Ho avuto circa 60 tentativi di accesso falliti oggi. E ce ne sono sempre di più.
Quindi sì, il server è protetto con una chiave SSH a 4096 bit (con passphrase). Il server ha installato Fail2ban e l'accesso root è disabilitato.
Oct 23 23:42:30 **** sshd[9726]: Received disconnect from ***: 11: [preauth]
Oct 24 17:15:13 *** sshd[10386]: Bad protocol version identification '6Oct 23 23:42:30 **** sshd[9726]: Received disconnect from ***: 11: [preauth]
Oct 24 17:15:13 *** sshd[10386]: Bad protocol version identification '6%pre%3%pre%1' from **** port 34017
Oct 24 03:57:30 * sshd[9929]: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "root"
Oct 24 03:57:32 * sshd[9929]: Failed password for root from * port 58904 ssh2
Oct 24 03:57:32 * unix_chkpwd[9932]: password check failed for user (root)
Oct 24 03:57:35 ** sshd[9929]: PAM 1 more authentication failure; logname = uid=0 euid=0 tty=ssh ruser= rhost=* user=root
Oct 23 14:59:16 * sshd[9389]: reverse mapping checking getaddrinfo for s aargo.com.mx [*] failed - POSSIBLE BREAK-IN ATTEMPT!
vps330608 sshd[8993]: Received disconnect from **: 11: Bye Bye [preauth]
vps330608 sshd[10393]: Received disconnect from **: 11: Closed due to user request. [preauth]
3%pre%1' from **** port 34017
Oct 24 03:57:30 * sshd[9929]: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "root"
Oct 24 03:57:32 * sshd[9929]: Failed password for root from * port 58904 ssh2
Oct 24 03:57:32 * unix_chkpwd[9932]: password check failed for user (root)
Oct 24 03:57:35 ** sshd[9929]: PAM 1 more authentication failure; logname = uid=0 euid=0 tty=ssh ruser= rhost=* user=root
Oct 23 14:59:16 * sshd[9389]: reverse mapping checking getaddrinfo for s aargo.com.mx [*] failed - POSSIBLE BREAK-IN ATTEMPT!
vps330608 sshd[8993]: Received disconnect from **: 11: Bye Bye [preauth]
vps330608 sshd[10393]: Received disconnect from **: 11: Closed due to user request. [preauth]
L'attacco Brute-Force è ancora in esecuzione ... Oltre 400 linee in / var / log / secure Fail2Ban continua a vietare Ip-Adresses. La maggior parte degli IP proviene dall'Italia / Francia. Server situato in Francia.
Qualche preoccupazione?
Saluti