Domain-name based ssh login attempts
Wednesday, April 23rd, 2008The last few weeks I have noticed some illicit ssh login attempts that uses parts of the reverse DNS domain name as user name when it tries to login. The last attempt looked like this in my LogWatch summary: Illegal users from these: 195.38.107.55 (aquila.euroexpert.tvnet.hu): 9 times root/password: 4 times ...