Le fail2ban ne sert pas à grand chose mis à part à limiter tes logs. J’ai mis une limite chez moi à 5 minutes et voilà ce que j’obtiens en ce moment
[...]
May 12 09:17:48 cerbere sshd[30179]: Failed password for root from 58.218.205.68 port 40706 ssh2
May 12 09:17:49 cerbere sshd[30181]: Failed password for root from 58.218.204.213 port 52026 ssh2
May 12 09:17:50 cerbere sshd[30179]: Failed password for root from 58.218.205.68 port 40706 ssh2
May 12 09:17:51 cerbere sshd[30181]: Failed password for root from 58.218.204.213 port 52026 ssh2
May 12 09:17:55 cerbere sshd[30194]: Failed password for root from 58.218.205.68 port 47671 ssh2
May 12 09:17:56 cerbere sshd[30196]: Failed password for root from 58.218.204.213 port 44204 ssh2
May 12 09:17:57 cerbere sshd[30194]: Failed password for root from 58.218.205.68 port 47671 ssh2
May 12 09:17:58 cerbere sshd[30196]: Failed password for root from 58.218.204.213 port 44204 ssh2
May 12 09:18:00 cerbere sshd[30194]: Failed password for root from 58.218.205.68 port 47671 ssh2
May 12 09:18:01 cerbere sshd[30196]: Failed password for root from 58.218.204.213 port 44204 ssh2
May 12 09:18:05 cerbere sshd[30200]: Failed password for root from 58.218.205.68 port 54533 ssh2
May 12 09:18:06 cerbere sshd[30212]: Failed password for root from 58.218.204.213 port 39345 ssh2
May 12 09:18:06 cerbere sshd[30200]: Failed password for root from 58.218.205.68 port 54533 ssh2
May 12 09:18:08 cerbere sshd[30212]: Failed password for root from 58.218.204.213 port 39345 ssh2
May 12 09:18:08 cerbere sshd[30200]: Failed password for root from 58.218.205.68 port 54533 ssh2
May 12 09:18:11 cerbere sshd[30212]: Failed password for root from 58.218.204.213 port 39345 ssh2
May 12 09:18:14 cerbere sshd[30214]: Failed password for root from 58.218.205.68 port 60768 ssh2
May 12 09:18:16 cerbere sshd[30214]: Failed password for root from 58.218.205.68 port 60768 ssh2
[...]
le gars tourne sur plusieurs machines. J’ai déjà vu un gars passer 3 mois avec un botnet et essayer un dictionnaire de quelques milliers de login, chacun avec plusieurs mots de passe. Impressionnant mais en pure perte.
Parfois j’ai ça
Illegal users from:
41.220.26.222 (mail.firstpack.co.zw): 20 times
oracle: 4 times
123: 2 times
123456: 2 times
boot: 2 times
dff: 2 times
git: 2 times
test: 2 times
ubuntu: 2 times
zhangyan: 2 times
58.64.197.111: 9931 times
admin: 56 times
test: 42 times
toor: 34 times
tester: 32 times
student: 28 times
students: 28 times
testing: 28 times
guest: 26 times
oracle: 22 times
vic: 22 times
victor: 22 times
[...]
test1: 6 times
test123: 6 times
unreal: 6 times
var: 6 times
www: 6 times
xxx: 6 times
abe: 4 times
abel: 4 times
abigail: 4 times
abraham: 4 times
account: 4 times
ace: 4 times
ada: 4 times
adam: 4 times
adela: 4 times
adeline: 4 times
admins: 4 times
admissions: 4 times
adolf: 4 times
adolph: 4 times
adrian: 4 times
adriana: 4 times
africa: 4 times
agnes: 4 times
al: 4 times
alan: 4 times
albert: 4 times
albertha: 4 times
alec: 4 times
alex: 4 times
[...]
mais souvent c’est ça
Failed logins from:
43.255.190.89: 153 times
root/password: 153 times
43.255.190.92: 314 times
root/password: 314 times
43.255.190.115: 139 times
root/password: 139 times
43.255.190.116: 319 times
root/password: 319 times
43.255.190.117: 157 times
root/password: 157 times
43.255.190.118: 156 times
root/password: 156 times
43.255.190.119: 156 times
root/password: 156 times
43.255.190.120: 159 times
root/password: 159 times
43.255.190.122: 152 times
root/password: 152 times
43.255.190.123: 157 times
root/password: 157 times
43.255.190.124: 316 times
root/password: 316 times
43.255.190.126: 312 times
root/password: 312 times
43.255.190.130: 145 times
root/password: 145 times
43.255.190.132: 201 times
root/password: 201 times
43.255.190.133: 147 times
root/password: 147 times
43.255.190.134: 298 times
root/password: 298 times
43.255.190.135: 151 times
root/password: 151 times
43.255.190.137: 123 times
root/password: 123 times
43.255.190.139: 322 times
root/password: 322 times
43.255.190.141: 153 times
root/password: 153 times
43.255.190.144: 151 times
root/password: 151 times
43.255.190.145: 162 times
root/password: 162 times
43.255.190.146: 159 times
root/password: 159 times
43.255.190.147: 134 times
[..](plusieurs milliers de lignes (13000))[..]
sur un log de quelques semaines (le gars a fait les classiques puis de a, aa, aaa, abba… à zzelano en passant par morgengold), j’ai une collection de logins impressionnante