2026-07-19 · 7 min
1234 login attempts in 41 hours: who really knocks on an exposed SSH port
A quiet test box, no DNS, nothing published. We counted the knocks: 93 IPs,
132 usernames from postgres to AdminGPON to pi, activity around the clock, and the one
zero that kept the door shut.
2026-07-19 · 7 min
1234 tentatives de connexion en 41 heures : qui cogne vraiment sur un port SSH exposé
Une box tranquille, pas de DNS, rien de publié. On a compté les coups : 93 IP,
132 noms de comptes de postgres à AdminGPON à pi, de l'activité 24 heures sur 24, et le
zéro qui a gardé la porte fermée.
2026-07-19 · 7 min
Raising your Lynis hardening index: what actually moves the score
Measured fix by fix: the 25-point penalty apt upgrade leaves behind, why
installing security tools earns nothing, the SSH block that scores all or nothing, and four
rules for an honest climb.
2026-07-19 · 7 min
Faire monter son score Lynis : ce qui rapporte vraiment
Mesuré fixe par fixe : la pénalité de 25 points qu'apt upgrade laisse traîner,
pourquoi installer des outils de sécurité ne rapporte rien, le bloc SSH qui score tout ou
rien, et quatre règles pour un climb honnête.
2026-07-19 · 6 min
Locked out of your own server: the five classic SSH lock-outs
Password login off without a tested key, the firewall before the allow rule,
fail2ban banning you, the port change systemd ignores, and the typo that explodes weeks
later. Each one has a habit that makes it survivable.
2026-07-19 · 6 min
Barré dehors de ton propre serveur : les cinq lock-outs SSH classiques
Mot de passe désactivé sans clé testée, le pare-feu avant la règle allow,
fail2ban qui te bannit toi, le changement de port que systemd ignore, et la typo qui explose
des semaines plus tard. Chacun a l'habitude qui le rend survivable.