Re: ssh brute force attacks

Peter Espen <[email protected]> Sat, 29 Jan 2011 11:39:36 -0700
Newsgroups gmane.org.user-groups.nmlug
Message-ID <[email protected]>
On Jan 29, 2011, at 11:33 AM, Wesley J. Landaker wrote:

> On Saturday, January 29, 2011 10:10:06 Peter Espen wrote:
>> In addition, I wrote a script that's in crontab and it examines auth.log
>> and automatically blocks the offending originating IP address via
>> iptables.
> 
> You may want to consider using fail2ban, which is a maintained open-source 
> project that does the same sort of thing:
> 
> http://www.fail2ban.org/

Thanks.  However, sshd 22 is the only port I leave open on my personal linux box and something like fail2ban is overkill for me.  Plus, my script does exactly what I want and it was fun to write.



_______________________________________________
NMLUG mailing list
[email protected]
http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug