Scripted SSH Attacks

Discussion in 'Site & Server Administration' started by nevetS, Jan 11, 2005.

  1. #1
    Going through my logs yesterday, I see that one computer is repeatedly trying to log on via ssh. Over and over and over again with various guessed logins.

    Is there any way that you guys know of to just have ssh deny an IP address?
     
    nevetS, Jan 11, 2005 IP
  2. crazyhorse

    crazyhorse Peon

    Messages:
    1,137
    Likes Received:
    19
    Best Answers:
    0
    Trophy Points:
    0
    #2
    crazyhorse, Jan 11, 2005 IP
  3. J.D.

    J.D. Peon

    Messages:
    1,198
    Likes Received:
    65
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Can't you just configure your firewall to block this IP range?

    J.D.
     
    J.D., Jan 11, 2005 IP
  4. bLaDeY

    bLaDeY Guest

    Messages:
    48
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #4
    You could use something like the following in your /etc/hosts.allow

    sshd: 172.17.12.0/255.255.255.0

    should you need to access from another location simply add that on another line.

    and then in your /etc/hosts.deny put
    ALL:ALL

    If your using IP tables you can ban an IP range along with most other firewall applications.
     
    bLaDeY, Jan 11, 2005 IP