<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheets/rss.css" type="text/css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>swaits.com: sshd brute forcers</title>
    <link>http://swaits.com/articles/2006/04/21/sshd-brute-forcers</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description>A Blog by Stephen Waits</description>
    <item>
      <title>sshd brute forcers</title>
      <description>&lt;p&gt;Wherever you look, idiots.  I got sick of my nightly logs being full of sshd brute force attempts.  I didn&amp;#8217;t want to run sshd through inetd, which does provide connection throttling.&lt;/p&gt;

&lt;p&gt;I wanted to blacklist the idiots in realtime - but i don&amp;#8217;t believe in fscking with firewalls automagically.  So, I rebuilt sshd with libwrap support, and hacked together this ruby script.&lt;/p&gt;

&lt;p&gt;It&amp;#8217;s been running fine for a few months now, so have at it!&lt;/p&gt;

&lt;p&gt;Download it &lt;a href="http://www.waits.net/~swaits/sshbruted.rb"&gt;here&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Enjoy!&lt;/p&gt;</description>
      <pubDate>Fri, 21 Apr 2006 23:17:46 -0500</pubDate>
      <guid isPermaLink="false">urn:uuid:e0c6e5a3-56f3-406f-a213-33bc4c41bfda</guid>
      <author>steve@waits.net (Stephen Waits)</author>
      <link>http://swaits.com/articles/2006/04/21/sshd-brute-forcers</link>
      <category>security</category>
      <category>os</category>
      <trackback:ping>http://swaits.com/articles/trackback/224</trackback:ping>
    </item>
  </channel>
</rss>
