DDOS ssh brute force attacks



Looks like a change on the force attack to attempt also to use auth keyboard-interactive in their methods.

I have two days seeing at my server logs from denyhosts… but looks like it’s bigger than I thought.

  1. Gunnar dijo:

    When I had my last wave of such attacks, I moved the ssh service to a high port (of course, that is not always an option) and rate-limited with iptables to four connections per minute (except from trusted networks, as it is a PITA when it bites you!)

    It really helped.

