- Code: Select all
ALL: ALL
I thought this would be enough to enforce /etc/hosts.deny so that all remote login attempts from foreign IPs would be blocked. However, when I check the login attempts with
- Code: Select all
grep "Failed password" /var/log/auth.log
- Code: Select all
May 11 16:57:22 myserver sshd[369786]: Failed password for invalid user vbox from 165.227.142.62 port 58324 ssh2
May 11 16:57:45 myserver sshd[371196]: Failed password for invalid user cc from 104.248.140.201 port 60568 ssh2
May 11 16:57:50 myserver sshd[372568]: Failed password for root from 178.62.63.165 port 48988 ssh2
May 11 16:57:53 myserver sshd[372603]: Failed password for root from 157.230.1.224 port 59400 ssh2
May 11 16:58:05 myserver sshd[372610]: Failed password for invalid user dns from 165.227.142.62 port 39930 ssh2
May 11 16:58:06 myserver sshd[372608]: Failed password for root from 49.234.24.246 port 54290 ssh2