Om een idee te geven, dit is op m'n thuis machine van gister
en vandaag:
Sep 27 00:00:00 maelcum sshguard[1069]: Got exit signal, flushing blocked addresses and exiting...
Sep 27 00:00:00 maelcum sshguard[1558]: Started successfully [(a,p,s)=(4, 420, 1200)], now ready to scan.
Sep 27 02:16:03 maelcum sshd[1939]: Did not receive identification string from 222.221.12.11
Sep 27 02:31:05 maelcum sshd[1974]: Invalid user staff from 222.221.12.11
Sep 27 02:31:11 maelcum sshd[1979]: Invalid user sales from 222.221.12.11
Sep 27 02:31:16 maelcum sshd[1981]: Invalid user recruit from 222.221.12.11
Sep 27 02:31:21 maelcum sshd[1983]: Invalid user alias from 222.221.12.11
Sep 27 02:31:21 maelcum sshguard[1558]: Blocking 222.221.12.11: 4 failures over 16 seconds.
Sep 27 02:38:52 maelcum sshguard[1558]: Releasing 222.221.12.11 after 451 seconds.
Sep 27 06:40:52 maelcum sshd[3002]: Did not receive identification string from 222.90.65.251
Sep 27 06:46:11 maelcum sshd[3026]: Invalid user fluffy from 222.90.65.251
Sep 27 06:46:16 maelcum sshd[3028]: Invalid user admin from 222.90.65.251
Sep 27 06:46:22 maelcum sshd[3030]: Invalid user test from 222.90.65.251
Sep 27 06:46:27 maelcum sshd[3032]: Invalid user guest from 222.90.65.251
Sep 27 06:46:27 maelcum sshguard[1558]: Blocking 222.90.65.251: 4 failures over 16 seconds.
Sep 27 06:54:56 maelcum sshguard[1558]: Releasing 222.90.65.251 after 509 seconds.
Sep 27 19:52:14 maelcum sshd[5664]: Did not receive identification string from 200.26.155.250
Sep 27 22:28:13 maelcum sshd[6090]: Invalid user test from 200.26.155.250
Sep 28 00:00:01 maelcum sshguard[1558]: Got exit signal, flushing blocked addresses and exiting...
Sep 28 00:00:01 maelcum sshguard[6343]: Started successfully [(a,p,s)=(4, 420, 1200)], now ready to scan.
Sep 28 07:00:01 maelcum sshguard[6343]: Got exit signal, flushing blocked addresses and exiting...
Sep 28 07:00:01 maelcum sshguard[7808]: Started successfully [(a,p,s)=(4, 420, 1200)], now ready to scan.
Zonder sshguard had ik waarschijnlijk ook een paar duizend brute-force pogingen gehad. Nu worden ze even tijdelijk geblokkeerd in de firewall na een paar mislukte inlog pogingen. Uiteraard controleer ik alsnog regelmatig de logs want sommige volhouders gaan gewoon verder als de blokkade is opgeheven. Die blokkeer ik, handmatig, permanent op de firewall.