SSHGuard!

* Written in small, portable C and Bourne shell with ~3000 LOC * Simple, extensible firewall interface * Download http://sshguard.net/download/
* Source code https://sourceforge.net/projects/sshguard/files/sshguard/
* Git repository https://bitbucket.org/sshguard/sshguard/
* Documentation http://sshguard.net/docs/
* Installation http://sshguard.net/docs/setup/
* Whitelisting http://sshguard.net/docs/whitelist/
* Security http://sshguard.net/docs/security/

SSHGuard alternatives

  • Fail2ban

  • Fail2ban scans log files (e.g. /var/log/apache/error_log) and bans IPs that show the malicious signs -- too many password failures, seeking for exploits, etc. Generally Fail2Ban is then used to update firewall rules to reject the IP addresses for a specified amount of time, although any arbitrary other action (e.g. sending an email) could also be configured. Out of the box Fail2Ban comes with filters for various services (apache, courier, ssh, etc).

    tags: firewall security-utilities internet-filter iptables ip-blocking
  • Denyhosts

  • The idea of denying access to SSH servers is nothing new and I was inspired by many other scripts that I discovered. However, none of them did things the way I envisioned them to. Also, they were all shell scripts which do not offer the elegance of Python.

    tags: daemon bruteforce web-log-analyzer ssh-bruteforce
  • IPQ BDB

  • IPQ BDB filtering is done by a user space netfilter daemon that issues verdicts after looking up the IP address in a Berkeley DB. The fuzzy blocking model, freely inspired by STOCKADE, is designed to block non-distributed dictionary attacks and mitigate spam.

    tags: firewall gnu iptables
  • RdpGuard

  • RdpGuard allows you to protect your Remote Desktop (RDP) from brute-force attacks by blocking attacker's IP address. Fail2Ban for Windows.

    tags: remote-desktop-access rdp
  • IPBan

  • A FREE and open source application that allows banning ip addresses from failed terminal services or SQL server logins out of the box. Other types of banning are easily added via an application configuration file.

    tags: remote-desktop-access terminal-services
  • HeatShield

  • HeatShield is a network firewall management service for Linux servers. A firewall configured by HeatShield prevents unauthorized access to services running on your servers, such as SSH and MySQL. Using HeatShield, you can easily restrict access to these services so that only IP addresses you trust are allowed to communicate with your servers.

    tags: firewall server-management firewall-management bruteforce iptables
  • e.guardo Smart Defender

  • e.guardo protects your RDP, MSSQL, FTP, SMTP, EXCHANGE, OWA, LYNC, MICROSOFT DYNAMICS CRM, SHAREPOINT and many more services from Brute Force and Dictionary Attacks

    tags: online-service heuristic-detection hacker-protection ddos-protection brute-force-protection
  • ACRIBA logdog

  • logdog - Comparable with fail2ban but based on Java and optimized for high performance.

    tags: firewall-management log-scanner
  • LF Intrusion Detection

  • Lit Fuse Intrusion Detection (LID) protects your Windows system from brute force attacks and other intrusion attempts by placing a brick wall between your server and would-be hackers. Lightweight and lightning-fast, our software keeps an eye on your network traffic 24/7, watching for suspicious activity.

    tags: security-and-privacy rdp-client autoblock fail2ban rdp-server
  • SpyLog

  • lua-spylog - Execute actions based on log records

    tags: autoblock brute-force-protection bruteforce protection rdp-protection