4 ms·
I've never been a fan of shunning/blocking ip-addresses based on number of wrong passwords. It's to easy to exploit as denial-of-service attack and can be used
by np422 13y ago
I've never been a fan of shunning/blocking ip-addresses based on number of wrong passwords. It's to easy to exploit as denial-of-service attack and can be used to lock out legitimate users.
Possibly use a non-standard ssh port, make sure you disable ssh v1 and apply a password policy, allow password logins only for white listed users. Now you should be reasonably safe against brute force attacks and still have a system that is accessible.
If/when you disable root logins through ssh, try to have another way to login as root - maybe a console/kvm switch, prefferably with remote access through a secure network.
- zokier 13y ago> It's to easy to exploit as denial-of-service attack and can be used to lock out legitimate users. Could you explain what's the "easy" way to DoS using fail2ban(or equivalent system)?
- elktea 13y agoThere's still a lot of ISPs that don't follow BCP-38 so source address IP spoofing is easy enough
- zokier 13y agoSSH is TCP based, you need two-way handshake to construct the connection. Source address spoofing gets you only half-way there.
- bostik 13y agoUnless your server's TCP stack has SYN-cookies enabled (and I think most do): http://www.jakoblell.com/blog/2013/08/13/quick-blind-tcp-connection-spoofing-with-syn-cookies/ http://www.jakoblell.com/blog/2013/08/13/quick-blind-tcp-con... Law of unintended consequences strikes again.