 >
9 > Yes. But the software you mentioned doesn't block your own hosts as a
10 > simple shellscript would do. That's what the original poster wanted... a
11 > more or less ``simple'' script to parse /var/log/secure and block the
12 > IPs using iptables.
13
14 Uhm... I suppose I read the request a little less literally. It seems
15 pretty clear -- at least to me -- that the original poster's idea is to
16 limit ssh port probing using the features of the kernel-level firewall.
17 "Simple" seems to be a somewhat relative term here. I take simple to
18 be "the smallest amount of logic needed to accomplish the goal with the
19 fewest adverse effects" rather than "the smallest amount of logic possible."
20
21 -Bill
22 --
23 William Yang
24 wyang@××××.net
25
26 --
27 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] RE: help blocking automated ssh scanning attack script "Brian G. Peterson" <brian@×××××××××.com>