LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Desktop
User Name
Password
Linux - Desktop This forum is for the discussion of all Linux Software used in a desktop context.

Notices


Reply
  Search this Thread
Old 05-29-2007, 07:42 AM   #1
robbbert
Member
 
Registered: Oct 2005
Location: Hannover, Germany
Distribution: Let there be Ubuntu... :o)
Posts: 573

Rep: Reputation: 32
Automated FTP login attacks


Hi,

There are hundreds and thousands of login attempts per day to our FTP server (pure-ftpd, Ubuntu 7.04). Because of them, other, legal, users are getting timeouts.

This is in /var/log/messages:
Code:
May 27 09:38:38 websrv-lindner pure-ftpd: (?@60-249-208-52.HINET-IP.hinet.net) [INFO] New connection from 60-249-208-52.HINET-IP.hinet.net
May 27 09:38:38 websrv-lindner pure-ftpd: (?@60-249-208-52.HINET-IP.hinet.net) [INFO] PAM_RHOST enabled. Getting the peer address
May 27 09:38:40 websrv-lindner pure-ftpd: (?@60-249-208-52.HINET-IP.hinet.net) [WARNING] Authentication failed for user [Administrator]
May 27 09:38:44 websrv-lindner pure-ftpd: (?@60-249-208-52.HINET-IP.hinet.net) [INFO] PAM_RHOST enabled. Getting the peer address
May 27 09:38:46 websrv-lindner pure-ftpd: (?@60-249-208-52.HINET-IP.hinet.net) [WARNING] Authentication failed for user [Administrator]
How to get rid of them?

(BTW, I've been already able to greatly reduce the number of SSH login attempts by applying advanced techniques with iptables suggested here. Unfortunately, that's a bit high to me, so I'm asking.^^)

Any ideas?

Thanks & cheers
Robert
 
Old 05-29-2007, 01:02 PM   #2
osor
HCL Maintainer
 
Registered: Jan 2006
Distribution: (H)LFS, Gentoo
Posts: 2,450

Rep: Reputation: 78
Quote:
Originally Posted by robbbert
(BTW, I've been already able to greatly reduce the number of SSH login attempts by applying advanced techniques with iptables suggested here. Unfortunately, that's a bit high to me, so I'm asking.^^)
Forgive me, but I don’t understand what you’re saying here. Do you mean that you tried using the recent match with iptables unsuccessfully for ssh? Or do you mean you used it successfully for ssh, but aren’t sure of how to use it for ftp?
 
Old 05-29-2007, 02:18 PM   #3
robbbert
Member
 
Registered: Oct 2005
Location: Hannover, Germany
Distribution: Let there be Ubuntu... :o)
Posts: 573

Original Poster
Rep: Reputation: 32
Quote:
Originally Posted by osor
Or do you mean you used it successfully for ssh, but aren’t sure of how to use it for ftp?
That's right. Thanks for the reply.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
automated ftp sang_froid Programming 6 05-07-2007 10:53 AM
Defending against ftp attacks otacon 14112 Linux - Security 3 04-02-2007 01:01 PM
automated ftp Anthraxnz Linux - Newbie 4 10-15-2005 09:36 PM
Automated Backup via FTP KePSuX Linux - Newbie 3 02-11-2004 08:25 AM
automated FTP backup josephswagner Linux - Software 2 06-06-2003 04:42 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Desktop

All times are GMT -5. The time now is 08:20 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration