Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » O Canada! » Canadian » TekSavvy » Update on Throttling: Part 2...
Search Topic:
Uniqs:
9531
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
... »
« Teksavvy Home Phone Bundle  
page: 1 · 2 · 3 ...5 · 6 · 7 · 8
AuthorAll Replies


derekm

join:2008-02-26
·TekSavvy Solutions..
·Rogers Hi-Speed


1 edit
reply to LiQuiD
Re: Update on Throttling: Part 2...

said by LiQuiD See Profile :

No matter what port number you use, eventually you'll get scans. What I've done to avoid them is set the sysctl on fbsd to drop syn+fin (not perfect, but marked improvement) and b: a buddy of mine and myself once created a perl script that would parse my /var/log/auth.log (or wherever connection attempts are logged) every hour and find numerous attempts from an IP and add them to a table for pf to chew on. I then had a cronjob that would reload the table into pf every hour. Needless to say, it was a table of unwelcomed hosts, and reloading it caused it to be added to the addresses blocked by my gateway.
LiQuiD, thanks for further confirming SCP/SSH findings.

A related note, I'm using pf and this rule simplifies the process for me:

table <badneighbors> persist
pass in on $ext_if inet proto tcp from any to any \
port { ssh } flags S/SA keep state \
(max-src-conn 3, max-src-conn-rate 5/3, \
overload <badneighbors> flush global)

I'm also running security/expiretable to timeout old entries, although I think in 7.0-RELEASE and above, you can do something like pfctl -t bruteforce -T expire 86400 (in OpenBSD 4.1 and above)

You may wish to throw POP3, or other services behind that little puppy too.
Forums » O Canada! » Canadian » TekSavvy... »
« Teksavvy Home Phone Bundle  
page: 1 · 2 · 3 ...5 · 6 · 7 · 8


Tuesday, 08-Dec 22:11:53 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [193] Sprint Sued For Distracted Driving Death
· [81] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [62] Sprint Poised For A Turnaround?
· [50] The Future Of Wi-Fi Is Bright
· [48] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [44] Microwaving Your Innards Is Not 'Extreme'
· [39] Verizon LTE: 5-12 Mbps Downstream
· [18] Verizon Settles With NJ Over Misleading FiOS Marketing
Most people now reading
· Comcast refused to install 400' feet. [Comcast HSI]
· ICC Strats??? [World of Warcraft]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Man Downloads Child Porn "Accidentally," Faces 20 Years [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· Servers UP!!! [World of Warcraft]
· Comcast Customers: Would You Prefer Metered Billing? [Comcast HSI]
· Account Hacked With Authenticator [World of Warcraft]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]
· Realistic expectation's of all the CRTC hoopla [TekSavvy]