Quoting Adrian-Ioan Vasile <adrian.vas...@gmail.com>:

On Jun 7, 2010, at 12:06 PM, Valentin Cozma wrote:

salutare,

va rog sa ma indrumati in urmatoarea problema :

observ pe syslog atacuri de la anumite ip-uri.

as vrea sa blochez automat, din firewall, un ip considerat suspect de atac.

sshd-ul zice el ceva in loguri, dar nu sta nimeni sa le citeasca in timp
real.

cum s-ar aborda o astfel de problema ?

multumesc.


_______________________________________________
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug

vezi sshguard

vezi si fail2ban, e mult mai capabil decat multe alte scule, se uita prin diverse loguri(auth, apache, mail, etc) in functie de ce module activezi.

----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.

Attachment: pgpcbBtcAxTbt.pgp
Description: PGP Digital Signature

_______________________________________________
RLUG mailing list
RLUG@lists.lug.ro
http://lists.lug.ro/mailman/listinfo/rlug

Raspunde prin e-mail lui