Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

  ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:ssh limit: up to 1/min burst 2 mode srcip
Have fun brute forcing at 1 connection per minute.

(Oh, and PasswordAuthentication is off too.)



Can you paste the config line that adds this to your iptables?


  -A PORTS -p tcp -m tcp --dport 22 -m hashlimit --hashlimit-upto 1/min --hashlimit-burst 2 --hashlimit-mode srcip --hashlimit-name ip4-ssh-brute -j ACCEPT


Is this per IP or for all incoming connections?


"srcip"




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: