Re: [tor-relays] SSH brute force attempts to connect to my Middle Relay IP address

2017-10-04 Thread Igor Mitrofanov
: [tor-relays] SSH brute force attempts to connect to my Middle Relay IP address > On 4 Oct 2017, at 02:26, Igor Mitrofanov <igor.n.mitrofa...@gmail.com> wrote: > > I have setup a (private, key-based) Tor hidden service for SSH administration. It works well and leaves no extra open

Re: [tor-relays] SSH brute force attempts to connect to my Middle Relay IP address

2017-10-04 Thread Jonathan Proulx
still have no response on what triggered that so can't provide any more detail, just eventually went away on it's own. -Jon : :regards, Robin : :- Original message - :From: Fr33d0m4all <fr33d0m4...@riseup.net> :To: tor-relays@lists.torproject.org :Subject: [tor-relays] SSH brut

Re: [tor-relays] SSH brute force attempts to connect to my Middle Relay IP address

2017-10-04 Thread Robin
relays@lists.torproject.org Subject: [tor-relays] SSH brute force attempts to connect to my Middle Relay IP address Date: Wed, 4 Oct 2017 08:02:55 +0200 Hi, My Tor middle relay public IP address is victim of SSH brute force connections’ attempts and the attack is going on since two weeks ago

Re: [tor-relays] SSH brute force attempts to connect to my Middle Relay IP address

2017-10-04 Thread teor
> On 4 Oct 2017, at 02:26, Igor Mitrofanov wrote: > > I have setup a (private, key-based) Tor hidden service for SSH > administration. It works well and leaves no extra open ports to attack. > > If you also take advantage of package updates over Tor (via the local

Re: [tor-relays] SSH brute force attempts to connect to my Middle Relay IP address

2017-10-04 Thread Thomas Dünser
Hi, could it help to use ||iptables to limit to 3 attempts per minute, or to use Fail2ban? Regards Tom On 10/04/2017 01:07 PM, Martin Møller Skarbiniks Pedersen wrote: > On 4 October 2017 at 08:41, Fr33d0m4all > wrote: > > > > I know, I

Re: [tor-relays] SSH brute force attempts to connect to my Middle Relay IP address

2017-10-04 Thread Martin Møller Skarbiniks Pedersen
On 4 October 2017 at 08:41, Fr33d0m4all wrote: > > I know, I know about how internet works :) I’ve just simply noted a large increase in SSH brute force attempts in the last two weeks. BTW I don’t have root login enabled and I have two factor authentication on my SSH port

Re: [tor-relays] SSH brute force attempts to connect to my Middle Relay IP address

2017-10-04 Thread Santiago
El 04/10/17 a las 08:41, Fr33d0m4all escribió: > I know, I know about how internet works :) I’ve just simply noted a large > increase in SSH brute force attempts in the last two weeks. BTW I don’t have > root login enabled and I have two factor authentication on my SSH port (not > standard),

Re: [tor-relays] SSH brute force attempts to connect to my Middle Relay IP address

2017-10-04 Thread Fr33d0m4all
I know, I know about how internet works :) I’ve just simply noted a large increase in SSH brute force attempts in the last two weeks. BTW I don’t have root login enabled and I have two factor authentication on my SSH port (not standard), which is enabled only for a single low privileges user,

Re: [tor-relays] SSH brute force attempts to connect to my Middle Relay IP address

2017-10-04 Thread Sean Greenslade
On October 3, 2017 11:02:55 PM PDT, Fr33d0m4all wrote: >Hi, >My Tor middle relay public IP address is victim of SSH brute force >connections’ attempts and the attack is going on since two weeks ago. >It’s not a problem, the server that is listening with SSH on the same >IP

Re: [tor-relays] SSH brute force attempts to connect to my Middle Relay IP address

2017-10-04 Thread Gareth Llewellyn
Original Message On 4 Oct 2017, 07:02, Fr33d0m4all wrote: Hi, My Tor middle relay public IP address is victim of SSH brute force connections’ attempts Welcome to the Internet! Any Internet connected machine will be port scanned, vuln probed, brute forced, blindly hit with

Re: [tor-relays] SSH brute force attempts to connect to my Middle Relay IP address

2017-10-04 Thread Igor Mitrofanov
Message- From: tor-relays [mailto:tor-relays-boun...@lists.torproject.org] On Behalf Of Fr33d0m4all Sent: Tuesday, October 3, 2017 11:03 PM To: tor-relays@lists.torproject.org Subject: [tor-relays] SSH brute force attempts to connect to my Middle Relay IP address Hi, My Tor middle relay public IP

[tor-relays] SSH brute force attempts to connect to my Middle Relay IP address

2017-10-04 Thread Fr33d0m4all
Hi, My Tor middle relay public IP address is victim of SSH brute force connections’ attempts and the attack is going on since two weeks ago. It’s not a problem, the server that is listening with SSH on the same IP address than my Tor relay blocks the connections and bans the IP addresses (with