roland brouwers writes:
Hello everybody,
Someone is attacking for a certain time on port SSH2
He is trying to login as root and uses all kind of usernames.
See annexed textfile
How can I block a user after x failed logins? Can I do something else?
You can reconfigure ssh to listen on another port, and set up portsentry to automatically firewall anyone who's hammering on the default ssh port.
Attachment:
pgpjjL4Y4desB.pgp
Description: PGP signature