Re: S: ssh worms FAQ

From: Jos (jos_at_nospam.nl)
Date: 10/09/04

  • Next message: microcheap: "Re: S: ssh worms FAQ"
    Date: Sat, 09 Oct 2004 10:53:29 +0200
    
    

    On Fri, 08 Oct 2004 21:48:24 -0400, microcheap wrote:

    > On Fri, 17 Sep 2004 11:43:42 +0000, Stephan Goeldi wrote:
    >
    >>> Not really.
    >>
    >> Ah yes, I see. But anyway: Is there any script available, which totally
    >> blocks any machine trying to log in as user test (e.g.)?
    >>
    >> The discussion about this
    >> (http://seclists.org/lists/fulldisclosure/2004/Jul/1243.html and
    >> http://dev.gentoo.org/~krispykringle/sshnotes.txt) suggests, that there is
    >> more on this than only password guessing ...
    > What would be nice is a script that checks the logs and through IPTABLES
    > blocks multiple login attempts by the same IP.
    > Anyone know of such a script?
    >
    > mc
    Try psad. Not a script but checks your logs and optionally (but not
    recommended by psad) blocks the offender.

    http://www.cipherdyne.com/psad/

    Jos


  • Next message: microcheap: "Re: S: ssh worms FAQ"

    Relevant Pages

    • RE: SP1 Install Errors
      ... I have received your logs files and emails. ... time difference between us, and as you know, SP1 log is a large file and we ... First attempt at executing script sp1_serv_uni.sql failed; ... Microsoft CSS Online Newsgroup Support ...
      (microsoft.public.windows.server.sbs)
    • RE: Domain Startup Scripting
      ... the following command always works and logs the appropriate info ... above which tells me it is accessing the script, ... could help me with troubleshooting a domain startup script routine. ... @echo off ...
      (microsoft.public.windows.server.scripting)
    • Re: Need some problemsolving-cgi/xml
      ... Did you check the server logs to see what ... Have you tested the script at ... > I get a CGI timeout error. ... How can I combine all these xml files/xsl to ...
      (comp.lang.perl.misc)
    • Re: GPO Logon Script that requires AD rights
      ... Preferring not to do this by hand, I whipped up a quick vbs script ... The script will run repeatedly, everytime someone logs on. ... From the shared log file you can create a spreadsheet with the Distinguished Names of each computer and the Distinguished Name of the OU they should be moved into. ... Then you can code a VBScript program to read the values from the final spreadsheet, bind to each OU, and use the MoveHere method to move the computer objects into the correct OU's. ...
      (microsoft.public.scripting.vbscript)
    • METAR REPORTS & PYTHON
      ... to live within a sensible distance from a METAR reporting site. ... The script basically logs onto NOAA FTP and pulls the data in raw format. ... saveout = sys.stdout ...
      (uk.sci.weather)