empoweri
07-14-2002, 02:40 PM
This is something new I haven't seen before, a DOS attack with SSH. We HAVE the latest openssh-3.4p1 RPM. The DOS attack is preventing real ssh clients to enter in.
My question is what would you recommend to stop or block out the ssh attack?
dandanfirema
07-14-2002, 02:49 PM
If you know who the DOS is coming from...you can use something like iptables/ipchains to block the incoming or hosts.deny or lastly request your ISP to block the offending IP address
infinite
07-15-2002, 04:47 AM
If you have a dedicated firewall, I imagine it would soon pick up on this and block them. Otherwise, as dandanfirema says, find the IP address in the correct log file, and add them to hosts.deny:D
Cheers,
Infinite ;)
if it's really hardcore contact your provider and have them block the ip upstream - that way you don't have to pay for the bandwidth.
-neil