RE: Custom messages for failed ROOT logins on RedHat

From: Stephen Villano (steve@LWR.yi.org)
Date: 09/21/01


Message-ID: <212C9CABF894D4118B43005004AF6CF514F9@SERVER21>
From: Stephen Villano <steve@LWR.yi.org>
To: "Focus-Linux (E-mail)" <focus-linux@securityfocus.com>
Subject: RE: Custom messages for failed ROOT logins on RedHat
Date: Fri, 21 Sep 2001 00:28:23 -0400

Personally I'd rather they keep bouncing off of a denied root telnet than
they bounce off with a message like that and try something that works
instead.

-----Original Message-----
From: netnerd [mailto:nkav@tpg.com.au]
Sent: Tuesday, September 18, 2001 11:18 AM
To: focus-linux@securityfocus.com
Subject: Custom messages for failed ROOT logins on RedHat

Hi, just curious if its possible to get PAM or TCP Wrappers... or anything
else for that matter, to give me a custom error message, like:
  "go away & stop trying to login as root"
When idiots try telnetting into my box. I know its possible to use TWIST
with tcpd, but i dont want it to be host based! I just want it to happen
when someone from any address tries to login as root.
Is it possible to get PAM to return custom error messages??
Any help/suggestions/flames appreciated

netnerd