sshdfilter

sshdfilter automatically blocks ssh brute force attacks by reading sshd log output in real time.
Download

sshdfilter Ranking & Summary

Advertisement

  • Rating:
  • License:
  • GPL
  • Price:
  • FREE
  • Publisher Name:
  • Greg
  • Publisher web site:

sshdfilter Tags


sshdfilter Description

sshdfilter automatically blocks ssh brute force attacks by reading sshd log output in real time. sshdfilter automatically blocks ssh brute force attacks by reading sshd log output in real time and adding iptables rules based on authentication failures.Block rules are created by logging on with an invalid user name, or wrongly guessing the password for an existing account.Block rules are removed after a week to maintain a small list of blocks. It also comes with a LogWatch filter.What's New in This Release:· The configuration parser and the pattern matching engine were rewritten to provide all the flexibility you could ever want.· sshdfilter can now read sshd messages from either sshd -eD (as with previous versions of sshdfilter) or via a named pipe maintained by syslog.· Hostname lookup for messages was added for PAM-based systems that show hostnames and never a source IP.· ipfw support was added.


sshdfilter Related Software