View Single Post

   
  #1 (permalink)  
Old 02-20-2008, 06:50 AM
The Eighth Doctor
 
Posts: n/a
Default SSH visits from users who were not given permission--can they be blocked?

Hello from the Eighth Doctor
The subject line says it all: "SSH visits from users who were not given
permission--can they be blocked?"

Basically my box now running Slack 10.1 is being visited by people who were not
given my permission to do so, read hackers, and other annoyances. I frequently use
SSH from my Manhattan client to show them Linux, or to just keep busy, and I've
given a fellow I know online who's currently using the services of his school to visit
the box. He needs to learn Linux, and I trust him as much as he trusts me.

However since we reached that decision, I've seen scads of IP addresses attempting
to enter the box from the Internet. Sometimes they use FTP, but almost always
SSH. Once I saw something from a UUNET customer attempt a hack, I found out
later that there's a worm running who targets machines which have the SSH port
open.

That being said; once I've got the list of acceptable IP addresses from the I'net, any
suggestions on how to configure the current firewall mechanism to reject everyone
else? Also the router does contain a firewall, but I'm not sure as to how to have it
block those addresses, if it can...
--
Gregg drwho8 atsign att dot net
"This signature is waiting for Garbot."

Reply With Quote