Aldryic messaged me early yesterday morning telling me he had been seeing an unusual amount of SSH brute forces coming in.
Sure enough, I ran a quick counter and saw a RETARDED spike in the past 2 days:
[root@nj-edge01 ~]# grep -c 2014-08-28 /var/log/blackholed.log
15
[root@nj-edge01 ~]# grep -c 2014-08-29 /var/log/blackholed.log
13
[root@nj-edge01 ~]# grep -c 2014-08-30 /var/log/blackholed.log
16
[root@nj-edge01 ~]# grep -c 2014-08-31 /var/log/blackholed.log
14
[root@nj-edge01 ~]# grep -c 2014-09-01 /var/log/blackholed.log
150
[root@nj-edge01 ~]# grep -c 2014-09-02 /var/log/blackholed.log
61
Anyone else seeing something similar?
Francisco
Sure enough, I ran a quick counter and saw a RETARDED spike in the past 2 days:
[root@nj-edge01 ~]# grep -c 2014-08-28 /var/log/blackholed.log
15
[root@nj-edge01 ~]# grep -c 2014-08-29 /var/log/blackholed.log
13
[root@nj-edge01 ~]# grep -c 2014-08-30 /var/log/blackholed.log
16
[root@nj-edge01 ~]# grep -c 2014-08-31 /var/log/blackholed.log
14
[root@nj-edge01 ~]# grep -c 2014-09-01 /var/log/blackholed.log
150
[root@nj-edge01 ~]# grep -c 2014-09-02 /var/log/blackholed.log
61
Anyone else seeing something similar?
Francisco
Last edited by a moderator: