3 ms·
Attacks on port 22 end up consuming CPU.
by wildgift 13y ago
Attacks on port 22 end up consuming CPU.
- yeukhon 13y agoand attack on other ports don't?
- riobard 13y agoThe assumption is that bots don't usually scan other ports: way too inefficient for them to scan all ports for every potential target host.
- lotyrin 13y agofail2ban
- danieldk 13y agoAnd now you have another exploitable venue, the log parser of fail2ban ;). Personally, I trust netfilter/iptables' rate limiting more.
- MertsA 13y agoEven better yet is pam_abl. If any IP or user fails authentication faster than a configured rate pam_abl will block logging into that user or any authentication attempts coming from the same IP address and it's all nicely tied into PAM so you don't have to worry about yet another fail2ban vulnerability or someone spoofing some important IP address and tricking your server into blocking it.
- davis_m 13y agoUsing pam_abl to disallow logging into an account that is being hit sounds like a easy way to DoS a box.