View Single Post

  #5 (permalink)  
Old 09-07-2004
Mark A. Odell
 
Posts: n/a
Default Re: Automatic blocking of attackers' IP

"FEEB" <feeb@chem.utoronto.ca> wrote in
news:srropurzhgbebagbpn.i3ohdhe.pminews@news1.chem .utoronto.ca:

>>> I would like to have the following scenario implemented on my network:
>>>
>>> 1.
>>> Someone tries repeatedly and illegally to log in as 'admin', 'root' or
>>> whatever from some IP using SSH (or any other means).

>>
>>Why not just set hosts.deny to ALL: ALL and then open up only those IPs

> or
>>domains you wish to allow in hosts.allow?

>
> We must be open to anyone. That's our business :-)


Ah. Then just put the bad IP or IP range into the hosts.deny. Of course
this won't scale well for many IP addresses.

--
- Mark ->
--
Reply With Quote