Le fail2ban ne sert pas à grand chose mis à part à limiter tes logs. J’ai mis une limite chez moi à 5 minutes et voilà ce que j’obtiens en ce moment
[...]
May 12 09:17:48 cerbere sshd[30179]: Failed password for root from 58.218.205.68 port 40706 ssh2
May 12 09:17:49 cerbere sshd[30181]: Failed password for root from 58.218.204.213 port 52026 ssh2
May 12 09:17:50 cerbere sshd[30179]: Failed password for root from 58.218.205.68 port 40706 ssh2
May 12 09:17:51 cerbere sshd[30181]: Failed password for root from 58.218.204.213 port 52026 ssh2
May 12 09:17:55 cerbere sshd[30194]: Failed password for root from 58.218.205.68 port 47671 ssh2
May 12 09:17:56 cerbere sshd[30196]: Failed password for root from 58.218.204.213 port 44204 ssh2
May 12 09:17:57 cerbere sshd[30194]: Failed password for root from 58.218.205.68 port 47671 ssh2
May 12 09:17:58 cerbere sshd[30196]: Failed password for root from 58.218.204.213 port 44204 ssh2
May 12 09:18:00 cerbere sshd[30194]: Failed password for root from 58.218.205.68 port 47671 ssh2
May 12 09:18:01 cerbere sshd[30196]: Failed password for root from 58.218.204.213 port 44204 ssh2
May 12 09:18:05 cerbere sshd[30200]: Failed password for root from 58.218.205.68 port 54533 ssh2
May 12 09:18:06 cerbere sshd[30212]: Failed password for root from 58.218.204.213 port 39345 ssh2
May 12 09:18:06 cerbere sshd[30200]: Failed password for root from 58.218.205.68 port 54533 ssh2
May 12 09:18:08 cerbere sshd[30212]: Failed password for root from 58.218.204.213 port 39345 ssh2
May 12 09:18:08 cerbere sshd[30200]: Failed password for root from 58.218.205.68 port 54533 ssh2
May 12 09:18:11 cerbere sshd[30212]: Failed password for root from 58.218.204.213 port 39345 ssh2
May 12 09:18:14 cerbere sshd[30214]: Failed password for root from 58.218.205.68 port 60768 ssh2
May 12 09:18:16 cerbere sshd[30214]: Failed password for root from 58.218.205.68 port 60768 ssh2
[...]
le gars tourne sur plusieurs machines. J’ai déjà vu un gars passer 3 mois avec un botnet et essayer un dictionnaire de quelques milliers de login, chacun avec plusieurs mots de passe. Impressionnant mais en pure perte.
Parfois j’ai ça
 Illegal users from:
    41.220.26.222 (mail.firstpack.co.zw): 20 times
       oracle: 4 times
       123: 2 times
       123456: 2 times
       boot: 2 times
       dff: 2 times
       git: 2 times
       test: 2 times
       ubuntu: 2 times
       zhangyan: 2 times
    58.64.197.111: 9931 times
       admin: 56 times
       test: 42 times
       toor: 34 times
       tester: 32 times
       student: 28 times
       students: 28 times
       testing: 28 times
       guest: 26 times
       oracle: 22 times
       vic: 22 times
       victor: 22 times
[...]
       test1: 6 times
       test123: 6 times
       unreal: 6 times
       var: 6 times
       www: 6 times
       xxx: 6 times
       abe: 4 times
       abel: 4 times
       abigail: 4 times
       abraham: 4 times
       account: 4 times
       ace: 4 times
       ada: 4 times
       adam: 4 times
       adela: 4 times
       adeline: 4 times
       admins: 4 times
       admissions: 4 times
       adolf: 4 times
       adolph: 4 times
       adrian: 4 times
       adriana: 4 times
       africa: 4 times
       agnes: 4 times
       al: 4 times
       alan: 4 times
       albert: 4 times
       albertha: 4 times
       alec: 4 times
       alex: 4 times
[...]
mais souvent c’est ça
Failed logins from:
    43.255.190.89: 153 times
       root/password: 153 times
    43.255.190.92: 314 times
       root/password: 314 times
    43.255.190.115: 139 times
       root/password: 139 times
    43.255.190.116: 319 times
       root/password: 319 times
    43.255.190.117: 157 times
       root/password: 157 times
    43.255.190.118: 156 times
       root/password: 156 times
    43.255.190.119: 156 times
       root/password: 156 times
    43.255.190.120: 159 times
       root/password: 159 times
    43.255.190.122: 152 times
       root/password: 152 times
    43.255.190.123: 157 times
       root/password: 157 times
    43.255.190.124: 316 times
       root/password: 316 times
    43.255.190.126: 312 times
       root/password: 312 times
    43.255.190.130: 145 times
       root/password: 145 times
    43.255.190.132: 201 times
       root/password: 201 times
    43.255.190.133: 147 times
       root/password: 147 times
    43.255.190.134: 298 times
       root/password: 298 times
    43.255.190.135: 151 times
       root/password: 151 times
    43.255.190.137: 123 times
       root/password: 123 times
    43.255.190.139: 322 times
       root/password: 322 times
    43.255.190.141: 153 times
       root/password: 153 times
    43.255.190.144: 151 times
       root/password: 151 times
    43.255.190.145: 162 times
       root/password: 162 times
    43.255.190.146: 159 times
       root/password: 159 times
    43.255.190.147: 134 times
[..](plusieurs milliers de lignes (13000))[..]
sur un log de quelques semaines (le gars a fait les classiques puis de a, aa, aaa, abba… à zzelano en passant par morgengold), j’ai une collection de logins impressionnante
 
      
     , mais bon, ça, ce n’est que mon interprétation toute personnelle avec ma très petite expérience en réseau et petite compétence.
, mais bon, ça, ce n’est que mon interprétation toute personnelle avec ma très petite expérience en réseau et petite compétence.