Note to LEAF users on ssh logins
    Brian Reichert 
    reichert at numachi.com
       
    Thu Mar  3 06:22:01 PST 2005
    
    
  
On Thu, Mar 03, 2005 at 03:14:41PM +0100, Simon 'corecode' Schubert wrote:
> On 03.03.2005, at 14:35, Joerg Sonnenberger wrote:
> >> * Detects failed ssh login attempts and maps out the originating IP
> >> * using IPFW.
> >Someone wants to write a nice PF version? It should just add the IP to
> >a table :)
> 
> collaborative ssh scan firewalling with a distributed database? *ducks*
I've heard assertions that the DROP list is good for cutting down
on 'improper' web/ssh connections.  I haven't correlated with my
own logs, so I can't offer more details:
  <http://www.spamhaus.org/drop/index.lasso>
-- 
Brian Reichert				<reichert at xxxxxxxxxxx>
37 Crystal Ave. #303			Daytime number: (603) 434-6842
Derry NH 03038-1713 USA			BSD admin/developer at large	
    
    
More information about the Users
mailing list