Control Web Panel
Security => CSF Firewall => Topic started by: facata on March 18, 2021, 07:09:21 AM
-
Hello everybody.
I keep receiving e-mail about block IP like this:
lfd: (sshd) Failed SSH login from 221.181.185.141 (CN/China/-): 5 in the last 3600 secs - Fri Mar 5 15:09:57 2021
lfd: (sshd) Failed SSH login from 179.112.119.206 (BR/Brazil/179-112-119-206.user.vivozap.com.br): 5 in the last 3600 secs - Fri Mar 5 16:14:05 2021
lfd: (sshd) Failed SSH login from 222.187.222.55 (CN/China/-): 5 in the last 3600 secs - Fri Mar 5 17:57:38 2021
lfd: (sshd) Failed SSH login from 12.221.85.22 (US/United States/-): 5 in the last 3600 secs - Fri Mar 5 18:03:49 2021
Is this normal ? Can I stop this ? Or can I change port ???
thanks
-
its bruteforce attack by the kid hackers but beware they can be successful if your password is small and dictionary based
-
Is it possible to stop this by disabling ssh log in shell or changing a port ???
-
yes we recommend always to change ssh port
-
ok thanks I will do that....