Re: Options for dealing with sshd brute force attacks

Rhialto <[email protected]>
Newsgroups gmane.os.netbsd.devel.network
Message-ID <[email protected]>
On Sat 28 Dec 2024 at 21:43:06 +0000, John Klos wrote:
> Hi,
> 
> > In pkgsrc there is security/pam-af which keeps the same sort of
> > information as blacklistd, but using PAM instead of being generic.
> > It is configured using the pam_af_tool which stored the config in the
> > same database.
> 
> Wouldn't this reject connections at the same place as connections that are
> rejected because of the lack of password authentication?

Close, I suppose, but a bit earlier. I don't have a configuration
example at hand (the manual doesn't seem to have one) but I think you'd
configure it in /etc/pam.d/sshd as the first or one of the first lines
and I expect that PAM is checked before sshd tries most other things.

> John
-Olaf.
-- 
___ Olaf 'Rhialto' Seibert                            <rhialto/at/falu.nl>
\X/ There is no AI. There is just someone else's work.           --I. Rose
signature.asc (application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEFVAhiiWjqgwBVdQAmYnGRWHD+9MFAmdxSN4ACgkQmYnGRWHD
+9O0Swf9GNdqkLci2UE3X1pgVmoedxsd8Onvsi/wIVLHPcLJHwShlowBmmAEUVCx
xmTrG5MQbEwIbElh/LVHGIWiSHWLHy6GOfE5RjGi16s9C5VXihDKQZgeVaJW6hHJ
hxi53Stxle825BujCNFp9pZkrKgNkdwmvQYxzAWB/diaAl9Lh56lu/+1I1E3raea
7M3sA96FBwPr71Xd5ajxa2rTQaNcrVic3E2moDSxKEI9VJJ+BcM/fFo2TE/aX6oK
JhtbpeiJfC14UeNetKTYmf60Wn2oqhJTYqx/SnHOLSYJeHm30ol+zgQL1Oz3WfEb
Gj93PEr0pGDzmIwmGIEs4lPQfek1Fg==
=3iQ9
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.