ATTEMPTED LOGGINS


shushi1010

Recommended Posts

On Feb 20 there were 52259 invalid login attempts. This could either be yourself attempting to login to your server (SSH / Telnet) with the wrong user or password, or you could be actively be the victim of hack attacks. A common cause of this would be placing your server within your routers DMZ, or improperly forwarding ports.

This is a major issue and needs to be addressed IMMEDIATELY

NOTE: Because this check is done against the logged entries in the syslog, the only way to clear it is to either increase the number of allowed invalid logins per day (if determined that it is not a hack attempt) or to reset your server. It is not recommended under any circumstance to ignore this error

 

any ideas what I need to do to protect the server?

overse-diagnostics-20220221-1004.zip

Link to comment

Interesting.  Thanks for that.

 

The reason I asked is that Netgear ARMOR (their router security scanner) has been the subject of several similar threads.  Your syslog looked a bit different (login attempt methodology), but if replacing the router eliminated it (and it doesn't return) you may likely found the source.

 

If you would like, you could look through the RT-AX86U setup screens, and see if turning on/off security packages in the AiProtection tabs eliminates the issue.  I quick look at the User manual states that it turns on a number of protection packages when you run their security scan.

Edited by ConnerVT
speeling
Link to comment

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.