Re: Advice on dealing with scripted SSH attacks?



--- "Zembower, Kevin" <kzembowe@xxxxxxxxxx> wrote:

What's the current advice on dealing with scripts
that repeatedly try to
log onto SSH using a list of common usernames and
'password' for the
password? I get up to 4,000 of these a day from a
single server. In
searching Google on this, I've learned of techniques
using PAM and
firewall rules that are created dynamically in
response to log-in
attempts.


I've seen systems where an entry is made in
/etc/hosts.allow for sshd: for the offending IP if too
many attempts are detected. But in order for this to
work, your sshd must be compiled with tcp_wrappers
support.
I see this sort of attack a lot, and if the attacking
script hits a tcp wrapped ssh, it will stop
immediately. After a few minutes/hours, the entry can
be removed from hosts.allow (or not).



__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com



Relevant Pages

  • Re: no sshd log exists
    ... I have the same thing in my sshd_config for logging my ssh ... Do You Yahoo!? ... Mail has the best spam protection around ...
    (SSH)
  • Re: Brute Force Detection + Advanced Firewall Policy
    ... > Im getting flooded with ssh and ftp attempts. ... Maybe it helps to disallow password athentication, ... Do You Yahoo!? ... Mail has the best spam protection around ...
    (FreeBSD-Security)
  • Re: allow SFTP FTP but not SSH. Can ??
    ... If I can even allow sftp not disallow SSH, ... Do You Yahoo!? ... Mail has the best spam protection around ...
    (Fedora)
  • no sshd log exists
    ... I want to see a log of all users that log in via ssh, ... is on a Debian Linux. ... Do You Yahoo!? ... Mail has the best spam protection around ...
    (SSH)
  • Analysis of SSH crc32 compensation attack detector exploit
    ... Analysis of SSH crc32 compensation attack detector exploit ... detector vulnerability to remotely compromise a Red Hat Linux ... Active Internet connections (servers and established) ...
    (Incidents)