When SSH logging is enabled in the wizard, automatically: - Set dropbear.@dropbear[0].verbose=1 to log auth failures - Restart dropbear to apply changes This ensures CrowdSec can detect SSH brute force attempts. Without verbose mode, Dropbear doesn't log failed auth to syslog. Also enable uhttpd syslog when HTTP logging is enabled. Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| secubox | ||