This is data from auth.log over a timespan of 3 days. I have since moved the ssh port form 22 to a non default one.

    by rundowntomato

    12 Comments

    1. Twas I! Twas I whomst attempted the log in from Guadeloupe! And be warned mine dastardly deeds shall not end here!

    2. Nice collection! Good call on changing ports, also if you don’t use it yet, check out fail2ban, it’s very useful.

    3. StickyThickStick on

      Why is Russia so low? I make the IT Secruity of a student network and we get tens of thousands of port sniffers from russia a day. Second is Iran with a few thousand, followed by US and China

    4. I don’t know anytging about ssh – is the country of the target relevant for the hacker? For example, can a hacker target servers in a specific country?
      (Is it possible to tell which country a server is in via SSH?)

    5. Saw something similar from my side, just ended up blocking china & russia since I have no business (ever) with those IPs, safety increased, feels good man

    Leave A Reply