[Tfug] Throttling SSHD
Ronald Sutherland
rsutherland at epccs.com
Tue Nov 29 20:36:47 MST 2005
This is happening to me also, I've had Linux running for 3 years in my
house without seeing this...
I see it from 209.25.178.53 in my log file, which is full of failed user
names like: arion, arinea, aristidis...
They hit once and then try a new name. I'm, going to look at fail2ban
also... Thanks
Steven Bowers wrote:
> Take a look at fail2ban.
>
> Mike Martinet wrote:
>
>> Hey Folks,
>>
>> A while back, someone wrote in about throttling or filtering IPs which
>> generated numerous bogus login attempts to the ssh daemon. I can't find
>> my copy of that mail - can someone please repost or reply off-list with
>> the instructions for locking out an IP after a certain number of failed
>> logins?
>>
>> This is getting out of hand!
>> unknown (221.165.2.59): 1707 Time(s)
>> root (210.219.251.113): 640 Time(s)
>> unknown (210.219.251.113): 344 Time(s)
>>
>>
>> Thanks,
>>
>>
>> MjM
>>
>> _______________________________________________
>> tfug mailing list
>> tfug at tfug.org
>> http://www.tfug.org/mailman/listinfo/tfug
>>
>
> _______________________________________________
> tfug mailing list
> tfug at tfug.org
> http://www.tfug.org/mailman/listinfo/tfug
>
More information about the tfug
mailing list