Skip to content

Prevent evil bots on the web from hacking the server #26

@mblomdahl

Description

@mblomdahl

I just logged in to the server, a 4-5 days since last time around, and what do I find..?

[me@hq ~]$ sudo su -
[sudo] password for me: 
Last login: Tue Jan  5 13:46:18 CET 2021 on pts/0
Last failed login: Sat Jan  9 11:10:05 CET 2021 from 106.12.107.252 on ssh:notty
There were 52366 failed login attempts since the last successful login.
[root@hq ~]# df -h
/.../

Over 50 k failed login attempts to root account in less than a week.

Can we please add some software to keep track of these bots and forbid them from touching our server?

(And what does everyone else use? "Audit-to-allow" or whatever it's called?)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions