Re: SSH scans vs connection ratelimiting

看板FB_security作者時間19年前 (2006/08/22 10:36), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串12/16 (看更多)
Hello! On Sat, 19 Aug 2006, Pieter de Boer wrote: > For months now, we're all seeing repeated bruteforce attempts on SSH. I've > configured my pf install to ratelimit TCP connections to port 22 and to I wonder why OpenSSH still doesn't support simple and nice feature of SSH.COM's sshd2_config: LoginGraceTime 60 AuthInteractiveFailureTimeout 10 These settings effectively cause robots to stop the scan for me. Every scan attempt gives only 1..N failed attempts (where N=number of externally-reachable and SSH-served IPs on machine if robot is capable of simultaneous scan of several IPs), so I can just ignore them. Sincerely, Dmitry -- Atlantis ISP, System Administrator e-mail: dmitry@atlantis.dp.ua nic-hdl: LYNX-RIPE _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #14wcse00 (FB_security)
討論串 (同標題文章)
文章代碼(AID): #14wcse00 (FB_security)