Login Delay in /etc/login.defs not working? Debian



I would like to set a login delay so that one can try to login only every
20 seconds from a given ip, to slow down the the bruit force attacks I
have been getting lately on my ssh port. I have set the FAIL_DELAY value
on the /etc/login.defs but it does not look like that changed anything :(

I am using Debian.

Also, I was wondering, are there any systems that would trick a robot into
a fake login trap? Like a system that would accept a failed connection at
random and pretend to be an SSH server or and FTP server. If the system is
sufficiently smart it could put an end to bruit force attacks by tricking
the robots into thinking that they have succeeded. Just some wishful
thinking on my part, have not seen anything like that yet.

Thanks for reading,

-Bogdan
.



Relevant Pages

  • Re: iptables in linux
    ... -the number of times a username can be tried, prefer it set at 2 and ... If someone tries to login 3 times within 40 seconds then ant further ... so I add a separate chain and jump to that chain at the top of the ... Set the ssh port to something other than 22 (some high number like ...
    (Fedora)
  • Re: [Full-disclosure] reduction of brute force log
    ... Source quench and redirect are both powerful, ... The 1599-1601 ports are used to open/close the ssh port, ... [Full-disclosure] reduction of brute force login attempts via SSH through iptables --hashlimit ...
    (Full-Disclosure)
  • Simple-ish question
    ... I've set up a Dovecot imap server on my home linux box (on a dynamic IP ... I've opened up the SSH port so i can make changes ... liberally sprinkled with multiple attempts to login from single ips. ...
    (comp.mail.imap)
  • Re: too many illegal connection attempts through ssh
    ... > server from a suspicious hacker. ... > IP address if it is attempting to guess my login usernames? ... ssh port to something else, like a high numbered port that's otherwise ... the best way to deal with this is through the firewall rather than ...
    (freebsd-questions)
  • RE: Allowing remote root login seems to be bad. Why?
    ... Allowing remote root login seems to be bad. ... If I can add my 2 cents, I recommend also changing the ssh port. ... attacks a day with several hundred to several thousand attempts per ...
    (SSH)