Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 6 May 2008 09:31:15 -0800
From:      Beech Rintoul <beech@freebsd.org>
To:        freebsd-questions@freebsd.org
Cc:        Gilles <gilles.ganault@free.fr>
Subject:   Re: [SSHd] Increasing wait time?
Message-ID:  <200805060931.18936.beech@freebsd.org>
In-Reply-To: <q7412457qoumm8v8dbth10fug2ctbrlfp0@4ax.com>
References:  <q7412457qoumm8v8dbth10fug2ctbrlfp0@4ax.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Tuesday 06 May 2008, Gilles said:
> Hello
>
> I'm a bit tired of people trying to break into SSH:
>
> May  6 16:59:23 freebsd sshd[24649]: Invalid user agatha from
> 195.43.9.246
> May  6 16:59:26 freebsd sshd[24651]: Invalid user cristie from
> 195.43.9.246
> May  6 16:59:29 freebsd sshd[24653]: Invalid user number from
> 195.43.9.246
> May  6 16:59:31 freebsd sshd[24655]: Invalid user chamber from
> 195.43.9.246
> etc.
>
> Is there a way to configure SSHd, so that the wait time between
> login attempts increases after X failed tries?
>
> Thank you.

Not that I know of. You should look into denyhosts (in the ports) it 
works well and even has a RBL feature to block some of these script 
kiddies proactively. Unfortunately, these attempts have become a fact 
of life. I probably get 20 - 30 attempts a day between my various 
servers.

Beech


-- 
---------------------------------------------------------------------------------------
Beech Rintoul - FreeBSD Developer - beech@FreeBSD.org
/"\   ASCII Ribbon Campaign  | FreeBSD Since 4.x
\ / - NO HTML/RTF in e-mail   | http://www.freebsd.org
 X  - NO Word docs in e-mail | Latest Release:
/ \  - http://www.FreeBSD.org/releases/7.0R/announce.html
---------------------------------------------------------------------------------------






Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200805060931.18936.beech>