Re: Brute force attacks



Welcome to the Internet! :)

Seriously, my open SSH ports get minimal brute force attacks daily, typically anywhere from 2 attempts to a couple thousand. Watch these long enough and you can see that while they come randomly and from different IPs, the same battery of username/password combinations tend to get used.

In other words, you may be experiencing normal random junk from automated scanning systems from the Internet.

And there is not much you can do about it.

You could block their IPs on your border, but be careful what you block in case you have business that comes from there.

My best practice is to just be aware of it and block if it starts to impact services/bandwidth or just block if you know you can safely do that. Keep those services hardened and accounts safely limited and protected with complex, regularly rotated passwords.


<- snip ->
Hi List,

I've been experiencing brute force dictionary attacks from various
sources against my gateway. The attacker is trying all kinds of
username/password combinations to get in.

I have traced the source IP addresses on internet authorities such as
Ripe, Arin & Apnic; the feedback I get is that "Country is really world
wide". I then traced the IPs using visual route, and saw that their
locations vary widely; some of them are in the US, some in China, others
in Poland...

What are my options in such a case? Have you ever experienced such a
behavior? And what are the best practices that apply?

Thank you,

-Mohamad.



Relevant Pages

  • Re: Message with attachments greater than 300K take forever to go out or do not go through
    ... We are experiencing a similar situation and I am trying to troubleshoot it. ... We use wireless DSL and have a Sonicwall between LAN and WAN which serves as ... Our internet access has been very slow for ... SP2 install on Exchange ...
    (microsoft.public.windows.server.sbs)
  • RE: all usb ports not communicating
    ... > They are internal and show as working properly in device manager. ... problem as you are experiencing. ... re-install this so-called operating system. ... And NEVER connect to the Internet! ...
    (microsoft.public.windowsxp.general)
  • internet explorer error
    ... I'm also experiencing the same problem and I also tried ... I start Internet ... >Explorer and goes immediately into "Microsoft Internet ... after going round and round ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Materialist Evolutionists
    ... experiencing, despite any evidence to the contrary. ... for the internet. ... You then have an array of computers work through the log ...
    (talk.origins)
  • Re: Computer takes a long time to "wake up"
    ... | Hello there,I have been experiencing long delays opening IE or OE every ... | after the computer goes into the Screen Saver mode,I am talking about ... Internet connection and how you have it set up. ...
    (microsoft.public.windowsxp.basics)

Loading