Apparently my VPS is being targeted by a slow grinding botnet, since the login attempts are coming from IP addresses "around the world".
Lucky me. :P
Is it just . . my turn? Does every VPS get its day/turn?
What makes a server "a more likely target" for a root attack? Are there "signals of weakness"?
Is there a way to disable "root" as the login for root and, at the same time, give the "root account" a new, less obvious, name?
The attempts continue as I type. I've alread notified my hosting company's NOC. I assumed that they would/should have systems in place that would alert them to such behavior but I'm not prepared to rest on that assumption. :-/