ipsum
Daily feed of bad IPs (with blacklist hit scores) (by stamparm)
endlessh
SSH tarpit that slowly sends an endless banner (by skeeto)
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
ipsum
Posts with mentions or reviews of ipsum.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2021-09-09.
- Lists of IPv4 abuse IPs
-
List of Blocklists in pfSense ?
Yeah pfsense uses pfblockerNG, but you can add you own blocklists from several open sources. Some of them are: IPsum, Ellio, MISP. https://github.com/stamparm/ipsum https://feed.ellio.tech https://www.misp-project.org/download
- blocking all traffic from attacking IPs?
-
Hackers exploit WordPress plugin flaw that gives full control of millions of sites
ConfigServer Security and Firewall (csf) using this list. https://github.com/stamparm/ipsum
- Cosa ne pensate dell'utilizzo di blacklist di IP malevoli per ridurre i bot che scansionano siti alla ricerca di vulnerabilità?
-
DShield Block List
Any plan release some of other block lists like https://github.com/stamparm/ipsum
- Do you use blacklists / IP threat intelligence and are they helpful?
-
So I opened up one port on my network for an SFTP server, and in just the last 7 days there have been 611 attempts to log into it... It's always interesting to see the usernames that try to log in, so I pulled them and sorted them all out.
Do yourself a favor and load up your iptables with the ipsum blacklist.
- Vendor-independent IP/DNS-block-list
- Shodan Lifetime $4 USD
endlessh
Posts with mentions or reviews of endlessh.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2023-06-22.
-
Why so many bots?
You can reduce the noise a lot by moving ssh to a non standard port. Security through obscurity isn't actually security, but it will reduce the number of attempts you receive. Another thing I like to do is put Endlessh on the standard port 22. That way as bots go by they will get stuck or at least slow down on that connection.
-
Is SSH secure enough?
SSH tarpit with Endlessh and for the hidden SSH: auth with both a key files (that need unlocking and is on the computer) AND an One Time Password on my phone.
-
"Failed password for root" SSH login hacking attemp?
If you change the ssh port, install https://github.com/skeeto/endlessh to slow down the attackers
-
ChatGPT doxes itself
Even this requires you to successfully guess the username and password correctly, and if it's just not the default most people won't bother brute forcing further. Sidenote: you can use endlessh on a computer and port forward port 22 to trap scanners that scan the entire internet for open ssh ports to exploit.
-
Ssh brute force attack with fail2ban.
The fun way is moving your ssh port somewhere else and installing endlessh to f the bots.
-
Security for your Homeserver
Such as endlessh
-
Keep it tight everyone! This is a day of sshd logs from a proxy server in China pinging my SSH server and trying every username imaginable. Does anyone have any tips to increase security?
But, as a prank to Chinese hackers, what I did on my system was to run endless ssh. It keeps the ssh client busy as it slowly sends the ssh banner. I modified the code to send strings like:
-
VPN to remotely access dockerized services
For hardening: I use lynis for some guidance, the VPS runs rkhunter, AIDE and other things nightly and mails me the reports, fail2ban manages the SSH port, having SSH on a custom port helps to keep things quiet. If you're into these kind of things, have a look at the Endlessh tarpit to learn about login attempts on port 22 on your machine - I found it eye-opening.
- Any app out there to trap port scanners?
- Mein Server wird für Bruteforce Attacken genutzt, was kann ich tun?