02-07-2019, 02:30 PM
I have experienced it. I think it was an attempted Brute Force attack
Because it broke the breakdown number of 81K
So I suggest using IPtables as a protection against this attack
/sbin/iptables -D INPUT -p tcp -m multiport --dports 22 -m conntrack --ctstate NEW -m recent --set --name antibrute
/sbin/iptables -D INPUT -p tcp -m multiport --dports 22 -m conntrack --ctstate NEW -m recent --update --seconds 3600000 --hitcount 1 -j DROP --name antibrute
Because it broke the breakdown number of 81K
So I suggest using IPtables as a protection against this attack
/sbin/iptables -D INPUT -p tcp -m multiport --dports 22 -m conntrack --ctstate NEW -m recent --set --name antibrute
/sbin/iptables -D INPUT -p tcp -m multiport --dports 22 -m conntrack --ctstate NEW -m recent --update --seconds 3600000 --hitcount 1 -j DROP --name antibrute