[mythtv-users] Semi-OT: Blocking Brute Force SSH attacks

Michael MacLeod mikemacleod at gmail.com
Mon Oct 22 07:12:39 UTC 2007


On 10/20/07, David Kramer <david at thekramers.net> wrote:
> I use one called DenyHosts (http://denyhosts.sourceforge.net/) which is
> very flexible and powerful; nearly completely automatic once set up.

Another vote for denyhosts. I have it installed on a couple of world
facing computers, and it's fantastic. Particularly slick is if you
enable the sync feature. All the hosts running DenyHosts can sync
their block lists to a central server. You can set parameters for
which hosts from the central database you pull out (for instance only
hosts that have attacked two computers in the pool, etc).

As a bonus, any application you run that respects
hosts.allow/hosts.deny is protected.

Mike


More information about the mythtv-users mailing list