Saturday, August 12, 2017

Attacks on my home server

This is what my home server experienced in two days ... strangely I did not announce the my IP in anyway. The following are only attacks on SSH as that is the only port I forwarded. Have not checked the router log yet. It is a jar of worms I don't want to touch.

From: Aug 7 03:38:02
To: Aug 9 14:03:27
Total attacks: 185674
Unique IPs: 112
Top 10 IPs: (by number of login attempts)
85368 61.177.172.--
46557 116.31.116.--
16630 116.31.116.--
16098 58.242.83.--
10224 59.63.166.--
4587 61.177.172.--
1866 218.87.109.--
758 103.58.116.--
634 162.243.39.--
498 60.165.208.--
Total countries: 31
Top 10 countries: (by number of unique IPs)
35 CN
12 AR
7 US
7 KR
5 BR
4 RU
4 DE
3 SE
3 FR
3 EC
IPs tried valid user names: 86
Total valid user names: 10
Top 10 valid user names:
183372 root
13 nobody
13 bin
10 ftp
9 adm
7 operator
5 sshd
5 daemon
4 transmission
2 rpc
IPs tried invalid user names: 92
Total invalid user names: 317
Top 10 invalid user names:
646 admin
170 postgres
89 odoo
62 backup
55 pi
50 support
47 usuario
40 ubnt
33 service
33 oracle
Top 10 info:
"61.177.172.--", "Nanjing", "Jiangsu", "CN",
"116.31.116.--", "Shenzhen", "Guangdong", "CN",
"116.31.116.--", "Shenzhen", "Guangdong", "CN",
"58.242.83.--", "Hefei", "Anhui", "CN",
"59.63.166.--", "Nanchang", "Jiangxi", "CN",
"61.177.172.--", "Nanjing", "Jiangsu", "CN",
"218.87.109.--", "Nanchang", "Jiangxi", "CN",
"103.58.116.--", "Namakkal", "Tamil Nadu", "IN",
"162.243.39.--", "New York", "New York", "US",
"60.165.208.--", "Lanzhou", "Gansu", "CN",

No comments: