The amount of toxic traffic hitting that port is scary.
The amount of toxic traffic hitting that port is scary.
So in the majority of cases, traffic will get through? :P
Even if fail2ban and others were perfect, all it would take is the sysadmin customizing the log format to include some random field and all the sudden it's possible for an attacker to block every IP address with one request.
Source: http://seclists.org/fulldisclosure/2007/Jun/138
A better alternative is something like pam_abl which only protects logins to a user on the system but with it ssh is essentially unbruteforceable.
I believe this is the problem with using pam_tally2. Then again, if you're only allowing PubkeyAuthentication then maybe you don't care about brute force login attempts so much.
Yes, moving ports helps, but it's not a real defense. It just lowers bandwidth costs and prevents some not-so-harmful attacks (from people who don't know whether what they've compromised has any value.)
At the very least, use public-key authentication instead of password authentication for SSH.
I get a kick out of viewing all the failed attempts in /var/log/auth
Added bonus is adding all those bad guy addresses to my blacklists.