Should I Afraid? (Someone trying to connect my ssl)

October 12, 2017 119 views
Server Optimization CentOS

hi,5 minutes ago, I login to my VPS with username and password.
And there was a message that: "There were 142453 failed login attempts since the last successful login." (i login last night)

what should I do? someone is trying to find my password.
how can I solve this problem?

2 Answers

Yeah, people will always try to brute force there way into your servers.

Digital Ocean has a good guide on how to initial setup a server which covers securing SSH further than the default.

https://www.digitalocean.com/community/tutorials/initial-server-setup-with-ubuntu-16-04

Key Points

  • Use Public Key Authentication
  • Create a new user and disallow root login
  • Install Fail2Ban

You could change your SSH port but there is a bit of debate around that and personally, I leave it as default.

When you start a new server, there are a few steps that you should take every time to add some basic security and give you a solid foundation. In this guide, we'll walk you through the basic steps necessary to hit the ground running with Ubuntu 16.04.

Switch to a nonstandard SSH port
Disable password based authentication
Deploy fail2ban

Have another answer? Share your knowledge.