Also, I noticed that I could INCREASE the block from 10 minutes to 24 hours (1 day)...but the way I've been getting slammed by bots lately,
I upped that to 72 hours (3 days).
That may be overkill, but it keeps the bot traffic down, as it were. I
am noticing more and more systems with that Mirai bot trying to get
in.
If a user has been blocked for too many incorrect passwords, what
needs to be done to remove that block??
Also, I'm noticing a lot of Bad/Unrecognized Data format with SSH
logons. Is this something I should be concerned about??
Also, I noticed that I could INCREASE the block from 10 minutes to 24 hours (1 day)...but the way I've been getting slammed by bots lately,
I upped that to 72 hours (3 days).
that's pretty low, IMHO... over here, the IDS blocks for 30+ days for Level ML>(aka severe) alerts...
there are thousands and thousands of them... plus there's an apparent new ML>recruiting campaign going on as i've seen several new variants as well as a ML>surge in older ones that have been around for a while... currently we're ML>tracking 22 variants and are aware of more out there...
If a user has been blocked for too many incorrect passwords, what
needs to be done to remove that block??
You mean a temporary ban? Just re-run the BBS.
Also, I'm noticing a lot of Bad/Unrecognized Data format with SSH logons. Is this something I should be concerned about??
No.
Also, I noticed that I could INCREASE the block from 10 minutes to
24 hours (1 day)...but the way I've been getting slammed by bots
lately, I upped that to 72 hours (3 days).
that's pretty low, IMHO... over here, the IDS blocks for 30+ days for
| Sysop: | Winzlo |
|---|---|
| Location: | Minnesota, USA |
| Users: | 11 |
| Nodes: | 16 (0 / 16) |
| Uptime: | 495938:30:56 |
| Calls: | 82 |
| Files: | 1,070 |
| D/L today: |
27 files (11,920K bytes) |
| Messages: | 286,961 |