Scanners

by rullzer on Mar.10, 2007, under Gentoo

So I was going trough the logs on my server the other day and my auth.log (ssh) was huge. So i wondered how it has gotten so huge. So I opened it. And I saw a list that would not end of invalid logins. Apparently i was in the IP range of some scanners. Now if you have the same problem I suggest you try the program fail2ban (it is in gentoo’s portage). It works like a charm! my /etc/hosts.deny grows steady :P . However fail2ban has the nice function to eliminate ranges of IP addresses so that you do not cut of your network. (which is nice).

However I also want to use this post to send a message to the scanners. If you would like better results do not try login names like AccesDB or ntDomain!


1 Trackback or Pingback for this entry

Leave a Reply

Looking for something?

Use the form below to search the site:

Still not finding what you're looking for? Drop a comment on a post or contact us so we can take care of it!