[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: SSH scans vs connection ratelimiting



Take a look at /usr/ports/security/bruteforceblocker. It monitors the system log for failed ssh logins, and blocks the sites via pf. It's reasonably configurable, and works very well. I've been running it for months without trouble.

Note that it lets you whitelist specific hosts to prevent against someone DOSing you by forging your IP address.

--lyndon
_______________________________________________
freebsd-security_(_at_)_freebsd_(_dot_)_org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe_(_at_)_freebsd_(_dot_)_org"


Visit your host, monkey.org