That SSH bot rotating IPs in your logs? Ban the whole subnet, then let the ban expire
It started with a Wazuh alert I've seen a thousand times: sshd: Attempt to login using a non-existent user (rule 5710) Invalid user taow from 203.0.113.239 port 50612 Then again. And again. Rule 5710 had fired 91 times on one VM, from a different IP almost every time, but always inside the same /24. Was it dangerous? No.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in