  • SSH Shut Out
    04/05/2007 5:49PM
    We're getting hit by ssh dictionary attacks much more frequently now.

    I just installed a daemon called "SShutOut" available from http://www.techfinesse.com/sshutout/sshutout.html.
    It's very quick to install and runs in the background to monitor the /var/log/messages file for excessive failed login attempts from a given IP address. If a configurable threshold is reached, it uses iptables to block the offender for a configurable period of time.