Announcement

Collapse
No announcement yet.

(solved) anybody running sshutout?

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    (solved) anybody running sshutout?

    I've been running sshutout on a debian stable box at work for a couple of years now. It worked out of the box, and I'm fairly certain it has saved me some grief from the door knockers that show up almost every day.

    http://www.techfinesse.com/sshutout/sshutout.html

    I recently installed it on my kubuntu jaunty system at home. So far I haven't been able to make it work. It builds without error and seems to be running normally, but it never catches any failed login attempts and never logs anything.

    Sshutout is not an ubuntu package, but I can't see anything that would keep it from working on my jaunty system. Just wondering if anyone else has tried it and whether they got it to work or not.

    FWIW, I also installed fail2ban and denyhosts, which are ubuntu packages, and they don't seem to be working either. That is, the daemons are running but they don't seem to catch anything. That makes me wonder if it's a permissions problem or lib mismatch or some such. As with sshutout, there's nothing in the logs to suggest what's wrong.

    Any suggestions would be most appreciated.

    Edit: Changing /etc/ssh/sshd_config LogLevel from Error to Info made it work. Apparently Info is the default in debian, while Error is the default in (k)ubuntu.
    linux since slack 2. kde since beta 1. kubuntu since hardy.

    #2
    Re: anybody running sshutout?

    Originally posted by budr
    ...but it never catches any failed login attempts and never logs anything.
    Have you looked at the /var/log/auth.log? Are there any logged attempts other than what you expect to see?
    Windows no longer obstructs my view.
    Using Kubuntu Linux since March 23, 2007.
    "It is a capital mistake to theorize before one has data." - Sherlock Holmes

    Comment


      #3
      Re: anybody running sshutout?

      Originally posted by Snowhog

      Have you looked at the /var/log/auth.log? Are there any logged attempts other than what you expect to see?
      Oh yeah. I see multiple attempts almost every day. Some of them I think are timed to avoid triggering sshutout or similar programs -- individual attempts are spaced about 10 minutes apart, etc. But I also see sometimes 20 or 30 at a time, about as fast as a script can fire them off. Those ought to trigger sshout, fail2ban, denyhosts, any of the log monitor programs. It's not clear to me why they don't.
      linux since slack 2. kde since beta 1. kubuntu since hardy.

      Comment


        #4
        Re: anybody running sshutout?

        Originally posted by budr
        Those ought to trigger sshout
        That's supposed to be sshutout... My keyboard can't spell for ****.
        linux since slack 2. kde since beta 1. kubuntu since hardy.

        Comment

        Working...
        X