Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [tlug] attack via ssh? (don't panic :-P)



Stuart Luppescu wrote:
  > I'm really interested. I get these at least once a day. If I notice it
> on root-tail, I add the originating IP address to my set of iptables
> rules to block. I have had PasswordAuthentication set to no
> in /etc/ssh/sshd_config, but it doesn't seem to have any effect. :-<

At one point I got tired of adding addresses to the firewall script and 
just moved sshd to a non-standard port. Not a real solution, but helps. 
My 'secure' log is now clean :) You may also want to limit the users 
that can login via ssh by user/group. That cuts the connection before 
any authentication checks are made.


Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links