• Skip to main content
  • Skip to primary sidebar
  • Skip to footer
Michele Neylon :: Pensieri

Michele Neylon :: Pensieri

Technology, Marketing, Domains, Thoughts

Stopping Bruteforce SSH Attacks

March 17, 2007 by Michele Neylon 11 Comments

Years ago when I got my first server I remember installing some scripts to check its integrity and warn me about attacks. I was amazed and quite frightened by the number of SSH attempts. I soon learnt, however, that this was quite normal. It maybe worrying, but it’s normal.
Put a server on a public IP and people will try to crack it.
There’s no avoiding that. Well, there is, but it’s a bit impractical to disconnect a web server from the internet 🙂
So what can you do?
One of the solutions is to use iptables to block the IPs of failed login attempts. If someone (or something) makes more than X connection attempts from a particular IP then you block it.
Of course that’s easy if you can program. I can’t!
Luckily I don’t have to, as there are solutions like the rather excellent Fail2Ban available:

Fail2ban scans log files like /var/log/pwdfail or /var/log/apache/error_log and bans IP that makes too many password failures. It updates firewall rules to reject the IP address.

So not only can you block SSH attacks, you can also use it to defend yourself from other bruteforce attempts.
There are debian / Ubuntu versions available, so all you need to do (as root) is run:
apt-get install fail2ban
This will install the daemon and its basic config, which is to silently block SSH attacks.
You can easily customise the configuration by editing /etc/fail2ban.conf
The developers have left nice clear comments in the file, so even I was able to make the necessary changes, including whitelisting my own IPs ie. you don’t want to lock yourself out just because you’ve forgotten your login details.
There’s also a nice writeup here which goes into some depth about the various options available.

Related Posts:

  • Photo of old hand written letters on a desk with some pencils and pens
    I Sometimes Yearn For Simpler Times
  • Video thumbnail for youtube video bzujtlshxci
    Aslan in the 1980s
  • Video thumbnail for youtube video zbg4wxpkje4
    Irish Around the World for St Patrick's Day
  • privacy-keyboard-keys
    My Privacy Has Been Sold
  • Hans Zimmer concert in Madrid 2023
    Another Year of Fun Concerts
  • Video thumbnail for youtube video 8s0fdjfbj8o
    Public Speaking Hacked

Filed Under: Linux, Open Source, Techie :: Techno ::, Ubuntu Tagged With: Debian, security, Ubuntu

Michele is founder and CEO of Irish hosting provider and domain name registrar Blacknight. Read More…

Reader Interactions

Leave a Reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

dotblog founder

Mastodon

Archives

  • Bluesky
  • Instagram
  • Threads
  • Twitter

Pages

  • About Me
  • About This Site
  • Archives
  • Comments Policy
  • Contact Me
  • Newsletter
  • Privacy

Blogroll

  • My Mastodon
  • Tom Doyle
  • Grandad
  • Stewart Curry
  • Damien Mulley

Stalking Links

Subscribe to Michele Neylon :: Pensieri

Blogroll

  • Blacknight Blog
  • Damien Mulley
  • Gianni Ponzi
  • Gordon Hudson
  • Grandad
  • My Mastodon
  • Paul Savage – BlackDog SEO
  • Stewart Curry
  • Technology.ie Podcast
  • Tom Doyle

Sites

  • Business Travel Tips
  • Discount Coupon Codes
  • Domain News
  • Fat.ie – my diet blog
  • Film Posters
  • Film Reviews
  • Films
  • Free Desktop Wallpapers
  • Irish Blogger Discussion Forum
  • Irish Stamps
  • Movie Trailers and News
  • Paste.ie

Footer

Site hosted in Ireland by Blacknight - Content copyright Michele Neylon

Copyright © 2026 · Magazine Pro on Genesis Framework · WordPress · Log in