linux ssh security defaults
- From: japele42@xxxxxxxxx
- Date: Sat, 8 Dec 2007 03:54:35 -0800 (PST)
To prevent brute force attacks i think that linux ssh, etc services
should default for example to allow at first 30 logins within 10
minutes or so and then if that is exceeded allow only 1 per minute for
next hour or so
Don't know if this is right place to complain but i don't think
current defaults are good enough as they are!!! Only 6.5536 * 10^12
variations in any good 8 charcters long password made out of only
lowercase letters and numbers. It's absolutely possible to crack that
with just brute force.
.
- Follow-Ups:
- Re: linux ssh security defaults
- From: James Hess
- Re: linux ssh security defaults
- From: bmarkwhite
- Re: linux ssh security defaults
- Prev by Date: public key authentication with openssh on openwrt
- Next by Date: Re: public key authentication with openssh on openwrt
- Previous by thread: public key authentication with openssh on openwrt
- Next by thread: Re: linux ssh security defaults
- Index(es):
Relevant Pages
|
|