[nlug] Re: Bruteforce attack on my sshd

2009-03-05 Thread Chris McQuistion
We used to use some little homebrew project called bfd (brute force detection) that would basically check the logs every 10 minutes, see if there were a lot of invalid logins from a particular IP and then automatically create a firewall rule to drop all packets from that IP. This would remain in

[nlug] Re: Bruteforce attack on my sshd

2009-03-05 Thread Jonathan Moore
On Thu, Mar 5, 2009 at 1:03 PM, karlhaines k...@nashvilleproweb.com wrote: I had this problem before and someone suggested an easy fix, some little app I installed to block these guys, who has a better memory than me that could point me to that app again?? Thanks. I really like fail2ban

[nlug] Re: Bruteforce attack on my sshd

2009-03-05 Thread Sabuj Pattanayek
On Thu, Mar 5, 2009 at 1:03 PM, karlhaines k...@nashvilleproweb.com wrote: I had this problem before and someone suggested an easy fix, some little app I installed to block these guys, who has a better memory than me that could point me to that app again?? Thanks. iptables can do it too: