{"id":6,"date":"2006-06-16T14:56:32","date_gmt":"2006-06-16T01:56:32","guid":{"rendered":"http:\/\/www.meta.net.nz\/~daniel\/blog\/?p=6"},"modified":"2006-06-16T14:56:32","modified_gmt":"2006-06-16T01:56:32","slug":"denyhosts","status":"publish","type":"post","link":"https:\/\/www.meta.net.nz\/~daniel\/blog\/2006\/06\/16\/denyhosts\/","title":{"rendered":"DenyHosts"},"content":{"rendered":"<p>If you have computer on a public-facing IP address, and it runs an SSH server on port 22, chances are pretty good you&#8217;ll be subjected to a number of dictionary attacks.  Compromised hosts will try to login with a list of common user names and passwords.<\/p>\n<p>Now, this isn&#8217;t a problem for most of us, right? We have secure passwords after all, and these attacks are just trying dictionary lists of words &#8211; username root, password of &#8216;password&#8217; or &#8216;root&#8217;, for example. However, they are still annoying &#8211; if only because they fill up the logfiles. Also, it&#8217;d be better to just not have the connections, just in case they manage to get through.<br \/>\nI recently came across a tool called <a title=\"denyhosts.sourceforge.net\" target=\"_blank\" href=\"http:\/\/denyhosts.sourceforge.net\">denyhosts<\/a>. Denyhosts monitors your ssh log file and modifies \/etc\/hosts.deny to disallow SSH (or all access to tcpwrapped services) from hosts that have a significant number of failed login attempts. It also has a synchronised mode in which hosts running denyhosts on the internet share their list of denied IP addresses.<\/p>\n<p>I set it up a week or so ago and get an email every couple of hours with a new IP address that has been blacklisted. I also managed to blacklist one of my own IP addresses while testing, which proved hard to remove &#8211; denyhosts kept adding the block back in. Fortunately I set it to purge entries after 3 days, so I can now ssh in again :)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you have computer on a public-facing IP address, and it runs an SSH server on port 22, chances are pretty good you&#8217;ll be subjected to a number of dictionary attacks. Compromised hosts will try to login with a list of common user names and passwords. Now, this isn&#8217;t a problem for most of us, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[2,9],"tags":[],"_links":{"self":[{"href":"https:\/\/www.meta.net.nz\/~daniel\/blog\/wp-json\/wp\/v2\/posts\/6"}],"collection":[{"href":"https:\/\/www.meta.net.nz\/~daniel\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.meta.net.nz\/~daniel\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.meta.net.nz\/~daniel\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.meta.net.nz\/~daniel\/blog\/wp-json\/wp\/v2\/comments?post=6"}],"version-history":[{"count":0,"href":"https:\/\/www.meta.net.nz\/~daniel\/blog\/wp-json\/wp\/v2\/posts\/6\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.meta.net.nz\/~daniel\/blog\/wp-json\/wp\/v2\/media?parent=6"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.meta.net.nz\/~daniel\/blog\/wp-json\/wp\/v2\/categories?post=6"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.meta.net.nz\/~daniel\/blog\/wp-json\/wp\/v2\/tags?post=6"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}