ot: how to block persistent same invalid account, different IPs
22 Dec
2017
22 Dec
'17
11:38 p.m.
"Voytek Eymont" <voytek@sbt.net.au>
If each IP is only used once in a long while, what would be the point?
In general, distributed attacks are very hard to stop if you have a default accept stance. I've observed that most of the attacks to my site are from the enormous Chinese stated owned public network superblocks. I finally got sick of them so I now spiral these IMAP/POP connections into the Scharwzschild radius of my firewall.
It's a prophylactic measure and not a reactive system like fail2ban, and may not work for you if you got road warriors that frequent that part of the world. However, it did get rid of a metric ton of BFD connections.
Joseph Tam <jtam.home@gmail.com>
2703
Age (days ago)
2703
Last active (days ago)
0 comments
1 participants
participants (1)
-
Joseph Tam