Apr 17 00:24:48 debian sshd[18665]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=61.174.51.207 user=root
Apr 17 00:24:49 debian sshd[18662]: Failed password for root from 61.174.51.207 port 2826 ssh2
Apr 17 00:24:50 debian sshd[18665]: Failed password for root from 61.174.51.207 port 4528 ssh2
Apr 17 00:24:51 debian sshd[18662]: Failed password for root from 61.174.51.207 port 2826 ssh2
Apr 17 00:24:52 debian sshd[18665]: Failed password for root from 61.174.51.207 port 4528 ssh2
Apr 17 00:24:55 debian sshd[18662]: Failed password for root from 61.174.51.207 port 2826 ssh2
Apr 17 00:24:56 debian sshd[18665]: Failed password for root from 61.174.51.207 port 4528 ssh2
Apr 17 00:24:59 debian sshd[18665]: Failed password for root from 61.174.51.207 port 4528 ssh2
Apr 17 00:24:59 debian sshd[18662]: Failed password for root from 61.174.51.207 port 2826 ssh2
Apr 17 00:25:00 debian sshd[18665]: Failed password for root from 61.174.51.207 port 4528 ssh2
Apr 17 00:25:01 debian sshd[18662]: Failed password for root from 61.174.51.207 port 2826 ssh2
Apr 17 00:25:01 debian sshd[18662]: Disconnecting: Too many authentication failures for root [preauth]
Apr 17 00:25:01 debian sshd[18662]: PAM 5 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=61.174.51.207 user=root
Apr 17 00:25:01 debian sshd[18662]: PAM service(sshd) ignoring max retries; 6 > 3
Apr 17 00:25:03 debian sshd[18665]: Failed password for root from 61.174.51.207 port 4528 ssh2
Apr 17 00:25:03 debian sshd[18665]: Disconnecting: Too many authentication failures for root [preauth]
Apr 17 00:25:03 debian sshd[18665]: PAM 5 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=61.174.51.207 user=root
Apr 17 00:25:03 debian sshd[18665]: PAM service(sshd) ignoring max retries; 6 > 3
Apr 17 00:25:03 debian sshd[18667]: reverse mapping checking getaddrinfo for 207.51.174.61.dial.wz.zj.dynamic.163data.com.cn [61.174.51.207] failed - POSSIBLE BREAK-IN ATTEMPT!
здесь есть report abuse на этот ip: http://www.abuseipdb.com/report-history/61.174.51.207
лог прочитал в /var/log/auth.log что это было ? там еще кучка айпишников + что-то не то с кроном . надо будет ковырнуть . пока что разрешен только исходящий трафик (перекрыл входящий в связи с последними событиями) . у кого еще завелась такая вот «паранойа» или зараза ? что нужно делать , чтобы избежать этого ?