Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Script Kiddy Defence Script
- Date: Thu, 9 Jun 2005 19:11:44 +0900 (JST)
- From: Joe Larabell <larabell@???>
- Subject: Re: [tlug] Script Kiddy Defence Script
- References: <20050607225949.2fd16669@example.com><20050608094344.91802.qmail@example.com> <20050608191147.613e42b4@example.com><Pine.LNX.4.51.0506091759390.4420@example.com> <20050609093900.GA74220@example.com><20050609190505.1d9531dd@example.com>
> Well, I don't see many IPs attacking twice, and the ssh-attacks normally > only take a short time, maybe several minutes. > > So what I wanted to do was to lock out any attacker as soon as possible Yeah... I figure the duration of the attack from a single IP would only be the time it takes for them to try the dozens (100s) of dummy accounts. But it gives me a great idea... If you write a simple C program to grab the IP of whoever logs in and add it to the SHITLIST chain, you could swap that executable for the '/bin/false' in /etc/passwd, then add several of the default accounts with the password set the same as the username (or not set at all). As soon as the miscreant attempts to login, his IP is added to the banned list. The drawback would be that other non-shell paths into the system might then be made more vulnerable to an attack via those dummy accounts. -- Joe Larabell -- Synopsys VCS Support US: larabell@example.com http://wwwin.synopsys.com/~larabell/ Japan: larabell@?jp
- Follow-Ups:
- Re: [tlug] Script Kiddy Defence Script
- From: Michael Reinsch
- References:
- [tlug] Script Kiddy Defence Script
- From: Michael Reinsch
- Re: [tlug] Script Kiddy Defence Script
- From: Nguyen Hung Vu
- Re: [tlug] Script Kiddy Defence Script
- From: Michael Reinsch
- Re: [tlug] Script Kiddy Defence Script
- From: Joe Larabell
- Re: [tlug] Script Kiddy Defence Script
- From: Shawn
- Re: [tlug] Script Kiddy Defence Script
- From: Michael Reinsch
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Script Kiddy Defence Script
- Next by Date: Re: [tlug] Script Kiddy Defence Script
- Previous by thread: Re: [tlug] Script Kiddy Defence Script
- Next by thread: Re: [tlug] Script Kiddy Defence Script
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links