LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-08-2005, 10:01 AM   #1
hlslaughter
Member
 
Registered: May 2003
Location: San Jose, CA
Distribution: Ubuntu
Posts: 47

Rep: Reputation: 15
portsentry replacement? (automated ip address based host blocking)


I haven't used portsentry for a number of years. I remember it doing a very good job at automatically blocking IPs of hosts trying to crack passwords and so on.

I know that basic common sense will prevent 99.9% of hack attempts from doing any damage, but I recently forgot to configure my firewall correctly and got my mysql server hacked. It was a M$ hack, so no harm was done, but It made me realize that I don't always apply common sense

I now only have 3 ports open on my box, only one of which I'm concerned about. Nonetheless, I want to head off attacks with an aggressive access denial policy based on stuff like failed logins and other stuff.

My heart was filled with sadness as I went to the old portsentry site and found that Cisco now owns the domain. I made a cursory attempt to locate portsentry, but I'm sure Cisco probably just wanted their web traffic (or felt they were a threat) and killed off all their products.

What are folks using these days for automatic host blocking via hosts.deny or equiv?

I've seen mentioned something called Guardian, but I wanted to know what other folks are using. Of course, LQ is the only place to go for such information

Thanks in advance
 
Old 08-08-2005, 07:45 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
I believe portsentry is still freeware and you can still download it here. As far as portsentry replacements, take a look at snort-inline and psad
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Website blocking w/ SUSE 9.3/KDE based on groups FrankP1973 Linux - Newbie 1 11-22-2005 02:13 PM
Automated install based off of current machine? MHouse Fedora - Installation 4 06-25-2004 05:28 PM
how to change notification email for portsentry and how to test portsentry roorings Linux - Security 1 11-04-2003 10:36 AM
iptables - blocking a host by MAC address retiem Linux - Security 6 08-29-2003 11:58 AM
Removing PortSentry address blocking ghight Linux - Software 5 02-12-2003 04:03 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:09 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration