Re: ssh brute force attacks
Aaron Birenboim <[email protected]> Tue, 01 Feb 2011 08:09:50 -0700
| Newsgroups | gmane.org.user-groups.nmlug |
|---|---|
| Message-ID | <[email protected]> |
On 01/28/2011 03:18 PM, Ed Heron wrote:
> What is the deal with the SSH brute force attacks? I wasn't paying
> attention until recently, but some of my new CentOS machines are giving
> me reports of all the failed login attempts.
I get hammered all the time at work.
See if denyhosts will work for you.
> Has everybody else already gotten to this conclusion or are there lots
> of people still allowing remote SSH access?
key access only, with denyhosts is quite safe IMOHO, and
denyhosts will cut down the hacker SSH traffic fast.
It starts putting hacker/zombie IPs on a blacklist.
Warning: you will get some false positives,
when users try many times in a row to login, and fail.
aaron
_______________________________________________
NMLUG mailing list
[email protected]
http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug