Automated password guessing against every exposed service.
WHAT IS TARGETED
SSH, control panel logins, FTP, mail, database ports, and application login pages.
THE PRIMARY DEFENCE
Remove passwords where you can. SSH key authentication cannot be brute-forced.
For services where passwords are unavoidable, use long unique ones.
AUTOMATED BLOCKING
fail2ban monitors logs and blocks addresses after repeated failures. CSF provides similar functionality alongside its firewall.
Configure it for SSH at minimum, and for your control panel, mail and application logins if supported.
Set thresholds that block attackers without locking out legitimate users who mistype twice.
RESTRICTING BY SOURCE
If you administer from a fixed address, restrict SSH and control panel access to it in the firewall. This is the strongest control available and costs nothing.
WHAT ELSE HELPS
Changing default ports, which removes most automated noise Two-factor authentication on control panel access Disabling services you do not use
MONITORING
Check how many attempts you are seeing. A sudden increase can precede a more targeted attempt.