LWN.net Logo

Brute-Force SSH Server Attacks Surge (InformationWeek)

Brute-Force SSH Server Attacks Surge (InformationWeek)

Posted May 14, 2008 16:05 UTC (Wed) by einstein (subscriber, #2052)
Parent article: Brute-Force SSH Server Attacks Surge (InformationWeek)

All the distros I've used lately don't allow ssh connections by default, I have to explicitly
enable sshd.

I don't bother with the overhead of iptables rules, I simply define a restrictive set of IPs
allowed to connect to sshd, via hosts.allow, and pare down the list of allowed ssh users, via
sshd_config, to the one or two who actually have a need to do so. For more security, I disable
password logins and require ssh keys to log in.

Every morning the syslog is full of new entries chronicling unsuccessful ssh login attempts.
Haha, suckers - knock yourself out!


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds