Skip to main content
Duy2003
Explorer
October 21, 2024
Question

Brute force attacker username admin

  • October 21, 2024
  • 2 replies
  • 2700 views

Hi team,
I have configured to disable access http and https on the interfaces, configured trust host on the admin account but still reported brute force log

 

 

 

 

 

2 replies

funkylicious
SuperUser
SuperUser
October 21, 2024

Hi,

Are you seeing them in logs for VPN or System Events ?

"jack of all trades, master of none"
Duy2003
Duy2003Author
Explorer
October 21, 2024

Hi @funkylicious ,
I am seeing them in logs for System Events

 

funkylicious
SuperUser
SuperUser
October 21, 2024

Well, if you disabled http/https for the wan interfaces, maybe they are ssh attempts?

I would advise you to use trusted hosts for all your administrators.

If one user/admin doesn't have trusted hosts enabled/configured , the mgmt ( ssh/http/https ) will still be opened from everywhere and attempts/brute force can be made ( the good part is that even they know the pass for the user that has it configured but the src ip isnt the one in the trustedhosts it cannot be accessed/permitted ), but if for all are configured nothing ( no prompt to enter credentials ) will be made available for them.

Another option would be to use local-in policies, cli configurable only.

"jack of all trades, master of none"
mpandya
Staff
Staff
October 21, 2024