SSH and FTP brute-force protection for Linux

Stop password-guessing attacks on your Linux servers

SSH Protector is a small Linux agent paired with a cloud panel. The agent watches failed SSH and FTP logons, blocks the attacking network with a single firewall rule and keeps working even without an internet connection. Setup takes a couple of minutes and needs no configuration.

The free version includes full protection for one server.

One agent for every Linux distribution

Debian · Ubuntu · FedoraRHEL · Alma · Rocky · Alpinex64 · x86 · ARM64near-zero CPU usage
00

Install the agent

One binary for everyone, no account needed to download it. Install now and connect the server whenever you like — the agent asks for an enrollment token from your panel, and protects nothing until you paste one.

Download install script

Any modern systemd-based Linux — Debian, Ubuntu, RHEL/CentOS/Alma/Rocky, Fedora — on x86-64 or ARM64. The script installs the same service and is the practical choice for a fleet.

01Why

An open SSH port is attacked around the clock

Bots scan the entire internet address space and try passwords on every reachable server. It does not matter whether it is a corporate machine or a single VPS.

Thousands of login attempts per day
Within hours of going online a server starts receiving login attempts from all over the world. A typical machine with an exposed SSH port logs thousands of failed logons every day.
Server resources burned for nothing
Every attempt costs CPU time, memory, an event-log write and network traffic. A constant stream of brute-force requests creates permanent background load, slows the server down and bloats the logs.
One guessed password from a breach
A single successful guess gives full access to the machine: ransomware, data theft, spam sent from your address. Weak and reused passwords fall to dictionaries within days.
Attackers can lock out your admin account
Linux (via PAM faillock) locks an account after too many failed logons. By guessing a valid username an attacker trips that limit and locks out the real administrator — a denial of service, even without ever guessing the password.

SSH Protector cuts attacks off at the firewall

The agent notices a series of failed logons and blocks the attacker's whole subnet with one nftables rule. Blocked packets are dropped before the system spends anything on them — CPU load and log noise go down, the server runs faster, and bots never get enough tries to guess a password.

02How it works

From download to a protected server in minutes

No config files and no command line: download the installer, run it, confirm the sudo prompt.

  1. Create an account

    Sign up with email or through Google/GitHub. No credit card needed.

  2. Download the installer

    You get a personal signed installer with your access token already embedded.

  3. Run it on the server

    The agent detects the SSH port on its own and adds your current IP to the whitelist so you cannot lock yourself out.

  4. Done

    The server shows up online in the panel within seconds and starts blocking attackers with sensible default settings.

03Features

Everything you need to protect and manage your servers

Brute-force protection at the core, extended with shared attacker intelligence, geo rules, temporary access and central management.

SSH and FTP brute-force protection01

The agent reads failed logons from the systemd journal (journald) and the FTP server logs and blocks the attacker locally — instantly, even with no cloud connection.

Bans whole subnets, not single addresses02

Attackers rotate addresses within their network. SSH Protector bans the whole subnet, using ASN data, with one consolidated firewall rule.

Shared attacker database03

An attack on one customer protects everyone: subnet reputation is aggregated across the platform and the worst networks are blocked before they reach you.

Geo rules04

Allow SSH only from the countries you actually work from. Everything is evaluated locally on the agent, so it stays fast and works offline.

Temporary access05

Keep the port closed by default and open it for a specific address after an MFA-confirmed request, with a timer and automatic close.

Whitelist and strict mode06

Trusted addresses and dynamic DNS names are never blocked. In strict mode only whitelisted sources may reach the port at all.

Notifications and audit07

Ban spikes, a server going offline, configuration drift — delivered by email, Telegram, Slack or webhook. Every action is recorded in an audit log.

One lightweight agent08

A single small executable running as a service. A few megabytes of memory, near-zero CPU, every major Linux distribution and architecture.

Central management09

Server list, policies, version rollback, groups and bulk actions — all from the panel, with no inbound ports opened on your servers.

Always-On lockout protection10

Guarantees your account is never locked out under brute force: the agent bans attackers before the PAM faillock threshold and auto-unlocks protected accounts (admins + your list). On by default, on every plan.

04Pricing

Flat plans, no per-server surprises

Free stays free forever, no card required. Paid plans have a fixed price with a set number of servers included.

Free

1 server
$0/mo

Basic SSH protection for a single server.

  • SSH brute-force protection
  • Soft whitelist
  • Minimal statistics

Solo

1 server
$9/mo

Full protection for one production server.

  • Everything in Free
  • FTP brute-force protection
  • Full statistics
  • Email notifications
  • Basic audit log

Pro

PopularUp to 5 servers
$15/mo

For teams and small server fleets.

  • Everything in Solo
  • Strict whitelist and groups
  • Full audit with export
  • Extended statistics
  • Shared behavioral blocklist

Enterprise

Up to 50 servers
$99/mo

For companies with a large server fleet.

  • Everything in Pro
  • Admin and moderator roles
  • Priority support
  • Shared behavioral blocklist

Need one more server than your plan includes? Add servers individually for $3 per server per month instead of jumping a tier.

14 days of Pro, free — no card

Sign up and try subnet bans, Telegram alerts, GeoIP and the shared threat database on your own server. When the trial ends your account returns to Free on its own and protection keeps running. Nothing is charged, and there is nothing to cancel.

Start the free trial
05FAQ

Frequently asked questions

Is it safe to install on a production server?

Yes. The agent only reads the auth log of its own operating system and blocks inbound connections to the protected ports on that same machine. It makes outbound HTTPS requests only and opens no inbound ports.

Does protection work without an internet connection?

Yes. The decision to block an attacker is made locally on the agent, so protection keeps working with the last applied policy even when the cloud is unreachable.

What if I changed the SSH port?

The agent detects the actual SSH port automatically from sshd_config and listening sockets, and rebuilds its rules when the port changes. The FTP port is detected the same way.

Can I lock myself out?

No. During installation your current IP address is added to the whitelist, and whitelisted sources always take priority over any block.

Which Linux distributions are supported?

Any modern systemd-based distribution — Debian, Ubuntu, RHEL/CentOS/Alma/Rocky, Fedora — on x86-64 and ARM64. One static binary with no additional runtimes to install.

How does payment work?

International payments go through PayPro Global, payments in Russia through YooKassa, with cryptocurrency available as a fallback. The Free plan is permanent and requires no card.

Protect your first server today

The Free plan stays free forever. Upgrade in one click whenever you need more.

Recovery Toolbox / File Master LLC

Contact Recovery Toolbox

Contact details for Recovery Toolbox and File Master LLC, plus the profile of Victor G. Bobrov, the company's leading software development specialist and file recovery expert.

Company office

File Master LLC is the legal entity behind the Recovery Toolbox online services and software products.

File Master LLC
Serena app., office C13
Golden Sands, Varna, 9007
Bulgaria, European Union
Bulstat/VAT
180842207

About Recovery Toolbox

File Master LLC develops and supports Recovery Toolbox online services and software products for repairing damaged files, databases and mail storage formats. The company focuses on practical recovery tools for users, IT specialists and businesses that need to restore access to corrupted data.

Comments and suggestions are welcome. Please send website feedback by email: webmaster@recoverytoolbox.com

Victor G. Bobrov
Company specialist

Victor G. Bobrov

Leading Software Development Specialist and File Recovery Expert

Victor G. Bobrov works with Recovery Toolbox / File Master LLC on file structure analysis, damaged file recovery, database recovery and online repair services.

  • File recovery
  • Data recovery
  • Online repair services
  • MCSD
  • MCDBA
About the author →

Microsoft certifications

Microsoft Certified Solutions Developer — MCSD. Microsoft Certified Database Administrator — MCDBA.

MCSD MCDBA