I use an iptables script setup that will add the ip address of someone
attempting to log into my servers with an invalid name or any of the common
services. The block list I have now has grown pretty large from all the
scans, but once in the blocked list they get cut off from all services.

> What are your thoughts on running a block list derived from the denyhosts
> network data on your firewall?
> I guess that the block list could be polluted by someone using the
> injection technique across a large number of hosts, but how likely is that?
