Tenemos alrededor de 60 intentos de inicio de sesión fallidos hoy. Y hay más y más.
Entonces, sí, el servidor está protegido con una clave SSH de 4096 bits (con frase de contraseña). El servidor tiene Fail2ban instalado y el inicio de sesión de raíz desactivado.
Oct 23 23:42:30 **** sshd[9726]: Received disconnect from ***: 11: [preauth]
Oct 24 17:15:13 *** sshd[10386]: Bad protocol version identification '6Oct 23 23:42:30 **** sshd[9726]: Received disconnect from ***: 11: [preauth]
Oct 24 17:15:13 *** sshd[10386]: Bad protocol version identification '6%pre%3%pre%1' from **** port 34017
Oct 24 03:57:30 * sshd[9929]: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "root"
Oct 24 03:57:32 * sshd[9929]: Failed password for root from * port 58904 ssh2
Oct 24 03:57:32 * unix_chkpwd[9932]: password check failed for user (root)
Oct 24 03:57:35 ** sshd[9929]: PAM 1 more authentication failure; logname = uid=0 euid=0 tty=ssh ruser= rhost=* user=root
Oct 23 14:59:16 * sshd[9389]: reverse mapping checking getaddrinfo for s aargo.com.mx [*] failed - POSSIBLE BREAK-IN ATTEMPT!
vps330608 sshd[8993]: Received disconnect from **: 11: Bye Bye [preauth]
vps330608 sshd[10393]: Received disconnect from **: 11: Closed due to user request. [preauth]
3%pre%1' from **** port 34017
Oct 24 03:57:30 * sshd[9929]: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "root"
Oct 24 03:57:32 * sshd[9929]: Failed password for root from * port 58904 ssh2
Oct 24 03:57:32 * unix_chkpwd[9932]: password check failed for user (root)
Oct 24 03:57:35 ** sshd[9929]: PAM 1 more authentication failure; logname = uid=0 euid=0 tty=ssh ruser= rhost=* user=root
Oct 23 14:59:16 * sshd[9389]: reverse mapping checking getaddrinfo for s aargo.com.mx [*] failed - POSSIBLE BREAK-IN ATTEMPT!
vps330608 sshd[8993]: Received disconnect from **: 11: Bye Bye [preauth]
vps330608 sshd[10393]: Received disconnect from **: 11: Closed due to user request. [preauth]
El ataque de fuerza bruta aún se está ejecutando ... Más de 400 líneas en / var / log / secure Fail2ban sigue prohibiendo las direcciones IP. La mayoría de los IP son de Italia / Francia. Servidor ubicado en Francia.
¿Alguna preocupación?
Saludos