Re: OpenSSH max auth tries issue

2015-07-18 Thread Mark Felder
On Fri, Jul 17, 2015, at 14:19, Mike Tancsa wrote: > Not sure if others have seen this yet > > -- > > > https://kingcope.wordpress.com/2015/07/16/openssh-keyboard-interactive-authentication-brute-force-vulnerability-maxauthtries-bypass/ > > "OpenSSH has a default value of six

Re: OpenSSH max auth tries issue

2015-07-18 Thread Jason Hellenthal
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 It wouldn't pass the pf overload rules if set correctly, that's just obvious. ipfw on the other hand I'm either not that conversed on and with the lack of named tables I would think it isn't going to catch it like pf would. It's trivial to just ad