hosts.deny not working

Posted by Captain Planet on Server Fault See other posts from Server Fault or by Captain Planet
Published on 2010-09-08T01:32:28Z Indexed on 2011/03/20 19:23 UTC
Read the original article Hit count: 312

Filed under:
|
|

Currently I am watching the live auth.log and someone is continuously trying the brute force attack for 10 hours.

Its my local server so no need to worry but I want to test.

I have installed denyhosts.

There is already an entry for that IP address in hosts.deny. But still he is trying the attacks from same IP. System is not blocking that.

Firstly I don't know how did that IP address get entered in that file. I didn't enter it, is there any other system script which can do that.

hosts.deny is

sshd: 120.195.108.22
sshd: 95.130.12.64

hosts.allow

ALL:ALL
sshd: ALL

Is there any iptable setting that can override the host.deny file

© Server Fault or respective owner

Related posts about security

Related posts about iptables