Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 05 Jan 2007 09:46:27 +0100
From:      peter@bsdly.net (Peter N. M. Hansteen)
To:        freebsd-questions@freebsd.org
Subject:   Re: sshd break-in attempt
Message-ID:  <87ejq9kgik.fsf@thingy.datadok.no>
In-Reply-To: <459A5A45.4080309@wmptl.com> (Nathan Vidican's message of "Tue, 02 Jan 2007 08:12:37 -0500")
References:  <459A5A45.4080309@wmptl.com>

next in thread | previous in thread | raw e-mail | index | archive | help
Nathan Vidican <nvidican@wmptl.com> writes:

>  of attempts). Anyhow, long story short; is there not an easy way to
> make sshd block or deny hosts temporarily if X number of invalid
> login attempts are made within a minute's time? 

if you use pf, it's fairly straightforward with an overload rule, see eg
http://home.nuug.no/~peter/pf/en/bruteforce.html

Cheers,
-- 
Peter N. M. Hansteen, member of the first RFC 1149 implementation team
http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/
"First, we kill all the spammers" The Usenet Bard, "Twice-forwarded tales"
Dec 22 02:13:59 delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?87ejq9kgik.fsf>