Note to LEAF users on ssh logins

Brian Reichert reichert at numachi.com
Thu Mar 3 06:22:01 PST 2005


On Thu, Mar 03, 2005 at 03:14:41PM +0100, Simon 'corecode' Schubert wrote:
> On 03.03.2005, at 14:35, Joerg Sonnenberger wrote:
> >> * Detects failed ssh login attempts and maps out the originating IP
> >> * using IPFW.
> >Someone wants to write a nice PF version? It should just add the IP to
> >a table :)
> 
> collaborative ssh scan firewalling with a distributed database? *ducks*

I've heard assertions that the DROP list is good for cutting down
on 'improper' web/ssh connections.  I haven't correlated with my
own logs, so I can't offer more details:

  <http://www.spamhaus.org/drop/index.lasso>

-- 
Brian Reichert				<reichert at xxxxxxxxxxx>
37 Crystal Ave. #303			Daytime number: (603) 434-6842
Derry NH 03038-1713 USA			BSD admin/developer at large	





More information about the Users mailing list