lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <7da922bf0603020840y25da7e3flfeaa530abf1dbf83@mail.gmail.com>
Date: Thu Mar  2 16:40:32 2006
From: tastytastybeef at googlemail.com (Gary Leons)
Subject: reduction of brute force login attempts via
	SSHthrough iptables --hashlimit

On 3/2/06, GroundZero Security <fd@....org> wrote:
> Well i dont want to destroy your happy time where you can feel superior, but
> if you would read the manpage of lastb you would notice that this approach wont work at all.
> lastb just shows successfull logins! not all the attempted logins....we discussed that before though,
> so better pay attention next time.

Holy crap, you must be the dumbest man alive. I really hope nobody has
ever hired you for any security related work, if they have, I would
advise them to get a second opinion or third party audit of any code
provided.

If you had scrolled down 20 LINES in the man page, you wold have seen
"Lastb is the same as last, except that by default it shows a log of
the file /var/log/btmp, which contains all the bad login attempts.",
maybe you have bad eyesight, let me blow that text up for you: BAD
LOGIN ATTEMPTS, ok? clear now? good.

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ