That's terrible!
AFAIK, AWS defaults to ssh-key logins with password logins disabled. Can someone comment about Rackspace/DO?
That's terrible!
AFAIK, AWS defaults to ssh-key logins with password logins disabled. Can someone comment about Rackspace/DO?
$ uptime
22:09:07 up 30 days, 12:19, 2 users, load average: 0,17, 0,09, 0,07
$ sudo fail2ban-client status ssh-iptablesPassword:
Status for the jail: ssh-iptables
|- filter
| |- File list: /var/log/messages
| |- Currently failed: 1
| `- Total failed: 1757
`- action
|- Currently banned: 0
| `- IP list:
`- Total banned: 242
1757 attempts from 242 IP address in the past 30 days... up 298 days, 20:42, 1 user, load average: 0.00, 0.01, 0.05
"zgrep ssh auth.log* | grep -i failed" has no traces of any intrusion attempts whatsoever, just me not being able to type.The distinction is, though, that the SSHd on that box is running on a non-standard port (220)... so that certainly makes a difference.
1) Password authentication 2) Root authentication 3) Changed root password to "password"
All the providers offer fairly safe defaults, either using very random passwords or just enabling SSH keys.
It is good to know that all providers have safe defaults, I only have experience with AWS in that regard.
As far as I know, you can still create/publish AMIs where password auth is enabled, but all of Amazon's stock images only allow ssh-key auth.