Re: sshd question

From: Gottin (gottin_at_gmail.com)
Date: 12/12/04


Date: 12 Dec 2004 01:01:55 -0800

Hm, bsd_mike, are you sure that your system's been broken into. I've
seen a lot of times such a unsuccessfull tries to log to a system I'm
responsible for. Well I think that there're people who are just trying
a great range of IPs for default passwords like root/root root/admin
root/password ... After I noticed such a try for logging to my system
from unknown for me IPs I just put some firewall rules. The rules were
on the main firewall and they were blocking all outside ssh/telnet
traffic. I think that there's no problems now, but may be I'm just
taking the risk.

However, as you are saying your system is 2 years old and may be it's
time to install a more current one :)



Relevant Pages

  • Re: walled garden concept
    ... I have done this using private ips. ... My method simply changes the firewall rules, ... When radius either gets a disconnect or auth attempt on the same port, ... instead we just let radius hand out static ips from a database pool. ...
    (freebsd-isp)
  • Re: SSH IP Blocking
    ... I suggest you're going to waste your firewall rules on ... > for 3 failed ssh logins and then block these IPs. ... > would then remove those IPs from my "ban list" again. ... > Talking about DoS. ...
    (comp.os.linux.security)
  • Re: Spam - What is a simple way to hide email address?
    ... > So what is the "set of firewall rules to block all traffic from ... > korea & china." ... I look up the details in blackholes.us to identify the whole block of IPs ...
    (comp.security.firewalls)
  • Re: SSH IP Blocking
    ... I suggest you're going to waste your firewall rules on folks who're ... would then remove those IPs from my "ban list" again. ... Talking about DoS. ...
    (comp.os.linux.security)