This is for members who have a web hosting accounts. My server informs me whenever theirs been an attempt to access root. I get about 8 emails a day of random ips (mostly in china) trying to gain access. Is this typical?
I'm surprised it's that low.
We blocked South America once .. attempts went way down.
Right now the firewall seems to be doing a descent job from what i can tell. Once the Ip tries to login 5 times it is permanently blocked. Also if anyone ever gains root I get an email. I just think its pretty messed up that theirs all these groups scouring the internet just to find an open door.
I taught lil rudeguy how to ban Canada on his server. I've never seen him so happy.
hi tony!
First post a year after registering? You have some mighty fine restraint.
Pics of your sister?
It's been a busy 3 years for me. Joined the Army, went to iraq, came back from the sand pit, now getting out![]()
Thanks :thumbsup:
I'm surprised it's that low.
Things you can do to lower your risk
1) Change SSH ports
2) Disable ROOT logins via SSH
3) Require public/private keys + passphrase for login
4) Install fail2ban
5) Use port knocking
I joined in 2007, signed up for 4 years...deployed in 2009 as a Military Intelligence Analyst (same job as that Manning dumbass). Came back after a year and now I'll be getting out in 2 months...w00t!
#4 is the best choice, in my opinion. There's an easier way to do it with iptables (Linux) or pf (FreeBSD) that makes fail2ban not needed... I can post the one line ruleset if you'd like.
Lay it on me, thought I think the firewall has been doing a good job. It's always good to learn something new![]()
Hell yeah, you going to school now?
What OS? What distro?
