Lesson 1 of 3 in The Ones Who Come Back · 4 min left in this chapter
Watch Them Try
Before you stop the brute force, look at it. The auth log of any box on the internet is a wall of failed logins from addresses all over the world — and buried in it is the difference between background noise and a determined attacker, which is exactly what the next tool needs to read.
2 min read
Not yet reviewed
You closed the door with keys. The knocking did not stop — it never does. Let us actually read it, because the log is where every defence from here starts.
I have never opened an auth log. What is even in it?
The wall of attempts
Every failed SSH login writes a line to /var/log/auth.log. On a box that has been online for an hour, there are hundreds of them: Failed password from addresses you have never heard of, for usernames you never created — admin, oracle, postgres, git. This is not someone after *you*. It is the whole internet, tried automatically, all the time.
In this terminal is a real auth log. Do not scroll it — that is the lesson from Linux, and it matters more here. Ask it questions. grep "Failed password" shows the attempts; pipe it to wc -l to count them; and one line in it is not a failure at all.
This auth log is four hundred lines of login attempts. Exactly one login succeeded. Find it — print the line that says a password was *Accepted*.
There are hundreds of Failed password lines. Is that an emergency you need to act on right now?
Accepted line you did not expect. The skill is not reacting to every attempt; it is reading the log well enough to tell the weather from the storm.