- Get a list of subnets like so: $ wget http://www.okean.com/chinacidr.txt
- Execute this command ...
... where ...
$ cat ~/scripts/blackhole-port22.sh
#!/bin/sh
hole=$1
sudo /sbin/iptables -v -t filter -I INPUT -p tcp --dport 22 -s $hole -j REJECT
... maybe someday the Chinese will stop attempting brute force attacks against sshd. LOL!
No comments:
Post a Comment