[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Connection closed by [IP] port [port] [preauth]



On 2/24/2020 9:38 PM, steve wrote:
> Hi there,
>
> Since February 11th at 00:25:09, I am getting the following every 12
> secondes:
>
> Feb 11 00:25:09 box sshd[17733]: Connection closed by 118.126.105.120
> port 54422 [preauth]
>
> And when I say every 12 seconds, it is really every 12 seconds, and this
> is now going on for more than 13 days, without any interruption. At the
> beginning, I thought that this was just standards nmap scans or
> something similar and so didn't bother taking any action. But now I'm
> asking myself who (in China) would be so stupid to continue this
> scanning.
>
> What should I do? Send an email to the abuse contact? Ignore it and wait
> that it's over? It doesn't seem naughty but it's getting irritating.
>

Find a way to block/ban this address, fail2ban, firewall and to some
extend sshd_config.

--
John Doe


Reply to: