4 ms·
If anything, you're doing them a (miniscule) favor by keeping them from wasting more resources on failed login attempts. If you really hated them, you'd set up
by Cpoll 3y ago
If anything, you're doing them a (miniscule) favor by keeping them from wasting more resources on failed login attempts. If you really hated them, you'd set up a honeypot.
- diggan 3y agoMore fun: setup a fail2ban actionban script that instead of banning the IP, shapes the traffic coming from it to have abysmal bandwidth so requests/responses takes really long time, so they'll have to timeout instead of getting failures.
- Tijdreiziger 3y agoThis is known as tarpitting, and apparently iptables can do it: https://en.wikipedia.org/wiki/Tarpit_%28networking%29 https://en.wikipedia.org/wiki/Tarpit_%28networking%29
- nvy 3y agoThis is hilarious
- diggan 3y agoNeat, didn't know that! Think before I've used Traffic Control (tc) for it, but iptables would be simpler. Available in `xtables-addons` it seems. After install: iptables -A INPUT -p tcp -s $SOURCE_IP -j TARPIT # add IP to tarpit iptables -D INPUT -p tcp -s $SOURCE_IP -j TARPIT # remove IP from tarpit