Re: OpenSSH keyboard-interactive authentication brute force vulnerability (MaxAuthTries bypass)

Posted by devel on Jul 18

Do you know if this is still affected if you have fail2ban in place.
Fail2ban uses the auth logs to monitor failed password attempts. I
assume that the auth log is still updated even if x number of attempts
is allowed. Thanks

Leave a Reply