Automatic blocking of attackers' IP

From: FEEB (feeb_at_chem.utoronto.ca)
Date: 09/07/04


Date: Tue, 07 Sep 2004 09:53:31 -0400 (EDT)

Hi,

I would like to have the following scenario implemented on my network:

1.
Someone tries repeatedly and illegally to log in as 'admin', 'root' or
whatever from some IP using SSH (or any other means).

2.
When the number of attempts reaches a predefined trigger level, an action
occurs (a script is executed, etc.)

The definition of attempts, the trigger level and the resulting action
should be configurable.

Is a watchdog like that that would fulfill my requirements available
somewhere out there or do I have to sit down and start scripting?

Thanks

Frank Bures, <feeb@chem.utoronto.ca>



Relevant Pages

  • Automatic blocking of attackers IP
    ... Someone tries repeatedly and illegally to log in as 'admin', 'root' or ... When the number of attempts reaches a predefined trigger level, ... occurs (a script is executed, ...
    (comp.os.linux.networking)
  • Automatic blocking of attackers IP
    ... Someone tries repeatedly and illegally to log in as 'admin', 'root' or ... When the number of attempts reaches a predefined trigger level, ... occurs (a script is executed, ...
    (comp.os.linux.security)
  • More: Finding which user sud
    ... My original post was: ... We have several admins having access to a privileged perl script ... problem is that I have records of when each admin su'd, ... I can only tell that it's being run by root. ...
    (SunManagers)
  • IBM Informix Web DataBlade: Local root by design
    ... IBM Informix Web DataBlade: Local root by design ... Impact: Any user who can: 1) Save a Perl script anywhere on the server's ... admin right on any database can do it by loading the WDB module into ...
    (Bugtraq)
  • Re: need to modify local group membership via VBscript
    ... Admin run the script on all NT computers. ... script can add domain groups to the local Administrators group. ... how to add a domain group to local administrators account: ...
    (microsoft.public.windows.server.scripting)