#persourcepenalties
OpenSSH 9.6 introduit PerSourcePenalties et PerSourcePenaltyExemptList, permettant de pénaliser les comportements non souhaités des clients SSH. Ces options renforcent la sécurité en compliquant les tentatives de force brute et autres attaques.
-> undeadly.org/cgi?act...
June 11, 2024 at 11:35 AM
OpenSSH introduces options to penalize undesirable behavior
www.undeadly.org
June 7, 2024 at 4:52 AM
2024年7月1日にリリースされたOpenSSH 9.8は繰り返し認証失敗するアクセス元IPアドレスに対して一時的にアクセス遮断するオプションPerSourcePenaltiesが追加されたらしい。fail2banのようなことがOpenSSHだけでできるようになると。
Chris's Wiki :: blog/sysadmin/OpenSSHPerSourcePenaltiesThings
utcc.utoronto.ca
August 17, 2024 at 12:44 PM
CVE-2025-26466
認証前に攻撃者がCPUとメモリを大量消費させることで、サーバーを過負荷状態にするDoS攻撃が可能。
OpenSSH9.5p1~9.9p1(2023年8月以降)に影響。
サーバー側ではLoginGraceTime、MaxStartups、PerSourcePenaltiesで部分的に軽減可能。
February 18, 2025 at 4:12 PM
11/16

default). This was not mitigated by MaxAuthTries, but would be
penalised by PerSourcePenalties. This was reported by Manfred
Kaiser of the milCERT AT (Austrian Ministry of Defence).
sshd(8): fix a number of cases where the minimum authentication
July 7, 2026 at 12:01 AM
Some thoughts on OpenSSH 9.8's PerSourcePenalties feature Discussion
Chris's Wiki :: blog/sysadmin/OpenSSHPerSourcePenaltiesThings
utcc.utoronto.ca
August 14, 2024 at 8:20 PM
I see it is Digital Ocean hosted mass SSH brute force attempts o'clock. Again. Unlike the usual brute forcers, these people don't give up when they're blocked, they keep on hammering.

I'm looking forward to Ubuntu 26.04, when we will have PerSourcePenalties in SSHD and these people will go away […]
Original post on mastodon.social
mastodon.social
March 3, 2026 at 4:22 PM
Some thoughts on OpenSSH 9.8's PerSourcePenalties feature
Chris's Wiki :: blog/sysadmin/OpenSSHPerSourcePenaltiesThings
Some thoughts on OpenSSH 9.8's PerSourcePenalties feature
utcc.utoronto.ca
August 14, 2024 at 11:52 PM
💡 Summary by GPT3:

Damien Millerは、望ましくない動作にペナルティを科し、特定のクライアントをペナルティから保護するための新しいsshd(8)の設定オプション、PerSourcePenaltiesとPerSourcePenaltyExemptListを導入しました。これらのオプションは、クライアントの動作を監視し、繰り返し失敗した認証試行やsshdを悪用しようとする試行に対してペナルティを科します。PerSourcePenaltiesは、OpenBSD 7.6ではデフォルトで有効になり、 (1/2)
June 8, 2024 at 1:43 AM
Fail2Ban больше не нужен? Разбираем PerSourcePenalties в OpenSSH на Ubuntu 26.04 Начиная с OpenSSH 9.7, sshd умеет автоматически ограничи...

#OpeSSH #ubuntu-server #информационная #безопасность #системное #администрирование

Origin | Interest | Match
May 7, 2026 at 6:02 PM
Some thoughts on OpenSSH 9.8's PerSourcePenalties feature (utcc.utoronto.ca)

Main Link | Discussion
August 14, 2024 at 6:04 PM
Some thoughts on OpenSSH 9.8's PerSourcePenalties feature (utcc.utoronto.ca)

Main Link | Discussion
August 14, 2024 at 6:03 PM