FreshPorts -- The Place For Ports Tue, 9 Feb 2010 8:11 PM GMT
Do I have any twitter.com followers? I'd like to get control of twitter.com/pgcon, since I run pgcon...
Port details
sshit 0.6_4 security on this many watch lists=7 search for ports that depend on this port
Checks for SSH/FTP bruteforce and blocks given IPs
Maintained by: rafan@FreeBSD.org search for ports maintained by this maintainer
Port Added: 18 Dec 2005 16:05:26


sshit is a perl script, which works along with ipfw, ipfw2, and pf.
It parses the output of syslogd, find out SSH/FTP bruteforce attacks.
If the number of failed login is more than a threshold that administarator
set, sshit will block the source IP via firewall for a while 
(administrators can set the period of blocking). 

WWW: http://anp.ath.cx/sshit/
CVSWeb : Sources : Main Web Site : Distfiles Availability : PortsMon
Required To Run: sysutils/p5-Unix-Syslog, devel/p5-IPC-Shareable, devel/p5-Proc-PID-File, lang/perl5.8

To install the port: cd /usr/ports/security/sshit/ && make install clean
To add the package: pkg_add -r sshit


Configuration Options
     No options to configure

Master Sites:
http://anp.ath.cx/sshit/
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/local-distfiles/
ftp://ftp.se.FreeBSD.org/pub/FreeBSD/ports/local-distfiles/
ftp://ftp.uk.FreeBSD.org/pub/FreeBSD/ports/local-distfiles/
ftp://ftp.ru.FreeBSD.org/pub/FreeBSD/ports/local-distfiles/
ftp://ftp.jp.FreeBSD.org/pub/FreeBSD/ports/local-distfiles/
ftp://ftp.tw.FreeBSD.org/pub/FreeBSD/ports/local-distfiles/
ftp://ftp.cn.FreeBSD.org/pub/FreeBSD/ports/local-distfiles/
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/distfiles/

Number of commits found: 8

Commit History - (may be incomplete: see CVSWeb link above for full details)
DateByDescription
10 May 2008 06:51:26
Original commit files touched by this commit  0.6_4
rafan search for other commits by this committer
- Always refer to perl by ${PERL}
- Bump PORTREVISION
07 Nov 2007 07:27:11
Original commit files touched by this commit  0.6_3
rafan search for other commits by this committer
- After last update, sshit keeps exiting with signal 15 due to wrong
  hostname regexp. Fix the regexp for hostname matching.
- While fixing that, fix IPv6 regexp, too.
- Reduce syslog level from ERROR to INFO for most informational messages.

These changes are submitted to author for inclusion in next version.

- Grab maintainership as current maintainer does not use it anymore.
- Bump PORTREVISION.

Approved by:    portmgr (linimon), maintainer via irc
18 Sep 2007 14:16:12
Original commit files touched by this commit  0.6_2
tabthorpe search for other commits by this committer
- make work with fqdn
- bump PORTREVISION

PR:             ports/115210
Submitted by:   Alex Keda <admin_AT_lissyara.su>
Approved by:    Jui-Nan Lin (maintainer), clsung (mentor)
08 Sep 2007 02:04:03
Original commit files touched by this commit  0.6_1
linimon search for other commits by this committer
Welcome bsd.perl.mk.  Add support for constructs such as USE_PERL5=5.8.0+.
Drop support for antique perl.

Work done by:   gabor
Sponsored by:   Google Summer of Code 2007
Hat:            portmgr
02 Jul 2007 09:36:13
Original commit files touched by this commit  0.6_1
rafan search for other commits by this committer
- Make sshit catch this type of error login:

PAM: authentication error for lissyara from 192.168.254.193

PR:             ports/114194
Submitted by:   Alex Keda <admin at lissyara.su>
Approved by:    maintainer via irc
03 Nov 2006 16:01:32
Original commit files touched by this commit  0.6
clsung search for other commits by this committer
- Update to 0.6

PR:             ports/104770
Submitted by:   Joe Horn <joehorn_AT_leobbs dot net>
Approved by:    maintainer (Jui-Nan Lin)
27 Jul 2006 11:32:56
Original commit files touched by this commit  0.5_1
rafan search for other commits by this committer
(c) Rong-En Fan's, http://rafan.infor.org/patch/sshit.diff

In the code, the author uses two level hash, and IPC::Shareable
will create a share memory for those anonymouse object (the second
level hash). Those share memory will not be removed when sshit exists
or when the rule is removed. Running sshit for a period of time,
the number of share memory and semaphore will reach the limit for
one process, then sshit.pl can not get more share memory, thus it
quits. The only solution is to manually remove all share memory and
semaphore.

This is somehow the limitation of using IPC::Shareable. To workaround
this problem. The patch will removes associated firewall rules when
syslogd closes the fd [1], and use IPC::Shareable->clean_up
to remove all shm/sem created by this process. I also set 'destroy'
(Only the first 15 lines of the commit message are shown above View all of this commit message)
18 Dec 2005 16:03:28
Original commit files touched by this commit  0.5
vanilla search for other commits by this committer
Add sshit 0.5, checks for SSH/FTP bruteforce and blocks given IPs.

PR:             ports/90603
Submitted by:   Jui-Nan Lin <jnlin@csie.nctu.edu.tw>

Number of commits found: 8

Login
User Login
Create account

Servers and bandwidth provided by
New York Internet
SuperNews

Search
Enter Keywords:
 
more...

Latest Vulnerabilities
otrsFeb 08
otrsFeb 08
apache13*Feb 03
apache13*Feb 03
apache13+ipv6*Feb 03
apache13-modperl*Feb 03
apache13-modssl*Feb 03
apache13-modssl*Feb 03
apache13-modssl+ipv6*Feb 03
apache13-ssl*Feb 03
squid*Feb 02
squid30*Feb 02
squid31*Feb 02
bugzillaFeb 01
ircd-ratboxJan 28

5 vulnerabilities affecting 16 ports have been reported in the past 14 days

* - modified, not new

All vulnerabilities


Ports
Home
Categories
Deleted ports
Sanity Test Failures
Newsfeeds


Statistics
Graphs
NEW Graphs (Javascript)
Traffic

Calculated hourly:
Port count 21261
Broken 171
Deprecated 36
Ignore 905
Forbidden 2
Restricted 386
No CDROM 142
Vulnerable 56
Expired 14
Set to expire 25
Interactive 79
new 24 hours 6
new 48 hours8
new 7 days28
new fortnight87
new month197

This site
What is FreshPorts?
About the Authors
FAQ
How big is it?
The latest upgrade!
Privacy
Forums
Blog
Contact

Add tab to Netscape 6

Servers and bandwidth provided by
New York Internet
SuperNews
Valid HTML, CSS, and RSS.
Copyright © 2000-2008 DVL Software Limited. All rights reserved.
This page created in 0.059 seconds.