On Wed, Apr 20, 2005 at 08:57:23AM +1000, Paul Dwerryhouse wrote:
> On Tue, Apr 19, 2005 at 11:20:01AM +0200, Gottfried Szing wrote:
> > what i want to achieve is to detect failed logins via SSH (e.g. with a
> > limit of 3 attempts within one minute) and to drop/deny packages from the
> > source IP via iptables for about one hour.
> 
> You can do this with the iptables 'ipt_recent' module.
How does it determine between good ssh packets and bad ssh packets ?

> 
> Have a look at the docs here:
> 
> http://snowman.net/projects/ipt_recent/
> 
> Cheers,
> 
> Paul.
> 
> 
> -- 
> Paul Dwerryhouse                              | PGP Key ID: 0x6B91B584
> -- 
> SLUG - Sydney Linux User's Group Mailing List - http://slug.org.au/
> Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html
> 

Attachment: signature.asc
Description: Digital signature

-- 
SLUG - Sydney Linux User's Group Mailing List - http://slug.org.au/
Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html

Reply via email to