Gentoo Archives: gentoo-user

From: Adam Carter <Adam.Carter@×××××××××.au>
To: "gentoo-user@l.g.o" <gentoo-user@l.g.o>
Subject: RE: [gentoo-user] Curious pattern in log files from ssh...
Date: Wed, 03 Dec 2008 22:53:11
Message-Id: 5602B0BD6D59AE4791BE83104940118D3BD1CF05@excprdmbxw002.optus.com.au
In Reply to: Re: [gentoo-user] Curious pattern in log files from ssh... by Steve
1 > I previously used denyhosts - but (I can't remember why) it became
2 > preferable to block with IPtables rather than with
3 > tcpwrappers... which
4 > prompted me to dump it in favour of a bespoke script based upon
5 > blacklist.py (http://blinkeye.ch/mediawiki/index.php/SSH_Blocking) -
6 > though, now, I'm tempted by the more professional looking sshguard -
7 > thanks for the tip. Of course, this doesn't really address
8 > the problem
9 > I posted about - because I'm now faced with a highly distributed
10 > dictionary attack...
11
12 Fail2ban is iptables based. From the website it now appears to have a map feature so if say you notice most of the attacks coming from China, and none of you ssh useres are in China, you could perhaps block the entire country with http://people.netfilter.org/~peejix/geoip/howto/geoip-HOWTO.html