Gentoo Archives: gentoo-user

From: Alan McKinnon <alan.mckinnon@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] SSH brute force attacks and blacklist.py
Date: Wed, 27 Feb 2008 18:16:53
Message-Id: 200802272012.19809.alan.mckinnon@gmail.com
In Reply to: [gentoo-user] SSH brute force attacks and blacklist.py by Steve
1 On Wednesday 27 February 2008, Steve wrote:
2
3 > I migrated to try using iptables as my firewall and using
4 > blacklist.py - which I got working after some minor config-tweaking.
5 > I'm aware that there is configuration in the blacklist.py script for
6 > BLOCKING_PERIOD - but what I really miss the "blocked forever" nature
7 > of the DenyHosts alternative.... though I prefer every other aspect
8 > of the
9 > iptables/blacklist.py approach.
10
11 blacklist.py seems to work well for you, so why not just set
12 BLOCKING_PERIOD to it's maximum value?
13
14 I would imagine that even after say one week the vast majority of zombie
15 bots would have given up and moved on
16
17
18
19 --
20 Alan McKinnon
21 alan dot mckinnon at gmail dot com
22
23 --
24 gentoo-user@l.g.o mailing list