So we are constantly being hit by logon attempts from all over the world (mostly China). I was blocking any newly discovered IP address. But I am not sure if I see any reduction in those attempts, well, maybe just a little. Is this being done by one person (or a few) who is spoofing the IP addresses and me blocking all those IP addresses won't achieve anything or is our server IP listed on some hackers forums and so many people are trying to access it? I see some patterns and they are targeting a very similar-looking list of user names.
Thanks