Wait, who is logging SSH passwords? Is this an intentional attack on OpenSSH Portable or is it a honeypot?
The "POSSIBLE BREAK-IN ATTEMPT!" message worried me for a bit but a little googling and the fact I've disabled password login calmed me down.
Presumably, changing my sshd port will drastically reduce these attempts right? Or do attackers routinely port scan servers?
Only nuisance is that the higher ports may be blocked, for example my uni blocks my new ssh port so I can't connect to the vps when I'm on campus.
Mind you it isn't that this is a defense, but it gets the drive-by scanning stuff out of the log.
By all means disable password login, and all direct root login.