So first I would SSH into my box and grep through the logs for failed login attempts.
grep -i failed /var/log/auth.log | less
data:image/s3,"s3://crabby-images/78696/78696d3ba05f0ec1422189efe5384fed8141b282" alt=""
First I took just one IP from my logs, and Nmap'd it (well they started it!). I found a single SSH port open running a vulnerable version of OpenSSH.
nmap -F 199.33.132.127 -PN
data:image/s3,"s3://crabby-images/d8f87/d8f87b277384c77c4932c49116b910838bfad16f" alt=""
Okay, so using nmap fast scan (looking for the most common ports) I see that port 22 is open.
Now I used a really great website called clez.net to look at the port in more detail.
data:image/s3,"s3://crabby-images/ace4e/ace4e05998348b3b4aaf2563b154de2b0650da6a" alt=""
This site gives me the SSH version and plenty of other intresting info.
So now if I google the SSH version I quickly find that it's an old vulnerable version (OpenSSH 3.9p1).
data:image/s3,"s3://crabby-images/cf47d/cf47d3fd63135ea50936940465e8edd5cea559ea" alt=""
So it would seem that some poor sucker has got his box owned and now he is scanning my box.
So that's it really. I just wanted to demonstrate to anyone who might read this why it is important to patch.