Logging Login Attempts

Perry Wagle wagle at mac.com
Fri Oct 8 06:39:13 EST 2010


LogLevel VERBOSE logs the ipaddress of the attempt on a "signon that exists", but not which signon name.

-- Perry


On Oct 7, 2010, at 9:51 AM, Iain Morgan wrote:

> On Wed, Oct 06, 2010 at 18:07:29 -0500, Perry Wagle wrote:
>> I have passwords turned off, and require keys to match.  The zombie armies swarming outside are trying brute force attacks that in part involve guessing login NAMES.  If they guess the wrong NAME, this is logged in syslog.  If they guess a working user name, then the attack has PARTIALLY SUCCEEDED, but this information is IGNORED.  That is, it is not logged.  If the zombie army has tell when it has found a working user name, then it might concentrate on finding its key, and I will be none the wiser.  I will not see that happening.
>> 
>> I can get this info by turning logging to DEBUG, but then it is very noisy.  I do not understand why failed attempts to login to my account are not logged.
>> 
>> Why is this, and how do I get it fixed?
> 
> Try verbose rather than debug.



More information about the openssh-unix-dev mailing list