Re: IPTABLES question

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Le mardi 18 juillet 2006 à 15:00 -0500, Michael Yep a écrit :
> I have been blocking some IPs because they are brute forcing my ssh
> port. I access this server from many different places so I cant really
> just add a few hosts.
> I'm talking about 36000 attempts in a short time from some IP addresses

pam_abl (in extras) will work for you

The good thing is it works at the pam level and not by parsing logs
retroactively like denyhosts. So they can do their attempts in whatever
short time they want they'll get blacklisted anyway. And every pam-using
service is protected.

The bad thing is it works at the pam level, it won't interface with
iptables like denyhost so even if it's blocking something you'll still
pay some processing time. However I rather like the fact the bad guys
have no way to know they are blocked (unlike a firewall-level solution)
so they can't optimise attacks by giving up on hosts which have detected
them.

Of course if you never change your passwords and want to allow ssh
logins from everywhere a low-intensity distributed brute-force attack is
going to get you regardless of the solution used. But I don't think
crackers are that deseperate (yet)

-- 
Nicolas Mailhot

Attachment: signature.asc
Description: Ceci est une partie de message =?ISO-8859-1?Q?num=E9riquement?= =?ISO-8859-1?Q?_sign=E9e?=

-- 
fedora-list mailing list
fedora-list@xxxxxxxxxx
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
[Index of Archives]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora Magazine]     [Fedora News]     [Fedora Summer Coding]     [Fedora Laptop]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [SSH]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Gnome Users]     [KDE Users]     [Fedora Art]     [Fedora Docs]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Libvirt Users]     [Fedora ARM]

  Powered by Linux