On Thursday 22 January 2009, Paul Hartman wrote: > I don't use PAM in sshd so I don't think that's my problem, but the > whole regexp thing is a possiblity in general as someone else > suggested. I will check into it tonight after work. Have you thought of using iptables to match the rate of new connections? Drop everything that comes in thick and fast and, or drop repeated attempts from a certain ip address. -- Regards, Mick