From owner-freebsd-questions@FreeBSD.ORG Mon Jun 18 06:24:56 2007 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id E7FEE16A400 for ; Mon, 18 Jun 2007 06:24:56 +0000 (UTC) (envelope-from beech@freebsd.org) Received: from stargate.alaskaparadise.com (181-11-178-69.gci.net [69.178.11.181]) by mx1.freebsd.org (Postfix) with ESMTP id 8995213C4AE for ; Mon, 18 Jun 2007 06:24:56 +0000 (UTC) (envelope-from beech@freebsd.org) Received: from localhost (localhost [127.0.0.1]) by stargate.alaskaparadise.com (Postfix) with ESMTP id D37597F72; Sun, 17 Jun 2007 22:24:55 -0800 (AKDT) From: Beech Rintoul To: freebsd-questions@freebsd.org Date: Sun, 17 Jun 2007 22:24:47 -0800 User-Agent: KMail/1.9.6 References: <46761D5B.1000406@szalbot.homedns.org> In-Reply-To: <46761D5B.1000406@szalbot.homedns.org> X-Face: jC2w\k*Q1\0DA2Q0Eh&BrP/Rt2M,^2O#R07VoT98m*>miQF9%Bi9vy`F6cPjwEe?m,)=?utf-8?q?2=0A=09X=3FM=5C=3AOE9QgZ?="xT3/n3,3MJ7N=Cfkmi%f(w^~X"SUxn>; 27NO; C+)g[7J`$G*SN>{<=?utf-8?q?O=3Bg7=7C=0A=09o=7D=265A=5D4?=@7D`=Eb@Zs1Ln814?]|k@'bG=.Ca"[|8+_.OsNAo8!#?4u MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-2" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200706172224.51761.beech@freebsd.org> Cc: Zbigniew Szalbot Subject: Re: denyhosts and the threshold level X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: beech@freebsd.org List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 18 Jun 2007 06:24:57 -0000 On Sunday 17 June 2007, Zbigniew Szalbot said: > Hello, > > I have denyhosts set with the following options: > > DENY_THRESHOLD_INVALID = 3 > DENY_THRESHOLD_VALID = 3 > > In my understanding this should block all ssh login attempts from a > host which fails to provide correct login credentials 3 times (no > matter if the user actually exists or not at my system). This > appears to work. But I have a question. When I look at the log I > can see something like that: > > Failed password for root from 218.9.127.236 port 46472 ssh2 Jun 17 > 19:55:38 lists sshd[8048]: > Failed password for root from 218.9.127.236 port 46631 ssh2 Jun 17 > 19:55:42 lists sshd[8052]: > Failed password for root from 218.9.127.236 port 46786 ssh2 Jun 17 > 19:55:45 lists sshd[8057]: > Failed password for root from 218.9.127.236 port 46952 ssh2 Jun 17 > 19:55:49 lists sshd[8069]: > Failed password for root from 218.9.127.236 port 47106 ssh2 Jun 17 > 19:55:53 lists sshd[8071]: > Failed password for root from 218.9.127.236 port 47261 ssh2 Jun 17 > 19:55:56 lists sshd[8075]: > Failed password for root from 218.9.127.236 port 47414 ssh2 Jun 17 > 19:56:00 lists sshd[8079]: > Failed password for root from 218.9.127.236 port 47566 ssh2 Jun 17 > 19:56:03 lists sshd[8081]: > > How can I determine whether the user has actually been cut off > after 3 attempts? Or does the above mean that the user was not > blocked? > > Many thanks for your advice! > > Warm regards from Poland. > > Zbigniew Szalbot I use denyhosts on a couple of my servers. Those login scripts try many a second. It takes denyhosts a bit of time to catch it. As for them being blocked root should be receiving mail telling you what IP was blocked. What I see above looks about normal for the app. Beech -- --------------------------------------------------------------------------------------- Beech Rintoul - FreeBSD Developer - beech@FreeBSD.org /"\ ASCII Ribbon Campaign | FreeBSD Since 4.x \ / - NO HTML/RTF in e-mail | http://www.freebsd.org X - NO Word docs in e-mail | Latest Release: / \ - http://www.FreeBSD.org/releases/6.2R/announce.html ---------------------------------------------------------------------------------------