Re[2]: bruteforceblocker + PF

2005-10-09 Thread Daniel Gerzo
Hi Enrique, Friday, October 7, 2005, 4:44:31 PM, you thoughtfully wrote the following: > El Viernes, 7 de Octubre de 2005 13:08, Daniel Gerzo escribió: >> 1) Update your OpenSSH to 4.2, you can find the port in the >> security/openssh-portable (you can use -DOPENSSH_OVERWRITE_BASE >> option) Note

Re: bruteforceblocker + PF

2005-10-07 Thread Enrique Ayesta Perojo
El Viernes, 7 de Octubre de 2005 13:08, Daniel Gerzo escribió: > 1) Update your OpenSSH to 4.2, you can find the port in the > security/openssh-portable (you can use -DOPENSSH_OVERWRITE_BASE > option) Note, that this one I prefer more. Nice!!! It works perfectly, that was the problem, the ssh vers

Re[2]: bruteforceblocker + PF

2005-10-07 Thread Daniel Gerzo
Hello Enrique, Friday, October 7, 2005, 10:12:34 AM, you has on mind: > El Osteguna 06 Urria 2005 22:18, Daniel Gerzo escribió: >> Hi questions, Enrique Ayesta Perojo, >> >> >> >>It seems like bruteforceblocker is running, since you can see >>messages in your auth.log. this is good. coul

Re: bruteforceblocker + PF

2005-10-07 Thread Enrique Ayesta Perojo
El Osteguna 06 Urria 2005 21:56, Noel Jones escribió: > I manually installed bruteforceblocker 1.1 (later noticed it's in > ports/security) and when it starts, it looks like: > --- log started at Wed Oct 5 13:13:01 2005 --- > > So it appears that your software is different from mine. No,

Re: bruteforceblocker + PF

2005-10-07 Thread Enrique Ayesta Perojo
El Osteguna 06 Urria 2005 22:18, Daniel Gerzo escribió: > Hi questions, Enrique Ayesta Perojo, > > > >It seems like bruteforceblocker is running, since you can see >messages in your auth.log. this is good. could you please provide >me info, which version of openssh are you using, so I

Re[2]: bruteforceblocker + PF

2005-10-06 Thread Daniel Gerzo
Hi Dave, Thursday, October 6, 2005, 10:24:20 PM, you wrote about: > Hello, > I've got bruetforceblocker going with pf, i just installed the port. My > box is a 5.4 machine. I have it going on my lan server, which does ssh for > my network, it's the box you'll hit if you ssh in as opposed to t

Re: bruteforceblocker + PF

2005-10-06 Thread Dave
Hello, I've got bruetforceblocker going with pf, i just installed the port. My box is a 5.4 machine. I have it going on my lan server, which does ssh for my network, it's the box you'll hit if you ssh in as opposed to the firewall box. It's adding ip's to the table, but it's doing it stagger

Re: bruteforceblocker + PF

2005-10-06 Thread Daniel Gerzo
Hi questions, Enrique Ayesta Perojo, It seems like bruteforceblocker is running, since you can see messages in your auth.log. this is good. could you please provide me info, which version of openssh are you using, so I can debug? I have som reports, that my bruteforceblocker does not

Re: bruteforceblocker + PF

2005-10-06 Thread Noel Jones
On 10/6/05, Enrique Ayesta Perojo <[EMAIL PROTECTED]> wrote: > El Miércoles, 5 de Octubre de 2005 21:53, Noel Jones escribió: > > > I'm going to assume this is just a small part of your pf.conf, because > > the part you show doesn't allow any internet access. Maybe you should > > show us your enti

Re: bruteforceblocker + PF

2005-10-06 Thread Enrique Ayesta Perojo
El Miércoles, 5 de Octubre de 2005 21:53, Noel Jones escribió: > I'm going to assume this is just a small part of your pf.conf, because > the part you show doesn't allow any internet access. Maybe you should > show us your entire pf.conf. Yes, it was a small part of my pf.conf. Anyway i'm trying

Re: bruteforceblocker + PF

2005-10-05 Thread Noel Jones
On 10/5/05, Enrique Ayesta Perojo <[EMAIL PROTECTED]> wrote: > Hello, i'm trying to install the bruteforceblocker script to stop ssh attacks, > but i'm having a problem with PF because it seems not to block the attacker > ip. > > The machine is connected to internet and has some needed services for

bruteforceblocker + PF

2005-10-05 Thread Enrique Ayesta Perojo
Hello, i'm trying to install the bruteforceblocker script to stop ssh attacks, but i'm having a problem with PF because it seems not to block the attacker ip. The machine is connected to internet and has some needed services for the LAN, so i want to log and block only outside attacks. The bru