Basic hosts.deny Q
rhel 5.7 fully updated,
i havent tried this yet, searched LQ but nothing specific. can i EXCEPT the wildcard keyword ALL ALL: ALL EXCEPT RFC1918, RFC1918, RFC1918 this would make my life easy since i am trying out denyhosts service. my hosts.allow would be empty. i would like to do it this way to outright deny anything that is not internal IP, then allow denyhosts to write (stack) deny entries for any brute forcing of ssh that might happen from internal IP. and yes, i know about iptables. |
The purpose of hosts.allow is to add exceptions to what is specified in hosts.deny. http://its.virginia.edu/unixsys/sec/hosts.html
For techniques for handling brute force attacks on ssh, read the sticky post in this forum. http://www.linuxquestions.org/questi...tempts-340366/ |
Quote:
anyone know the answer to my question about the syntax? |
Perhaps this will help. http://linux.about.com/od/commands/l...l5_hostsde.htm
|
Quote:
|
Did you get down to the EXAMPLES section?
Quote:
|
Quote:
update: ALL: ALL EXCEPT works as expected. with a combo of tcpd, pam, and denyhosts i have a flexible configuration that contains access/auth controls at different levels. |
All times are GMT -5. The time now is 09:51 AM. |