Re: www server hit by dictionary attack - suggestions?



On Mon, 05 Dec 2005 15:40:07 +0000, Peter wrote:

>
> Mark McIntyre <markmcintyre@xxxxxxxxxxx> wrote:
>
>>>I am not sure how this would help. The login attempts are all to port 22
>>>which is easily detected with a quick port scan. We can't enable only
>>>specific host IPs because I could be logging in from various locations,
>>>including over GPRS, so the IP could be anything.
>>
>>Enable blocks of IPs, eg your ISP?
>
> If accessing over GPRS, the IP would be that of the GSM network provider.
> Could be anything on the day.
>
> There's a lot of stuff on google under "ssh login attack freebsd" etc. A
> fairly recent problem.

Same gsm provider or multiple? The alternative is to load hosts.deny with
a list of ip addresses from regions that are know to be troublesome. So
unless you have a specific need to allow connections from Korea, Taiwan
and China I have a list of netblocks that you can put in hosts.deny that
willl probably go a long way towards easing your problem. If you want the
list mail me.

--
Regards
Tony
(Take out the garbage to reply)

.



Relevant Pages

  • Re: AIX is slow to login on port 22 and port 23
    ... CPU TID TSLOT PID PSLOT PROC_NAME ... AIX is slow to login on port 22 and port 23 ...
    (AIX-L)
  • Re: SQL2005: Cannot connect error 11001
    ... The famous Windows Firewall (turned on my Server from which I'm trying to ... Exception Details: System.Data.SqlClient.SqlException: Login failed for user ... Try starting the SQL Server ... if you changed the port ...
    (microsoft.public.sqlserver.connect)
  • Re: AIX is slow to login on port 22 and port 23
    ... Memory and I/O wait looks good; but user CPU is REALLY high... ... AIX is slow to login on port 22 and port 23 ...
    (AIX-L)
  • Re: SQL2005: Cannot connect error 11001
    ... Exception Details: System.Data.SqlClient.SqlException: Login failed for user ... Server connection. ... which trusted connection is meant? ... if you changed the port ...
    (microsoft.public.sqlserver.connect)
  • Re: SQL2005: Cannot connect error 11001
    ... user mapped to one database. ... Does the issue has to do with the login account / user ... Server connection. ... if you changed the port ...
    (microsoft.public.sqlserver.connect)