You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu服务器遭未知用户SSH登录尝试,请求技术支援

Fixing SSH Brute-Force Attacks & Mitigating DDoS Risks for New Server Admins

Hey there, let’s walk through how to tackle this—this kind of attack is super common for exposed servers, so you’re not alone! Let’s break down what’s going on and fix it step by step.

What’s Actually Happening?

From your log snippet and description:

Apr 6 20:39:20 Hl-Server sshd[5107]: pam_unix(sshd:auth): authentication failure; logname= uid=0...

  • Those bot/bot2 login attempts are automated SSH brute-force attacks—attackers use scripts to spam common usernames/passwords hoping to break in.
  • The flooded UFW logs mean this is a sustained attack, and it’s likely the culprit behind your unexpected shutdown (either from CPU/bandwidth being maxed out, or the server panicking under load). Good thing UFW was already blocking those IPs, but we need to harden things further.

Immediate Fixes to Stop the Attack

1. Ditch the Default SSH Port (22)

90% of automated attacks target port 22—switching to an unconventional port filters out most of this noise instantly:
Edit your SSH config file:

sudo nano /etc/ssh/sshd_config

Find the line Port 22 and replace it with something like Port 2222 (pick any unused port between 1024-65535). Save the file, then restart SSH:

sudo systemctl restart sshd

Update your UFW rules to allow the new port and drop the old one:

sudo ufw allow 2222/tcp
sudo ufw delete allow 22/tcp
sudo ufw reload

2. Disable Password Login Entirely (Use SSH Keys)

This is the single most effective way to stop brute-force attacks—no password means nothing to guess:

  • First, make sure you’ve uploaded your local SSH public key to your server’s ~/.ssh/authorized_keys file (test that you can log in with the key before moving on!).
  • Edit the SSH config again:
sudo nano /etc/ssh/sshd_config

Update these lines:

PasswordAuthentication no
ChallengeResponseAuthentication no
UsePAM no

Restart SSH to apply changes:

sudo systemctl restart sshd

⚠️ Critical note: Don’t do this unless you’re 100% sure your SSH key works—you’ll lock yourself out otherwise!

3. Limit SSH to Only Trusted Users

Block all users except your legitimate admin account to cut down on useless login attempts:
Add this line to your SSH config (replace your-actual-username with your server account):

AllowUsers your-actual-username

Restart SSH once more.

4. Clear UFW Logs to Free Up Space

If those logs are eating up disk space, empty them quickly:

sudo truncate -s 0 /var/log/ufw.log

You can also set up log rotation later to prevent this from happening again.

Long-Term Protection

1. Install Fail2ban

This tool automatically detects repeated failed login attempts and blocks the offending IPs via UFW—think of it as a bouncer for your server:
Install it with:

sudo apt update && sudo apt install fail2ban

Enable it to start on boot:

sudo systemctl enable --now fail2ban

The default config already protects SSH, but you can tweak rules in /etc/fail2ban/jail.local (like shortening detection windows or extending ban times) if needed.

2. Monitor Resources & Logs

  • Use htop to keep an eye on CPU, memory, and bandwidth usage—spikes here can signal ongoing attacks.
  • Quickly scan for suspicious activity in logs with grep:
    # Check SSH auth failures
    grep "authentication failure" /var/log/auth.log | head -20
    # Check UFW blocked IPs
    grep "BLOCK" /var/log/ufw.log | head -20
    

3. Hide Your Server’s Real IP (If Possible)

If your server hosts public services, use a CDN (like Cloudflare) as a reverse proxy. This hides your server’s actual IP, so attacks hit the CDN first instead of your machine—great for mitigating DDoS risks.

Checking the Unexpected Shutdown

To confirm if the attack caused the shutdown, check system logs for resource overload or errors:

# Check system shutdown logs
grep "shutdown" /var/log/syslog
# Look for CPU/memory spikes before shutdown
grep "out of memory" /var/log/syslog

内容的提问来源于stack exchange,提问作者Peter Hogya

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:35:17