This is TikiWiki v1.9.7 -Sirius- © 2002–2005 by the Tiki community. Thu 09 of Sep, 2010 [13:30 UTC]
  add
Menu [hide]

Viewing blog post - Network Security

Return to blog

denyhosts -- almost best thing since sliced bread

posted by TaneliOtala on Thu 19 of Nov, 2009 [07:25 UTC]
Denyhosts

Almost too good to be true...

What's good, is that it allows you to get almost rid of dictionary attacks on your SSH port...

What's not so good, is that as of recent, the dictionary attacks on POP3, IMAP4, TELNET, FTP are significantly on the rise... and Denyhosts does not make it particularly easy to block the other protocols...

If I manage to get the other protocols blocked, I'll publish the regex'es for those.

Meanwhile, if you notice it in your log files, rememember that:

iptables -A INPUT -s x.x.x.x -j DROP

always works....


Permalink (referenced by: 0 posts references: 0 posts) print email this post