re: SSH scans...

brian_at_ethernet.org
Date: 12/21/04

  • Next message: Jim Halfpenny: "Re: Strange command histories in hacked shell server"
    Date: Tue, 21 Dec 2004 14:14:48 -0500 (EST)
    To: incidents@securityfocus.com
    
    

    i dont know how relevant this is, but--

    i've been getting a lot of these too, but what's been annoying me is
    that they took bandwidth and space in my logs which i both need as the
    brute force attempts were mainly to my development machines.

    so i wrote this little piece of code called 'timelox' that allowed me
    to specify how many failed logins i want to allow from a single host in
    a time-frame of N seconds before i firewall it.

    http://ethernet.org/~brian/src/timelox/

    this was written basically for private use so dont expect too much
    fancy stuff. look at the code, read the README, and if you like the idea
    you can even use it. ;) if you need help adding it to the daemon of your
    choice or help understanding how to implement it yourself you can
    contact me - but note you need some basic programming background...

    this was tested only on openbsd (as this is what i run) but you could
    easily port it.

    the most important thing to note is that the code does *not* contain
    anything to actually firewall the offending host. you can snprintf() it
    and execute or write ioctl()'s to do it, whatever you like. just read
    the comments if you decide to use it.

    sorry if this is irrelevant..

    -b.


  • Next message: Jim Halfpenny: "Re: Strange command histories in hacked shell server"

    Relevant Pages

    • Re: Ads will not go away!!!
      ... :> Any updated antivirus and patched system will not be vulnerable to ... :> attack. ... No, I dont approve of spam thats why I said to disable messenger, remeber U ... :> A firewall has nothing to do with preventing ads ...
      (microsoft.public.windowsxp.general)
    • Re: Trying to connect a Windows XP to a Windows ME to transfer dat
      ... > Oh gosh, you sound like you know exactly what your talking about, but ... > firewall (I do know I have one, just dont know where to find it). ... find a very tech-savvy friend or pay someone else to do this for you. ...
      (microsoft.public.windowsxp.network_web)
    • Re: [OT] Wireless keyboard/mouse.....
      ... I know you dont have it and I dont want to feed the trolls, ... Software firewall is in many cases much better than outside hardware ... security, you should have both. ... There is no fixed version of my homepages. ...
      (comp.security.misc)
    • Re: Microsoft Critical Security Updates
      ... More difficult is to me explain a question 2 u understand what is a ball in ... >>If u dont proctectthis simple doors with some ... >>There is no firewall or antivirus that keep u safe. ...
      (microsoft.public.security)
    • Re: Two Firewalls...
      ... If you dont host any servers in your home ... With the advent of worms like MSBlaster, I'd say that putting a firewall on ... Assuming you have a NAT router, ... you bring home an infected laptop from work ...
      (comp.security.firewalls)