As I'm working to set up my new VPS, I've made a rather disturbing discovery. There are literally THOUSANDS of failed SSH login attempts, daily!
When I logged in earlier today, SSH said:
Last failed login: Fri Dec 4 17:19:03 EST 2020 from 123.45.67.89 on ssh:notty
There were 10514 failed login attempts since the last successful login.
Last login: Fri Dec 4 01:59:54 2020 from 172.106.10.130
That's 10,000 login attempts in about 15 hours :-O I'm only guessing that the previous owner had 0 security or something.
The VPS is using CentOS 7.9. I've installed ConfigServer Firewall, and used CC_ALLOW_FILTER to limit all connections to country codes US,MP,PR. And I'm about to change the SSH port.
Any other suggestions on what I might do to stop those login attempts? My old VPS rarely had any attacks like this, so 10,000 in 15 hours is... scary.