Picking up a lot of failed authentications for various accounts

Posted by Josh K on Server Fault See other posts from Server Fault or by Josh K
Published on 2010-05-18T00:56:40Z Indexed on 2010/05/18 1:01 UTC
Read the original article Hit count: 264

My server is getting a lot of various failed authentication attempts for various accounts. The most common one (that I've seen ) or the root account.

I have since enabled Fail2Ban and ran several rootkit / malware checks to ensure I wasn't compromised. Is there anything else I should do? I only have three accounts enabled, and SSH access for only two. I have a full 48hr ban on anyone making more then six failed SSH login attempts. I do not have FTP enabled.

© Server Fault or respective owner

Related posts about server-security

Related posts about hardening