sshdfilter

Vladimir G. Ivanovic vladimir at acm.org
Mon Oct 3 16:49:57 UTC 2005


>>>>> "ju" == Jonathan Underwood <j.underwood at open.ac.uk> writes:

    ju> 
    ju> Vladimir G. Ivanovic wrote:
    >> Has anyone ported sshdfilter to FC4? It seems like such a useful
    >> program now that I'm getting lots of ssh-based attacks.
    >> http://www.csc.liv.ac.uk/~greg/sshdfilter/
    >> --- Vladimir
    >> 
    ju> 
    ju> The following provides a similar service:
    ju> 
    ju> http://www.aczoom.com/cms/blockhosts/

I am currently using DenyHosts, but like blockhosts, it is not quite
the same as sshdfilter. sshdfilter parses the output of sshd and uses
iptables to block hosts. Both DenyHosts and blockhosts parse the
system log file and use /etc/hosts.deny to block hosts.

My sense is that sshdfilter's approach is (somewhat) better.

--- Vladimir

Name        : DenyHosts              Relocations: /usr
Version     : 1.1.1                  Vendor: Phil Schwartz <phil_schwartz at users.sourceforge.net>
Release     : python2.4              Build Date: Wed 28 Sep 2005 03:50:13 PM PDT
Install Date: Sun 02 Oct 2005 10:59:58 AM PDT      Build Host: soil
Group       : Development/Libraries  Source RPM: DenyHosts-1.1.1-python2.4.src.rpm
Size        : 209002                 License: GPL
Signature   : (none)
URL         : http://denyhosts.sourceforge.net
Summary     : DenyHosts is a utility to help sys admins thwart ssh hackers
Description :

DenyHosts is a python program that automatically blocks ssh attacks by
adding entries to /etc/hosts.deny. DenyHosts will also inform Linux
administrators about offending hosts, attacked users and suspicious
logins. 

-- 
Vladimir G. Ivanovic
Palo Alto, CA 94306
+1 650 678 8014




More information about the fedora-list mailing list