LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 09-16-2005, 08:49 PM   #1
Setheck
LQ Newbie
 
Registered: Jul 2004
Location: Seattle
Posts: 25

Rep: Reputation: 15
SSHD config question


Does anyone know how if there is a certain way of configuring sshd so that after x failed login attempts from the same IP addres it will block the IP address entirely?

Thanks,
Seth
 
Old 09-16-2005, 09:25 PM   #2
Snowbat
Member
 
Registered: Jun 2005
Location: q3dm7
Distribution: Mandriva 2010.0 x86_64
Posts: 338

Rep: Reputation: 31
Netfilter/iptables. See http://blog.andrew.net.au/2005/02/17
 
Old 09-17-2005, 07:38 AM   #3
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422
Of course another alternative to to move to key-based authentication and eliminate usernames and passwords altogether. If you do want to stick with usernames and passwords, make sure the passowrds are strong and I would definitely use the AllowUsers directive in your sshd config file to limit which users can access via ssh.
 
Old 09-17-2005, 07:04 PM   #4
Setheck
LQ Newbie
 
Registered: Jul 2004
Location: Seattle
Posts: 25

Original Poster
Rep: Reputation: 15
I am staying with username/passwords because i want to be able to log in from anywhere even if i don't have an rsa key with me. my passwords are strong but i keep getting HUGE dictionary attacks from china/korea/etc. i keep blocking the IPs but they just keep coming.
 
Old 09-18-2005, 08:44 AM   #5
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422
And their going to keep coming. At best, blocking IP addresses gives your log system some temporary relief. Security wise, it probably isn't doing anything to substantially improve things. However there is a project aimed at doing what you want.

Quote:
I am staying with username/passwords because i want to be able to log in from anywhere even if i don't have an rsa key with me.
This one is easy. I have a USB thumb drive with the needed software (both Windows and Linux) and keys. As long as you don't lose the USB drive, it works well.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
sshd config saavik Linux - Security 2 09-21-2005 02:17 AM
How to change ssh banner in sshd.config pAn1k Linux - Networking 2 03-24-2005 04:46 PM
alternate config file for sshd w/ RH EL3 kmitz Linux - Security 1 01-13-2005 04:46 PM
sshd/ssh config for local forwarding ewlnxnewB Linux - Networking 2 11-04-2003 02:09 PM
I can't make sshd like my config file Travis86 Linux - Networking 5 07-28-2003 09:23 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 08:11 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration