Report this

What is the reason for this report?

Login Attempts: Is this usual?

Posted on December 10, 2013
roht

By roht

When I ssh into my droplet, it reads out:

There were 670 failed login attempts since the last successful login.

Is this usual? Am I supposed to be concerned?



This textbox defaults to using Markdown to format your answer.

You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!

These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.

Q:\ Is this usual? <br>A:\ It is usual and common on servers facing the internet. These internet facing servers are being scanned for open ports by malicious users everyday all day. <br> <br>Q:\ Am I supposed to be concerned? <br>A:\ Yes, you should be concerned as your server might get compromised. <br> <br>Tip: You can check the Failed login attempts with: <br> sudo cat /var/log/secure | grep Failed <br> <br>

I recommend installing fail2ban (see joshuataylorx’s link above) and using SSH keys while disabling password authentication: <a href=“https://www.digitalocean.com/community/articles/how-to-set-up-ssh-keys--2”>https://www.digitalocean.com/community/articles/how-to-set-up-ssh-keys--2</a>

The developer cloud

Scale up as you grow — whether you're running one virtual machine or ten thousand.

Get started for free

Sign up and get $200 in credit for your first 60 days with DigitalOcean.*

*This promotional offer applies to new accounts only.