Beginning on August 29 2008, I've noticed a new attack strategy on the SSH server on my Linux gateway box.

Until now, I've just left SSH open, but had firewall rules to automatically blacklist any host that tries to connect too often within a short interval. This seems to have been working acceptably until now.

But a week ago, a botnet began attacking.. slowly.. a new connection attempt every few seconds, but from a different IP address each time. Up to a limit, after which the IP addresses roll around again, outside of the blacklist rules that I had set.


Anyway, the firewall has now been adjusted to deny drop SSH by default, and I'm moving to a different strategy for remote access there. Long overdue, I suppose.
