Hacker News new | ask | show | jobs
by mqzaidi 4391 days ago
You should also run logwatch - it will show you all the attempts that keep happening on any public servers running ssh. I once had to look at a box compromised, which was then used to brute force other servers, and it contained a file with 100-200 passwords for other hosts it brute-forced.