Advertisement
Guest User

Untitled

a guest
Jan 21st, 2015
264
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.58 KB | None | 0 0
  1. brute_force(){
  2. echo -n "Preventing Brute Force Attacks..."
  3.  
  4. ## Create New Chain
  5. iptables -N BRUTE_FORCE
  6.  
  7. ## FTP/Telnet/SSH
  8. iptables -A INPUT -i $LAN_IF -p tcp -m conntrack --ctstate NEW -m multiport --dports 21,22,23 -j BRUTE_FORCE
  9. iptables -A BRUTE_FORCE -m recent --hitcount 2 --rcheck --seconds 15 --name brute_force -m limit --limit 10/min -j ULOG --ulog-prefix "[BRUTE_FORCE DROP]: "
  10. iptables -A BRUTE_FORCE -m recent --hitcount 2 --update --seconds 15 --name brute_force -j DROP
  11. iptables -A BRUTE_FORCE -m recent --set --name brute_force -j RETURN
  12. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement