Attacks on ssh port

Peter Radcliffe pir at pir.net
Sat Sep 18 15:28:21 PDT 2004


Willem Jan Withagen <wjw at withagen.nl> probably said:
> I also have portsentry in a rather sensitive mode doing exactly the same 
> thing.
> Trigger one of  the "backdoor" ports, and you're out of my game.

The general problm with this type of reactive filtering is that if
someone can spoof the source addresses effectively or cause a connection
from a legitimate host you've just DoSed yourself...

Personally I only allow ssh from known legitimate sources and block the
rest so the "noise" is in a completely different list.

P.

-- 
pir



More information about the freebsd-security mailing list