My home server got hit with a weird login attempt from Brazil last night | Cybersecurity Tips - Freelance Forum - The Community for Independent Professionals
My home server got hit with a weird login attempt from Brazil last night
I saw the alert in my logs around 2 AM, and it was trying a bunch of common usernames like 'admin' and 'root'. I just shut down the port forwarding rule I had set up for remote access. Has anyone else had this happen and found a better way to keep an eye on things?
Used to think keeping port forwarding up and just having a strong password was enough. But after getting pinged with like 50 login attempts in one night from some random IP, I totally get why fail2ban is the way to go. Changed my mind real quick on that.
Welcome to the club, my server logs look like a failed UN summit. Had a bot from Russia try 'password' as the root password for six hours straight. Setting up fail2ban was a game changer, it auto-blocks those clowns after a few tries. What are you running on that server anyway?
Honestly, shutting down the port forward was the right move, that's your first line of defense. Ngl, my logs look like a world tour some days, with script kiddies trying the same old admin and root combos. I just set up fail2ban to automatically block those IPs after a few tries, it cuts down on the noise.