login
Header Space

 
 

Re: SSH brute force attacks no longer being caught by PF rule

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Stuart Henderson <stu@...>, OpenBSD <misc@...>
Date: Monday, August 13, 2007 - 7:51 am

----- Original Message ----- 
From: "Stuart Henderson" <stu@spacehopper.org>
To: "OpenBSD" <misc@openbsd.org>
Sent: Monday, August 13, 2007 1:30 PM
Subject: Re: [misc] SSH brute force attacks no longer being caught by PF 
rule




maybe somewhat off-topic, but:
why don't you just switch your ssh port to a different one.
we've been running with this configuration since years and
a log examination of the ssh-logs and connection logs from
the firewall shows that there was not even 1 (!) connect to
the ssh-port from "bad" IPs.
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: SSH brute force attacks no longer being caught by PF rule, no@spam@mgedv.net, (Mon Aug 13, 7:51 am)
Re: SSH brute force attacks no longer being caught by PF rule, Stuart Henderson, (Mon Aug 13, 8:25 am)
speck-geostationary