Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 25 Aug 2005 09:41:33 +0200
From:      peter@bgnett.no (Peter N. M. Hansteen)
To:        freebsd-questions@freebsd.org
Subject:   Re: Illegal access attempt - FreeBSD 5.4 Release - please advise
Message-ID:  <86y86qbh02.fsf@amidala.datadok.no>
In-Reply-To: <200508241119671.SM00756@chris> (Chris St Denis's message of "Wed, 24 Aug 2005 11:18:50 -0700")
References:  <200508241119671.SM00756@chris>

next in thread | previous in thread | raw e-mail | index | archive | help
"Chris St Denis" <chris@aebc.com> writes:

> How can I easily auto deny after x failed attempts? Is this an sshd setting?
> I could find it.
>
> Is there something in ports that will firewall off somebody who is brute
> forcing?

With PF, it's fairly easy to set up with max-src-conn, max-src-conn-rate
overload <tableofbadbuys> in your pass rule.  See pf.conf(5) for
details.  There's probably some magic around to make this doable with
other firewalls as well.

-- 
Peter N. M. Hansteen, member of the first RFC 1149 implementation team
http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/
"First, we kill all the spammers" The Usenet Bard, "Twice-forwarded tales"




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?86y86qbh02.fsf>