SSH brute force attacks
#4
I set mine up so only key-based login is accepted, and (via the firewall) only from RFC1918 addresses. (I have IPV6 completely firewalled off since I currently have no need to use it.)

If someone breaks in and just pokes around that can be difficult to detect. You can check your logs for suspicious entries. The default setup in Mobian is for systemd logs rather than traditional text logs, so they need to be viewed with journalctl. (Also once someone gets in and they gain root access they can purge the log.)

https://betterstack.com/community/guides...ournalctl/

There is also software available to detect root kits if someone breaks in and installs malware.

https://vitux.com/how-to-scan-a-debian-s...-rkhunter/

https://www.tecmint.com/scan-linux-for-m...-rootkits/
  Reply


Messages In This Thread
SSH brute force attacks - by user641 - 06-19-2022, 04:53 AM
RE: SSH brute force attacks - by jsch - 06-19-2022, 05:27 AM
RE: SSH brute force attacks - by user641 - 06-19-2022, 06:22 AM
RE: SSH brute force attacks - by Zebulon Walton - 06-19-2022, 06:39 AM
RE: SSH brute force attacks - by wibble - 06-20-2022, 01:42 AM
RE: SSH brute force attacks - by user641 - 06-20-2022, 03:42 AM
RE: SSH brute force attacks - by Zebulon Walton - 06-20-2022, 06:03 AM
RE: SSH brute force attacks - by wibble - 06-20-2022, 06:38 AM
RE: SSH brute force attacks - by user641 - 06-20-2022, 07:14 AM
RE: SSH brute force attacks - by wibble - 06-20-2022, 08:33 AM
RE: SSH brute force attacks - by user641 - 06-20-2022, 08:48 AM
RE: SSH brute force attacks - by bitnick - 06-21-2022, 11:38 AM
RE: SSH brute force attacks - by user641 - 06-21-2022, 04:45 PM
RE: SSH brute force attacks - by RTP - 06-23-2022, 12:49 PM

Forum Jump:


Users browsing this thread: 1 Guest(s)