Between my own stuff and that of clients I currently manage 11 servers in various configurations... I'm used to reasonable amounts of ssh/ftp/smtp brute force attempts in the fail2ban logs, but the past three days it's been a roller-coaster ride of entire IP blocks from the Ukraine, Russia, and ... get this .. Seychelles. All the IP address ranges correspond not to home coections but data centers so I'm just dropping the entire 0..255 blocks with iptables, but I find it odd that multiple servers (linsux and winblows) in different data centers, with different codebases are all seeing a sudden spike from the same regions. More strange is that all the attempts seem to be going after SMTP logins as it's always postfix that F2b is logging.
Thankfully fail2ban giving those nice timeouts drags brute-force attempts to a crawl, but not when they can throw a thousand or more IP addresses at me.
I was almost ready to blame it on the apt-get update/upgrade I did over the weekend on my VPS until I noticed the same thing on some client's Windows hosting in RDPGuard -- including some of the same address blocks.
"just me" or has anyone else noticed a similar upswing in failed login attempts, particularly for SMTP? I'm used to small variations but not a sudden gatling coect approach like this. My normal fail2ban log on one of my VPS is 4k a month. This was 1500k in two and a half days!
برچسب:
نویسنده: آیلین رضوانی
تاريخ: سه
شنبه
19 دی
1396 ساعت: 17:24