Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's because people can't agree on what is or isn't valuable.

For instance, if I (or my software anyway) see a bunch of sshd login attempts from some IP, and then that IP decides to try imap ... yeah, that's getting insta-blocked.

And that's hard to do if you decide to just ignore the sshd attempts.



Could additional honey pot on 22 help? Run sshd on non-standard port and honey pot on 22. Then automatically ban all the hosts that would connect to it. There could be a concern for a mistake, so then ban for limited time at first or something.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: