[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: PAM tarpit module for repeated SSH login attempts

On Wed, Oct 20, 2004 at 11:50:07AM +0200, martin f krafft wrote:
> For a tarpit, the best thing to do would be simply to drop the
> connection without sending a FIN or RST packet. I don't know if PAM
> can do this.
> Otherwise, just hold the connection open for several minutes and do
> nothing. After that time, send a RST or just drop it from the table.

AFAIK PAM is designed do return a single value like PAM_SUCCESS or
PAM_XXX_ERR, so the above isn't anything to deal with PAM.

Martin Reising			mailaddress see header
natural computing GmbH		http://www.natural-computing.de/
Martener Str. 535 		Phone: +49 231 6104850 
44379 Dortmund			Fax:   +49 231 6104840

Attachment: signature.asc
Description: Digital signature

Reply to: