|
From: Jos C. <ssh...@cl...> - 2016-09-05 12:16:26
|
Dear team,
Just to request a slightly different line on blocking earlier blocked IP
addresses:
Sep 5 13:23:56 ares kernel: Sep 5 13:23:56 ares sshguard[771]:
blacklist: added 116.209.118.176
Sep 5 13:23:56 ares sshguard[771]: 116.209.118.176: blocking forever (3
attacks in 7 secs, after 1 abuses over 7 secs)
Sep 5 13:23:56 ares kernel: Sep 5 13:23:56 ares sshguard[771]:
116.209.118.176: blocking forever (3 attacks in 7 secs, after 1 abuses
over 7 secs)
After blocking this ip you add this line:
Sep 5 13:23:56 ares sshguard[771]: 116.209.118.176: should already have
been blocked
Sep 5 13:23:56 ares kernel: Sep 5 13:23:56 ares sshguard[771]:
116.209.118.176: should already have been blocked
This is confusingas it reads that SSHGuard doesn't know whether it has
been blocked or not ("should have been blocked" - human line
interpretation).
Better(and more demanding) would be:
Sep 5 13:23:56 ares sshguard[771]: 116.209.118.176: has already been
blocked (forever)
Just thinking with your,
Jos Chrispijn
|