Fail2ban has a reasonably easy to tweak detection and blocking rules, plus lots of available ready-made ones that do the job. If you're comfortable with regular expressions (which most people on HN probably are), then it's really straight-forward to write your own rules.
The only problem I encountered with it is when you start it up and you have a huge amount of data in your log files. It can cause 100% cpu usage for a long time until it digests the whole thing...
Read Section 7.0
Same thing for non-root: `AuthenticationMethods = publickey`
And when buying a router, buy something that will get regular security updates, or where you can put OpenWRT.
* PermitRootLogin=without-password/prohibit-password now bans all
interactive authentication methods, allowing only public-key,
hostbased and GSSAPI authentication (previously it permitted
keyboard-interactive and password-less authentication if those
were enabled).
It mentions that previously without-password it would still allow keyboard-interactive logins. Should be fairly easy to fake for a botnet!The /etc/sudoers NOPASSWD and sshd without-password sound like the same thing, but are far from that.
I feel like they could have named it better.
Pull the plug /s
Don't allow password-based SSH access.
https://blogs.akamai.com/2015/09/xor-ddos-threat-advisory.ht...
https://isc.sans.edu/forums/diary/XOR+DDOS+Mitigation+and+An... example (first Google result)
If you turn off root logins but still allow user logins the remote attacking system will have no way to detect that fact and will still attempt to brute force you.