Brute force attack, exponential delay for reconnect?

From: S P Arif Sahari Wibowo (arifsaha_at_yahoo.com)
Date: 05/30/05


Date: Mon, 30 May 2005 15:15:24 -0400

Hi!

The machines I look after have been getting very bad brute force attack
on the openssh login. Sometime the machines just become locked up,
although I am not sure it is related. Some of the user names are easily
guessable and attacked, but I don't have the option to close
password-based login.

Any advice for this situation?

I think one good way to reduce the attack is having controllable delay
between reconnection from same IP. Ideally the delay should
exponentially increase for every failed login attempt. Is there any
configurations or patches that will allow such thing?

Thank you!

-- 
                              Stephan Paul Arif Sahari Wibowo
   _____  _____  _____  _____
  /____  /____/ /____/ /____
 _____/ /      /    / _____/       http://www.arifsaha.com/


Relevant Pages

  • WinXP laptop, simple-style login conn to Win2000 share, error
    ... So, to simplify matters, add all machines to the domain. ... local machine accounts) to keep track of... ... the local account information. ... the "pushbutton login") and configure the Laptops to auto ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Account Logon Time Restriction
    ... I will have to expose my ignorance here. ... workstation from which the login originates. ... this recognizable as one of your machines? ... account's likely logged-into workstation, check if ...
    (microsoft.public.win2000.security)
  • Re: Account Logon Time Restriction
    ... attempt to see what all it can access via network shares. ... workstation from which the login originates. ... this recognizable as one of your machines? ... account's likely logged-into workstation, check if ...
    (microsoft.public.win2000.security)
  • Re: Safe way to rsync a homedir on login?
    ... windows machines to our couple of linux machines (rather than mount ... sure the ownership is right. ... the biggest issue is the time taken to login if all these ... on the desktop, which also happens, I wrote an rsync script that is ...
    (Ubuntu)
  • Re: Domain Controller Stops Processing All Login Requests Randomly
    ... >> machines simultaneously that are Deep Freeze clients. ... the server exhibited the same behaviour. ... The wierd thing is that I was able to login to the DC ... >>> Accelerated MCSE ...
    (microsoft.public.windows.server.dns)