Re: Reality check: IPFW sees SSH traffic that sshd does not?

看板FB_security作者時間19年前 (2007/03/21 22:18), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串5/14 (看更多)
On Wed, Mar 21, 2007 at 09:27:24AM -0400, Bill Moran wrote: > Not in my opinion. I run a little script I wrote that automatically adds > failed SSH attempts to a table that blocks them from _everything_ in my > pf rules. I figure if they're fishing for weak ssh passwords, their next > likely attack route might be HTTP or SMTP, so why wait. This is on my > personal server. Here where I work, we're even more strict. I had a similar set up, but it was quite clunky. Following advise from this list and others I now firewall port 22 to a few locations (e.g. work), and also run ssh on a high port. This doesn't necessarily make things any safer, but has reduced my log noise drastically. Regards, Richard Jones -- http://www.jonze.com _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #160Jx300 (FB_security)
討論串 (同標題文章)
完整討論串 (本文為第 5 之 14 篇):
文章代碼(AID): #160Jx300 (FB_security)