Script kiddies are all over the place - You'd be much better off spending the time to secure your system than going after them. Just tell your friend to disable the ssh daemon if it's not needed. Also see : http://hotcripts.com/resources/tutorials/secure-server-securing/disable-direct-root-login.php Rick Lim wrote: >Hi there, > >I know this is not the correct forum to ask this question, but I have to >start somewhere....... > >I have a friend with a linux firewall box. >There appears to be a very simple minded hacker trying to do simple ssh >password attacks on this box. > >I have been using whois and reporting this to each ISP he/she is coming from >but he/she just breaks into a different machine on an new ISP and tries >again. > >Is there something more I can do to track this person down? >Thanks. > > > >