On Thu, May 20, 2021 at 02:29:20PM +0000, Walter Harms wrote: > Thx for the fast response, > for the background: little system, far-far-away land, but some script-kiddie > is filling the log ... > so no iptables or other fancy stuff. Seems i have to change that, somehow. > > @matt: > in case i get something working ... > i am thinking about fnmatch and inet_ntoa would that be acceptable ?
I'm not really sure it's the job of Dropbear to be doing that filtering. Though I wonder if it might make sense to optionally not bother logging failed SSH auth attempts, given how many there are... Cheers, Matt