Re: ssh brute force attacks

Aaron Birenboim <[email protected]> Tue, 01 Feb 2011 08:09:50 -0700
Newsgroups gmane.org.user-groups.nmlug
Message-ID <[email protected]>
On 01/28/2011 03:18 PM, Ed Heron wrote:
 >    What is the deal with the SSH brute force attacks?  I wasn't paying
 > attention until recently, but some of my new CentOS machines are giving
 > me reports of all the failed login attempts.

I get hammered all the time at work.
See if denyhosts will work for you.

 >    Has everybody else already gotten to this conclusion or are there lots
 > of people still allowing remote SSH access?

key access only, with denyhosts is quite safe IMOHO, and
denyhosts will cut down the hacker SSH traffic fast.
It starts putting hacker/zombie IPs on a blacklist.

Warning:  you will get some false positives,
   when users try many times in a row to login, and fail.

              aaron
_______________________________________________
NMLUG mailing list
[email protected]
http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug