I'm a server admin of sorts...not by choice, but I've got the job. Now things have been quiet lately, until this morning. My normal security logs are about 10-12k in size when they rotate every week, and today I noticed that one server it was 150k. In 2 days. So I take a look, like any good admin would do.
500+ SSH login attempts from this ip: 218.145.54.195
I check the next server: same thing. The next server: same thing.
Between 500 and 540 login attempts from that IP address on all my servers.
The ip is from somewhere in korea, and just on the odd chance that someone might have run into him before, I google'd it and this came up:
<a target=_blank class=ftalternatingbarlinklarge href="https://www.redhat.com/archives/fedora-list/2005-January/msg05519.html">https://www.redhat.com/archives/fedora-list/2005-January/msg05519.html</a>
A quick excerpt:
So this person has, for 2 months at least, been brute attacking servers from the SAME IP and no one has done a thing about it?
Anywho, this pissed me off and I want to know if there is anything I can do.
*edit* this probably should be moved to off-topic...thought I created it there.
500+ SSH login attempts from this ip: 218.145.54.195
I check the next server: same thing. The next server: same thing.
Between 500 and 540 login attempts from that IP address on all my servers.
The ip is from somewhere in korea, and just on the odd chance that someone might have run into him before, I google'd it and this came up:
<a target=_blank class=ftalternatingbarlinklarge href="https://www.redhat.com/archives/fedora-list/2005-January/msg05519.html">https://www.redhat.com/archives/fedora-list/2005-January/msg05519.html</a>
A quick excerpt:
Hello everyone,
My Logwatch report this moring is below. It appears that IP
218.145.54.195 has attempted to connect to my SSH daemon 500 times.
So this person has, for 2 months at least, been brute attacking servers from the SAME IP and no one has done a thing about it?
Anywho, this pissed me off and I want to know if there is anything I can do.
*edit* this probably should be moved to off-topic...thought I created it there.