So, I was looking at my logwatch report the other day, and saw one of my webservers was getting hammered via sshd. No big surprise, it happens, but, I started thinking about denyhosts, which was suggested to me by a friend a while back. It may work, but because its a log parsing application, it falls prey to a couple of oportunities which I am not interested in. Such as spoofing the user/pass name on the SSHD log to lock the localhost out, or to lock out the root user.