Gentoo Archives: gentoo-security

From: xyon <xyon@×××××××××××.com>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] [OT?] automatically firewalling off IPs
Date: Mon, 31 Oct 2011 03:55:50
Message-Id: ME-1EMC4v-0002jK-4u@indigorobot.com
In Reply to: Re: [gentoo-security] [OT?] automatically firewalling off IPs by "Hemmann
1 I agree. I use an obscure port for ssh as well as only allow key-based
2 auth (PasswordAuthentication is disabled). I have not have any attempts
3 on my boxes.
4
5 On Sun, 2005-10-02 at 23:37 +0200, Hemmann, Volker Armin wrote:
6 > On Sunday 02 October 2005 23:10, Jeremy Brake wrote:
7 > > Hey all,
8 > >
9 > > I'm looking for an app/script which can monitor for failed ssh logins,
10 > > and block using IPTables for $time after $number of failed logins (an
11 > > exclusion list would be handy as well) so that I can put a quick stop to
12 > > these niggly brute-force ssh "attacks" I seem to be getting more and
13 > > more often.
14 > >
15 > > Anyone have any ideas?
16 > >
17 > > Thanks, Jeremy B
18 >
19 > and what do you do, if they spoof your gateway/router/nameservers ip?
20 > If you use key-based authentifiction, you shouldn't have to fear brute-force
21 > attemps... and as the others wrote, changing the port, may also help a bit.
22
23 --
24 gentoo-security@g.o mailing list