3 ms·
A few months ago I started noticing failed login attempts on my non standard SSH port (> port 1024) so I moved it up a few port numbers. About 2-3 weeks ago, I
by Caligatio 6y ago
A few months ago I started noticing failed login attempts on my non standard SSH port (> port 1024) so I moved it up a few port numbers. About 2-3 weeks ago, I noticed that it was getting hit again by failed login attempts. I then changed the port to the original and immediately started getting login attempts again... it kind of spooked me.
I thought about using fail2ban but every login is a different IP (using my eyeballs, I didn't parse the logs).
- LinuxBender 6y agoI take a different approach than fail2ban. My sftp servers use a standard port 22 and any time people try to log in, I create an account for them automatically via a cron job in the sftp-only group and a null password. The bots will spend years trying to log in repeatedly every few minutes. I have yet to see them upload anything interesting. Many years ago, bots would upload malware, then try to browse to it on port 80. But no more... These bots just want to get a shell and install malware / c&c tools. Some of them try port forwarding, but I have that restricted for the sftp users.
- aesh2Xa1 6y agoYou can still use fail2ban to block unique IP addresses if you use some supporting scripting. There's an example ([1]), which will check the IP addresses by country code. If they're all the same country then you can just block the whole country. You do not need to use firewalld, either, although this does. See the second link for something generic ([2]). [1] https://pagure.io/firewalld-blacklist/tree/master https://pagure.io/firewalld-blacklist/tree/master [2] https://www.linuxjournal.com/content/advanced-firewall-configurations-ipset https://www.linuxjournal.com/content/advanced-firewall-confi...