Re: SSHD: Limit login attempt rate



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

bmearns escribió:

| I'm running an sshd on Fedora 8, and have recently been getting
| swamped with people trying to log in (i.e., break in). It's configured
| to only allow three authentication attempts per connection, but they
| just keep reconnecting: probably some script kiddies with port
| sniffers and password testers. Is there a way to configure it so that
| there's a timeout after failed attempts? For example, if a particular
| address tries and fails three times to authenticate, that address is
| blocked for three hours, or something similar?

What is DenyHosts?
DenyHosts is a script intended to be run by Linux system administrators
to help thwart SSH server attacks (also known as dictionary based
attacks and brute force attacks).

http://denyhosts.sourceforge.net/

- --
Un saludo
Alo [alo(@)uk2.net]
PGP en http://pgp.eteo.mondragon.edu [Get "0xF6695A61 "]
Usuario registrado Linux #276144 [http://counter.li.org]

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAkiJpN4ACgkQvzPPcPZpWmHzDwCffF28uXIZBOiGx5/TAi/TodMu
uWEAn2/0bzi9hnM1rPIU4K0DXDQZ2y9S
=aULR
-----END PGP SIGNATURE-----
.



Relevant Pages

  • Re: intrusion?
    ... DenyHosts is a script intended to be run by Linux system administrators ... attacks and brute force attacks). ... Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org ...
    (comp.os.linux.security)
  • Re: Denyhosts
    ... Package: denyhosts ... Installed-Size: 412 ... an utility to help sys admins thwart ssh hackers ... brute-force attacks by adding entries to /etc/hosts.deny. ...
    (Ubuntu)
  • Re: [opensuse] Coordinated, distributed ssh attacks?
    ... Something like that already exists in denyhosts. ... Yes, as a collaborative, dynamic effort. ... to help thwart SSH server attacks (also known as dictionary based attacks ... hackers attempted to gain access to your server. ...
    (SuSE)
  • Re: How do I look up an IP address?
    ... depending on where is the IP being used (Europe, USA, Asia...) ... | I am getting emails from NETGEAR that attacks are bring dropped. ... Comment: Using GnuPG with Debian - http://enigmail.mozdev.org ...
    (comp.security.firewalls)
  • Re: router security
    ... to a wired router with a considerably stronger ... However I wonder if the Elcomsoft approach is really ... attacks; wouldn't fail2ban and denyhosts and iptables suffice to block ... Would denyhosts be useful if there is no sshd server? ...
    (Ubuntu)