On Tue, 23 Dec 2014, Dick Steffens wrote:

> On 12/23/2014 07:51 AM, Rich Shepard wrote:
>>     Last Thursday or Friday the daily log reports showed fewer cracking
>> attempts via ssh. The number (and types) decreased over the weekend and
>> today there's nothing. Historically, there are hundreds to tens-of-thousands
>> probes each day attempting to use ssh to enter my network. Not seeing any is
>> an issue needing resolution.
>>
>>     I wonder if this might be related to the DNS change that separates
>> appl-ecosys.com (the web site name hosted at my ISP) from
>> mail.appl-ecosys.com hosted here with the ever-changing dynamic IP address.

The change is likely caused by your dynamic IP address. I just tried to 
connect to your server and everything, from an ssh perspective, looks 
fine. Take solace in the time without attack traffic because without a 
doubt the bad behavior will return.

Over the last few hours I've seen ssh attacks from these TLDs:

     .cn,.ru,.jp,.kr,.uk,.net,.com,.pt,.it,.fr,.de

to my home network.
_______________________________________________
PLUG mailing list
[email protected]
http://lists.pdxlinux.org/mailman/listinfo/plug

Reply via email to