On Fri, May 06, 2005 at 01:47:06PM -0300, Claudinei Matos wrote: > I have a lot of connection attempts in my ssh server. I've take a look > at sshd_config man pages but I didn't found a way to deny the source > ip of the attempts by 5 minutes (i.e.) if this ip can't login after 5 > attempts (i.e.). Is there a way to do this?
Use a perl utility called "sshd_sentry": http://linuxmafia.com/pub/linux/security/sshd_sentry/ It will allow you to block the hosts which abuse your sshd. Additionally, please consider mailing abuse@ the sending ISP, especially if it is in an English speaking country. Usually they care that one of their machines is probing for vulnerabilities. -D -- /--------------- - - - - - - | Dan Noe, freelance hacker | http://isomerica.net/
pgpBGtnSJG5qW.pgp
Description: PGP signature
