Yesterday I checked my server's stats for the first time in a while, because I've been busy, and noticed that there was some strange traffic, so I looked a little more closely and found that there were ~65 SYN_RECV TCP connections active on the ssh port:
My first thought was that someone was trying to gain access to my server, but that would raise even more questions, since I have my firewall set up in such a way that after 3 failed attepts trying to enter a password it won't accept a new connection from your ip for an hour, and while there are dips in the number of connections, those might also be a result of the the storms in my area, since I get internet from a wireless provider.
Also, this seems to have started right around a week ago so it's been going on for 7 days and in that time I've seen an increase over the normal daily average bandwidth and it's been ramping up slowly, from ~80MB the first 3 days to now seeing over ~220MB of traffic more than usual, though it might not be entirely from these ssh connections.
All of these connections come from a few IPs, I've looked them up and they're all from different datacenters around the world:
185.50.70.28 Osbil Technology Ltd., Turkey
34.246.4.96Amazon Data Services Ireland Limited, Ireland
8.212.183.33 Alibaba.com Singapore E-Commerce Private Limited, Philippines
42.236.136.163 China Unicom Henan Province Network, China
20.239.65.52 Microsoft Corporation, Hong Kong
43.142.110.118 Tencent Cloud Computing (Beijing) Co. Ltd, China
51.79.146.79 OVH Singapore Pte. Ltd, Singapore
This is even stranger to me because I would've thought that if it were some sort of attack, whoever's behind it would have used compromised home machines or something like that and certainly not cloud computing services from 7 different companies in 7 different locations around the world, right?
So, is it really an attack, and if not, what is going on?
For now, just for precaution, I've decided to remove port forwarding for the ssh port from my router.
[link] [comments]