Skip to content

Prevent evil bots on the web from hacking the server #26

Description

@mblomdahl

I just logged in to the server, a 4-5 days since last time around, and what do I find..?

[me@hq ~]$ sudo su -
[sudo] password for me: 
Last login: Tue Jan  5 13:46:18 CET 2021 on pts/0
Last failed login: Sat Jan  9 11:10:05 CET 2021 from 106.12.107.252 on ssh:notty
There were 52366 failed login attempts since the last successful login.
[root@hq ~]# df -h
/.../

Over 50 k failed login attempts to root account in less than a week.

Can we please add some software to keep track of these bots and forbid them from touching our server?

(And what does everyone else use? "Audit-to-allow" or whatever it's called?)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions