New User? Register here - Existing Users: Username: Password: [Advanced Login]

 

 

Current Poll

Your preferred Interactive shell?









( 1358 votes ~ 15 comments )

 

Weblog entry #169 for ajt

203.171.236.172
Posted by ajt on Fri 24 Jul 2009 at 22:14
Tags: none.

Some Tw*t Head using a box currently on IP 203.171.236.172 has (unsuccessfully) been trying to SSH to my box all evening. It's annoying now as they are clogging up my root messages. They can't get in as I have SSH turned off on at the moment but I have iptables set to log anyone trying to get in...

 

Comments on this Entry

Posted by Anonymous (81.5.xx.xx) on Sat 25 Jul 2009 at 08:09
denyhosts or fail2ban is useful. personally I always move ssh (even internally) onto non-standard ports in case there is a security hole in ssh. I was being paranoid apparently. Until the weak key fiasco happened...

Adrian

[ Parent | Reply to this comment ]

Posted by ajt (195.145.xx.xx) on Mon 27 Jul 2009 at 08:51
[ Send Message | View Weblogs ]

I've considered fail2ban and denyhosts in the past. In the current situation neither are a perfect match as the firewall is on one system and the SSH server is on another... I really should look at a way of integrating them somehow though.

--
"It's Not Magic, It's Work"
Adam

[ Parent | Reply to this comment ]

Posted by Alucard (24.61.xx.xx) on Sat 25 Jul 2009 at 16:42
[ Send Message | View Weblogs ]
Uh OK so block it? What's the problem?

[ Parent | Reply to this comment ]

Posted by ajt (195.145.xx.xx) on Mon 27 Jul 2009 at 08:47
[ Send Message | View Weblogs ]

It is blocked, in fact SSH was turned off so it was impossible to get in at all, however the annoyance is that it clogs up the logs.

--
"It's Not Magic, It's Work"
Adam

[ Parent | Reply to this comment ]

Posted by Anonymous (195.80.xx.xx) on Tue 4 Aug 2009 at 10:50
Stop logging?

But seriously I use IPTables with fail2ban adding IP's to the block rules, which just logs the IP and how long it's going to get blocked, I no longer bother logging the IP's denyed packets as they can get to be very big logs which filled the disk. You might want to log each packet deny if you want but I don't.

Paul

[ Parent | Reply to this comment ]

Posted by ajt (195.112.xx.xx) on Tue 4 Aug 2009 at 21:29
[ Send Message | View Weblogs ]

I probably should stop the logs, but I should also glue together a file2ban script first...

--
"It's Not Magic, It's Work"
Adam

[ Parent | Reply to this comment ]

 

 

Flattr