Mailing List ArchiveSupport open source code!
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Login/SSH Scan Detection
- To: tlug@example.com
- Subject: Re: [tlug] Login/SSH Scan Detection
- From: "A.Sajjad Zaidi" <sajjad@example.com>
- Date: Tue, 19 Feb 2002 14:51:55 +0900
- Content-disposition: inline
- Content-type: text/plain; charset=us-ascii
- In-reply-to: <20020218172903.J1556@example.com>
- References: <20020218054708.GA13856@example.com> <Pine.GSO.4.43.0202181530380.4735-100000@example.com> <20020218172554.I1556@example.com> <20020218172903.J1556@example.com>
- Sender: "A.Sajjad Zaidi" <sajjad@example.com>
- User-agent: Mutt/1.3.27i
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Ended up writing a bash script using grep and sed which sleeps for a few seconds and reads in the log file, but is efficient enough. It sends the 'sed'ed, readable output to a keitai, if there is any logging by sshd. It could be annoying (until blocked) if someone tries to be funny, but will do for now. Thanks for the suggestions. - -- A. Sajjad Zaidi System Administrator Technology & Operations Div. Digital Garage Inc. On Mon, Feb 18, 2002 at 05:29:03PM +0900, Matt Doughty wrote: > Never mind that suggestion since it won't work with sshd daemonized. I'm > having a bad reading day. > > --Matt > On Mon, Feb 18, 2002 at 05:25:54PM +0900, Matt Doughty wrote: > > Another option is tcp wrappers. The following is example from the > > man page that mails illegal tftp attempts to root: > > > > /etc/hosts.allow: > > in.tftpd: LOCAL, .my.domain > > > > /etc/hosts.deny: > > in.tftpd: ALL: spawn (/some/where/safe_finger -l @%h | \ > > /usr/ucb/mail -s %d-%h root) & > > > > --Matt > > On Mon, Feb 18, 2002 at 04:23:07PM +0900, ayako kato wrote: -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQE8cef5t1KjqyZ+DQ4RAoMUAKCdcsUtDuHm/hp2x+DuvpgQ+pyh1QCdF0f2 fLQpIJ2QYPqiRu1lVDOSAhM= =zJhZ -----END PGP SIGNATURE-----
- Follow-Ups:
- [tlug] grub vs lilo
- From: YAMAGATA Hiroo
- References:
- [tlug] Login/SSH Scan Detection
- From: A.Sajjad Zaidi
- Re: [tlug] Login/SSH Scan Detection
- From: ayako kato
- Re: [tlug] Login/SSH Scan Detection
- From: Matt Doughty
- Re: [tlug] Login/SSH Scan Detection
- From: Matt Doughty
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Brother MFC-9200J
- Next by Date: [tlug] TLUG webpage
- Previous by thread: Re: [tlug] Login/SSH Scan Detection
- Next by thread: [tlug] grub vs lilo
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links