[BUGS] Constant SSH login spam

Joshua Bromfield joshua.bromfield at gmail.com
Mon Feb 4 10:44:26 EST 2008


Hey Jerahmy,

I had 12,000 logins over one weekend just a month or so ago.

I installed: http://denyhosts.sourceforge.net/

Since then I have had absolutely no activity whatsoever.

Hope that helps.

JB.

On Feb 4, 2008 9:42 AM, Bernie Maier <bugs at lists.blurk.net> wrote:

> I'm another one who agrees with this:
>
> Peter Jeremy:
>
> > If it's annoying you, I suggest you move your sshd to a different
> > port and either block port 22 [...]
>
> FWIW I've been doing this for a few years now, so I don't know if attack
> frequency has increased recently.  All I know is that I was getting so
> many port 22 login attempts that I realised I'd never see any real threat
> in all the noise, so I simply switched ports.  Then, when eventually work
> tightened up its own policies and stated they would only allow SSH
> outbound
> on port 22, I just set up a firewall rule to allow only work's IP address
> to connect via port 22.
>
> Cheers,
>
>    Bernie
>
> _______________________________________________
> BUGS mailing list
> BUGS at bugs.au.freebsd.org
> http://mailman.barnet.com.au/mailman/listinfo/bugs
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mailman.barnet.com.au/pipermail/bugs/attachments/20080204/5c998180/attachment-0001.html 


More information about the BUGS mailing list