Blocking SSH Brute-Force Attacks: What Am I Doing Wrong?

Erik Norgaard norgaard at locolomo.org
Tue Nov 14 23:24:02 UTC 2006


Peter N. M. Hansteen wrote:
> Erik Norgaard <norgaard at locolomo.org> writes:
> 
>> Honestly, I wouldn't worry about it: review your config and make some 
>> simple choices to reduce the noise, see this article:
> 
> One other noise reduction method which is really easy to implement is
> to use pf and write arule set which to uses the overload feature, see
> eg http://home.nuug.no/~peter/pf/en/bruteforce.html (part of my
> EuroBSDCon and other places tutorial).
> 
> See http://home.nuug.no/~peter/pf/ for a choice of formats and languages.
> 
Neat!

Thanks, Erik

-- 
Ph: +34.666334818                      web: http://www.locolomo.org
X.509 Certificate: http://www.locolomo.org/crt/8D03551FFCE04F0C.crt
Key ID: 69:79:B8:2C:E3:8F:E7:BE:5D:C3:C3:B1:74:62:B8:3F:9F:1F:69:B9


More information about the freebsd-questions mailing list