Dark_Matter Posted October 21, 2005 CID Share Posted October 21, 2005 On one of my dedicated boxes i was getting brute force attacks on port 22 on my ssh server. I monitored the attacks for a few days as i have Access Control enabled for my ssh server so only the shell users i define can login anyway. I even went as far as restricting shell logins to a signle ip on my box instead of allowing shell logins on all ips. Thus far my added measures have stoped the attacks dead. My real question is for the other g33ks here that own dedicated boxes have you noticed or ever had any ssh brute force attacks. Do any of you even check your logs? Just anxious to see how wide an issue this might be. Quote Link to comment Share on other sites More sharing options...
Dark_Matter Posted October 22, 2005 Author CID Share Posted October 22, 2005 Found a nice program that also deals with this issue. http://www.csc.liv.ac.uk/~greg/sshdfilter/ Also an article on the issue of SSH Brute Force Attacks. http://it.slashdot.org/article.pl?sid=05/07/16/1615233&from=rss Quote Link to comment Share on other sites More sharing options...
lorne Posted October 22, 2005 CID Share Posted October 22, 2005 I have had them on my box but as usual they were unsuccesful. Brute force attacks like that are generally done by people that don't know what they are doing. The people you have to worry about are the ones that don't show up in the logs Quote Link to comment Share on other sites More sharing options...
Dark_Matter Posted October 22, 2005 Author CID Share Posted October 22, 2005 This is so true. ehhhh Quote Link to comment Share on other sites More sharing options...
ghostmaster Posted October 22, 2005 CID Share Posted October 22, 2005 A professor of mine wrote an adaptive firewall program for his SSH box that will detect a brute force attack and block the attacking IP address. I think he distributes it through GPL. Quote Link to comment Share on other sites More sharing options...
Dark_Matter Posted October 22, 2005 Author CID Share Posted October 22, 2005 very nice if you would care to send me in the direction of this tool/program feel free. Quote Link to comment Share on other sites More sharing options...
humorman Posted October 22, 2005 CID Share Posted October 22, 2005 Me to I would like this program please. I just got a new box and need it thanks. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.