I have used tools like fail2ban and denyhosts in the past, which check various system log files (ssh, apache, ftp, samba, etc) for failed login attempts, and ban the IP address from one (or all) system services after a set number of failures.
fail2ban adds iptables rules, and denyhosts adds malicious IP's to '/etc/hosts.deny'. Both are available through the Ubuntu repositories.
by
noondesertsky
2009-04-21 10:47
ubuntu
·
security
·
server
·
linux
http://ubuntuforums.org/showthread.php?t=874249&highlight=hacked&page=2
-
cached
-
mail it
-
history