Re: SSH2

From: David Tonhofer, m-plify S.A. (d.tonhofer_at_m-plify.com)
Date: 04/05/05

  • Next message: Burke, Thomas G.: "RE: SSH2"
    Date: Tue, 05 Apr 2005 22:37:20 +0200
    To: General Red Hat Linux discussion list <redhat-list@redhat.com>
    
    

    I don't think so, I have a few thousand attempts with various vanilla
    users each day on each machine. Tiresome. I think SSH should tarpit
    the connections, I have already an itch to fix the source....

    --On Tuesday, April 05, 2005 4:20 PM -0400 "Burke, Thomas G." <tg.burke@ngc.com> wrote:

    > All,
    >
    > I've always thought this interesting, so I'll ask... I thought SSH(2) used hosts.deny & hosts.allow. I find it interesting, then, that I get so many (L)users trying to hack my SSH connection. Any thoughts? Maybe I missed something in my setup?
    >
    > -Tom
    >
    > --
    > redhat-list mailing list
    > unsubscribe mailto:redhat-list-request@redhat.com?subject=unsubscribe
    > https://www.redhat.com/mailman/listinfo/redhat-list
    >
    >
    >

    -- 
    redhat-list mailing list
    unsubscribe mailto:redhat-list-request@redhat.com?subject=unsubscribe
    https://www.redhat.com/mailman/listinfo/redhat-list
    

  • Next message: Burke, Thomas G.: "RE: SSH2"

    Relevant Pages

    • RE: SSH2
      ... I think SSH should tarpit ... > the connections, I have already an itch to fix the source.... ...
      (RedHat)
    • Re: [Full-disclosure] reduction of brute force login attempts via SSH through iptables --
      ... reduction of brute force login attempts via SSH through iptables --hashlimit ... out why my first attempts at using the hashlimit functionality in iptables ... against legitimate SSH connections, unless someone spoofs a very large ...
      (Full-Disclosure)
    • Re: Looking for program that emails me when dhcp addr changes
      ... For SSH all you need forwarded is TCP Port 22... ... >>participate in TCP connections or UDP conversations it initiates but ...
      (comp.security.ssh)
    • Re: ssh disconnecting [WAS: Getting Cut-Off]
      ... I left an SSH connection open to my server last night, ... after unexpecteded termination of previous connections. ... >>I didn't think my connection was idle since file transfer was occuring, ...
      (freebsd-questions)
    • Re: SSH login takes very long time...sometimes
      ... to open many connections is probably not that important, ... These were different types of attacks, primarily originating from single IP addresses: ... but had the worst impact on the ssh availability. ... So the best option for me was to implement a log analyzer script placing temporary blocks on the firewall when necessary. ...
      (freebsd-stable)