Premature termination of SSH connection attempts

From: Augustus SFX van Dusen (ASFXvD_at_story.net)
Date: 08/17/05


Date: Wed, 17 Aug 2005 21:56:55 GMT


        I have been collecting SSH server data from my logs, for the last few
months, and it turns out to be the case that the vast majority of break-in
attempts had their origin in China, Taiwan or South Korea (one can't help
but wondering but the problem is with those guys, but that's sociological
issue irrelevant to this group.)

        Since the attempts seem to be crude dictionary attacks, the only thing
that they have achieved has been to leave their data in my logs. I was
wondering whether things could be arranged so that those logs are not even
created in the first place?

        What I would like is for the SSH server (OpenSSH, in this case) to behave
in such a way that, whenever a connection is received from a host at a
blacklisted domain, the connection is simply refused. That is, instead of
completing the SSH handshake, the server terminates the dialog at that
point.



Relevant Pages

  • Re: How Stupid Is Mottershead?
    ... From the USCF Issues Forum this morning. ... The logs were being generated by software that I ... USCF Forums database, I could have tampered with that, too. ... Once the connection is established between an IP ...
    (rec.games.chess.politics)
  • Re: SBS Dial-up Connector - Connects unexpectedly.
    ... If you have turned up the logging on RRAS and made sure it logs everything, ... it should turn up in the systemlog on the server. ... that the connection can't be made. ... > discount spyware on my client PC's. ...
    (microsoft.public.windows.server.sbs)
  • RE: Computers losing their connection
    ... I am getting some event errors in the security logs. ... > Have you looked at the logs on the server? ... they have to restart their computer to regain the connection to some ...
    (microsoft.public.windows.server.sbs)
  • Re: Unable to establish the VPN connection. The VPN server may be
    ... Router 192.168.3.1 DHCP server ... >> or security parameters may not be configured properly for this connection. ... What about the ISA logs? ... If you can get a VPN connection but authentication times ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA 2004 problems
    ... but under bordermanager (novell proxy) there ... I exported the logs to excel and when connecting to the specific app, ... The entry after that says failed connection attempt. ... with while other SSL sites work, then your ISA is handling SSL properly. ...
    (microsoft.public.isa)