Re: Options for dealing with sshd brute force attacks
Jarle Greipsland <[email protected]>
| Newsgroups | gmane.os.netbsd.devel.network |
|---|---|
| Message-ID | <[email protected]> |
John Klos <[email protected]> writes: > We all know that public facing ssh servers will get tons of > brute force attacks. That's just a fact of life. > > For many machines, running blocklistd helps tremendously. But > what happens when blocklistd won't help because npf can't be > used? > > OpenSSH doesn't use tcpwrappers any longer, but I suppose I > could launch it from inetd as one option. The OpenSSH version included in NetBSD (at least until 10.0) still has the tcpwrappers support. I use it all the time, and am very happy that it's still there. -jarle -- "Things always look the darkest before they go completely black."