Re: Banning SSH attackers

From: Christophe Garault (christophe_at_garault.org)
Date: 10/25/05

  • Next message: Frans Englich: "ssh: problem with publickey authentication"
    Date: Tue, 25 Oct 2005 12:09:23 +0200
    To: Paul Berube <stazz@shaw.ca>
    
    

    Paul Berube a écrit :

    >Wow, thanks for the flood of replies! Looks like there are a lot of
    >options that I can try out :)
    >
    >
    One more thing to try: fail2ban. A wonderfull script that locks Ip
    (using iptables) when they have failed a specific number of connection:
    Have a look to http://fail2ban.sourceforge.net/
    It works with ssh and Apache. I'm using it for a couple of months and I
    must say it works incredibly well.

    -- 
    Christophe Garault
    

  • Next message: Frans Englich: "ssh: problem with publickey authentication"

    Relevant Pages

    • Re: [opensuse] dictionary attacks
      ... sysconfig editor or YAST2 and remove the ssh port and then the above ... firewall and the rule produced by fail2ban is the first rule examined ... IPTables can and is logged of course, see /var/log/firewall, you can ...
      (SuSE)
    • Re: ssh howto for debian?
      ... Even easier and better add the following to your iptables firewall. ... connection if they try more than 4 connections in 10 minutes. ... I appreciated the solutions found in fail2ban. ...
      (Debian-User)
    • Re: IPtables hang system when loading over 254 IP Addresses
      ... > issue about loading the IPTables with Ingress/Egress filtering on ... But when it reaches to around 254, it just locks up ... > extensive uses of Ingress/Egress and I only seen it locks up when I ...
      (Linux-Kernel)
    • Re: (SOLVED) Dovecot configuration issues for IMAP/POP3 (squeeze)
      ... discovered that fail2ban has *multiport* support for iptables - it can ... be set up to filter chains control more than one port with a single ... I further discovered that the Dovecot website itself has filter and jail ...
      (Debian-User)