Monsantosucks
Verified User
- Joined
- Nov 10, 2014
- Messages
- 12
Hello I've been checking my logs for some time because I have thousands of Brute force attacks on the SSH. I changed my port from 22 to something else but I still get lots of messages, so here's one line:
14156301785993 122.225.109.198 root 1 sshd5 Nov 10 12:00:14 vps2563 sshd[11298]: Failed password for root from 122.225.109.198 port 43064 ssh2
Why does this count as a login attempt? This ipaddress uses a port (43064) which doesn't listen to anything. I thought it would only be logged if one would actually try on the port SSH is listening on.
When I use putty.exe to connect to my server and I put in a random port number it will just do nothing, is this different?
14156301785993 122.225.109.198 root 1 sshd5 Nov 10 12:00:14 vps2563 sshd[11298]: Failed password for root from 122.225.109.198 port 43064 ssh2
Why does this count as a login attempt? This ipaddress uses a port (43064) which doesn't listen to anything. I thought it would only be logged if one would actually try on the port SSH is listening on.
When I use putty.exe to connect to my server and I put in a random port number it will just do nothing, is this different?