Forum archive
Rogue root login attempts
Help!
A couple of days ago I setup a new debian lamp stack with turnkey on an EC2 instance using the default turnkey security group that only allows a few ports. I was examining the logs just now and noticed multiple SSH root login attempts on what looks like random ports.
3 questions:
1. What the hell is this from?
2. Should I be concerned?
3. What can I do to stop it?
I've attached a small section of the log file.
Thanks in advance,
Robert
For what it's worth this is happening to everyone. The attacks are automated and carried out on an Internet scale by millions of compromised computers on botnets. The correct question to ask isn't who is behind this, but who isn't behind this. Even your favorite western governments are in on the fun:
NSA/GCHQ/CSEC Infecting Innocent Computers Worldwide