Re: SSH Brute Force attempts

From: <sk_at_elegosoft.com>
Date: Tue, 7 Oct 2008 03:14:31 +0200 (CEST)
> sk_at_elegosoft.com wrote:
 mornin'

>  Rich Healey wrote:
> Recently I'm getting a lot of brute force attempts on my server, in
> the past I've used various tips and tricks with linux boxes but many of
> them  were fairly linux specific.

> disable pasword authentication OR use very strong passwords (24 chars)
> OR use OTP
>> if it is applicable you could limit access by hosts (from=)
>> nothing of the above is linux or BSD specific

>> btw. Software to delay Login Attempts could be tricked.
> Which software? how?

I was talking fail2ban
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4321
http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=denyhosts


regards
Stefan
Received on Mon Oct 06 2008 - 23:14:41 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:39:36 UTC