<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Dictionary attacks, or why log file monitoring is dumb</title>
	<atom:link href="http://www.n8gray.org/blog/2008/01/28/dictionary-attacks-or-why-log-file-monitoring-is-dumb/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.n8gray.org/blog/2008/01/28/dictionary-attacks-or-why-log-file-monitoring-is-dumb/</link>
	<description>distraction in action</description>
	<pubDate>Fri,  5 Dec 2008 08:36:24 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: n8</title>
		<link>http://www.n8gray.org/blog/2008/01/28/dictionary-attacks-or-why-log-file-monitoring-is-dumb/#comment-21046</link>
		<dc:creator>n8</dc:creator>
		<pubDate>Wed, 11 Jun 2008 19:21:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.n8gray.org/blog/2008/01/28/dictionary-attacks-or-why-log-file-monitoring-is-dumb/#comment-21046</guid>
		<description>I didn't claim that all the tools I listed were log file scanners, but I probably shouldn't have included ssh-faker since it falls under the "alter your sshd service" category.  I'll remove it now.</description>
		<content:encoded><![CDATA[<p>I didn&#8217;t claim that all the tools I listed were log file scanners, but I probably shouldn&#8217;t have included ssh-faker since it falls under the &#8220;alter your sshd service&#8221; category.  I&#8217;ll remove it now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CH</title>
		<link>http://www.n8gray.org/blog/2008/01/28/dictionary-attacks-or-why-log-file-monitoring-is-dumb/#comment-21045</link>
		<dc:creator>CH</dc:creator>
		<pubDate>Wed, 11 Jun 2008 18:58:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.n8gray.org/blog/2008/01/28/dictionary-attacks-or-why-log-file-monitoring-is-dumb/#comment-21045</guid>
		<description>I'm pleased to note that ssh-faker (on your list) doesn't scan log files.  It blacklists all hosts, until you telnet to port 22 and type a password, at which point your current ip address is whitelisted.  No cron job, no daemon, no log file scanning.  The database is /etc/hosts.allow.

On the downside, it doesn't remove addresses from the white list, but that's hardly a problem, as you're still blocking 99.999% of the internet whether your whitelist contains 10 or 1000 entries.</description>
		<content:encoded><![CDATA[<p>I&#8217;m pleased to note that ssh-faker (on your list) doesn&#8217;t scan log files.  It blacklists all hosts, until you telnet to port 22 and type a password, at which point your current ip address is whitelisted.  No cron job, no daemon, no log file scanning.  The database is /etc/hosts.allow.</p>
<p>On the downside, it doesn&#8217;t remove addresses from the white list, but that&#8217;s hardly a problem, as you&#8217;re still blocking 99.999% of the internet whether your whitelist contains 10 or 1000 entries.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
