While inspecting the logs on a client machine yesterday I stumbled on a rather crude manual attack actually in progress. The slow repeat rate made it clear that this was a manual attempt to gain entry - the villain was trying to gain access via SSH which I have opened up through the router to allow me to rsync this server and the server in the same client's other building. The attck failed, and because the attack was manual, it was pretty clear that the source address was the attackers home PC so I forwarded the attack log lines to the Italian ISP involved - hopefully that will get some action.
What is obvious, however, is that a good password blitz and a few lucky guesses at usernames might have got the person into the system.
My question is - can I limit the allowed incoming IP addresses, and how do I go about it?
Ed Form