Re: Brute force attack, exponential delay for reconnect?

From: Unruh (unruh-spam_at_physics.ubc.ca)
Date: 05/31/05


Date: 30 May 2005 23:20:26 GMT

S P Arif Sahari Wibowo <arifsaha@yahoo.com> writes:

>Hi!

>The machines I look after have been getting very bad brute force attack
>on the openssh login. Sometime the machines just become locked up,
>although I am not sure it is related. Some of the user names are easily
>guessable and attacked, but I don't have the option to close
>password-based login.

Make sure your users have good passwords. Eg make sure that cracklib is
used to test the password. User names are assumed public knowledge. It is
the password that is most important.

>Any advice for this situation?

>I think one good way to reduce the attack is having controllable delay
>between reconnection from same IP. Ideally the delay should
>exponentially increase for every failed login attempt. Is there any
>configurations or patches that will allow such thing?



Relevant Pages

  • WinXP laptop, simple-style login conn to Win2000 share, error
    ... So, to simplify matters, add all machines to the domain. ... local machine accounts) to keep track of... ... the local account information. ... the "pushbutton login") and configure the Laptops to auto ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Account Logon Time Restriction
    ... I will have to expose my ignorance here. ... workstation from which the login originates. ... this recognizable as one of your machines? ... account's likely logged-into workstation, check if ...
    (microsoft.public.win2000.security)
  • Re: Account Logon Time Restriction
    ... attempt to see what all it can access via network shares. ... workstation from which the login originates. ... this recognizable as one of your machines? ... account's likely logged-into workstation, check if ...
    (microsoft.public.win2000.security)
  • Re: Safe way to rsync a homedir on login?
    ... windows machines to our couple of linux machines (rather than mount ... sure the ownership is right. ... the biggest issue is the time taken to login if all these ... on the desktop, which also happens, I wrote an rsync script that is ...
    (Ubuntu)
  • Re: Domain Controller Stops Processing All Login Requests Randomly
    ... >> machines simultaneously that are Deep Freeze clients. ... the server exhibited the same behaviour. ... The wierd thing is that I was able to login to the DC ... >>> Accelerated MCSE ...
    (microsoft.public.windows.server.dns)