Re: inbound ssh ceased on 4 servers at same time

From: Marcin Jessa (lists_at_yazzy.org)
Date: 06/09/05

  • Next message: Steve Rieger: "Re: serial ata raid"
    Date: Thu, 9 Jun 2005 15:38:56 +0200
    To: john@day-light.com
    
    

    Hi John, guys.

    On Sat, 4 Jun 2005 13:14:28 -0500
    "John Brooks" <john@day-light.com> wrote:

    > Thanks, sounds good to do on the outward facing firewall. These
    > four freebsd boxes are protected behind an openbsd firewall so
    > none of the brute-force sshd attacks have ever reached them.

    How do you filter those brute-force attacks?
    Do you check existence of users on the actual server running sshd ?
    I get hundreds of those attacks every day.

    Cheers,
    Marcin Jessa.
    _______________________________________________
    freebsd-isp@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"


  • Next message: Steve Rieger: "Re: serial ata raid"

    Relevant Pages

    • Re: A moderated forum: inconsistent with my Liberal principles
      ... on the new group - it seems obvious some have checked out the other group with their opinions already firmly fixed. ... It's as if some can't understand the concept of a group without personal insults or attacks. ... there is no 'filter'. ...
      (rec.music.classical.recordings)
    • Re: IDS event filtering
      ... > I am wanting to get an idea of what you guys out there filter from your ... > IDS sensors. ... Some customers simply don't want to be told ... I think it's fair to say that most attacks happen over TCP, and, given the ...
      (Focus-IDS)
    • Re: Linux 2.4.27 SECURITY BUG - TCP Local and REMOTE(verified) Denial of Service Attack
      ... Which attacks, and what could be done about them? ... You just filter ICMP packets, in the way RST packets are already ... The rate limit for RST processing on ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)
    • RE: [fw-wiz] medical records, web server, & stateful firewall vs packet filter
      ... Maybe a simple packet filter would be ... less prone to DoS ... > firewall device like a PIX or ASA 5500 would offer better overall ... I think you're off-target to be worrying about DoS attacks over attacks that ...
      (Firewall-Wizards)
    • Re: Well well well
      ... but you're just using words without knowing what they ... When you get proved wrong you add me to your filter. ... responses in one case, and he thinks OTHER folks are fanatical? ... Wingnut, you INVITE attacks. ...
      (alt.sports.football.pro.ne-patriots)