Hope these have not recently been asked (Sourceforge mailing list archives are 500). Trying denyhosts for the first time.
1) Have received 3 "DenyHosts Reports" in the past day - each one containing one ip address (with the corresponding hostname, I enabled lookups). However, there are now over 800 ip addresses in my /etc/hosts.deny. 2) Also, logwatch reports many sshd authentication failures from various hosts, some several hundred times. Am I misunderstanding something basic? I am surprised to see so many failed attempts from the same hosts - my expectation was that once an address goes in /etc/hosts.deny, it would be blocked before it had a chance to make another (or several hundred more) bogus login attempts. Thanks much - hope these are not dumb questions. Peter ------------------------------------------------------------------------- Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to share your opinions on IT & business topics through brief surveys -- and earn cash http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV _______________________________________________ Denyhosts-user mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/denyhosts-user
