Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 5 Dec 1999 22:32:23 -0800 (PST)
From:      Brian Feldman <green@FreeBSD.org>
To:        cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org
Subject:   cvs commit: ports/security/openssh Makefile ports/security/openssh/patches patch-ap patch-aq patch-ar patch-an patch-ao
Message-ID:  <199912060632.WAA71815@freefall.freebsd.org>

next in thread | raw e-mail | index | archive | help
green       1999/12/05 22:32:23 PST

  Modified files:
    security/openssh     Makefile 
    security/openssh/patches patch-an patch-ao 
  Added files:
    security/openssh/patches patch-ap patch-aq patch-ar 
  Log:
  In the meantime (while things are being worked and decided on on the
  OpenBSD OpenSSH front), add ConnectionsPerPeriod to prevent DoS via
  running the system out of resources.  In reality, this wouldn't
  be a full DoS, but would make a system slower, but this is a better
  thing to do than let the system get loaded down.
     So here we are, rate-limiting.  The default settings are now:
  Five connections are allowed to authenticate (and not be rejected) in
  a period of ten seconds.
  One minute is given for login grace time.
     More work in this area is being done by alfred@FreeBSD.org and
  markus@OpenBSD.org, at the very least.  This is, essentially, a
  stopgap solution;  however, it is a properly implemented and documented
  one, and has an easily modifiable framework.
  
  Revision  Changes    Path
  1.29      +3 -3      ports/security/openssh/Makefile
  1.5       +134 -15   ports/security/openssh/patches/patch-an
  1.4       +8 -5      ports/security/openssh/patches/patch-ao



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe cvs-all" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199912060632.WAA71815>