HowtoForge: Preventing SSH Dictionary Attacks With DenyHosts
Feb 22, 2006, 05:30 (3 Talkback[s])
(Other stories by Falko Timme)
[ Thanks to Falko
Timme for this link. ]
"In this HowTo I will show how to install and configure
DenyHosts. DenyHosts is a tool that observes login attempts to SSH,
and if it finds failed login attempts again and again from the same
IP address, DenyHosts blocks further login attempts from that IP
address by putting it into /etc/hosts.deny. DenyHosts can be run by
cron or as a daemon. In this tutorial I will run DenyHosts as a
daemon..."
Complete Story
Related Story:
BindView
advisory: sshd remote root (bug in deattack.c)(Feb 09,
2001)