LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-13-2006, 06:53 PM   #1
zdenisl
Member
 
Registered: Nov 2005
Distribution: CentOS-4
Posts: 41

Rep: Reputation: 15
A lot of authentication failure messages


I just noticed in /var/log/messages I have a lot of authentication failure messages from foreign IP addresses.

I guess this is a hacker. How can I prevent this?

Today I've had 50 so far.

Here's a snipit:
Code:
May  7 09:38:45 ramair sshd(pam_unix)[24218]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=217.160.250.152  user=root
May  7 11:11:48 ramair sshd(pam_unix)[26330]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=218.89.164.18  user=root
May  7 11:11:56 ramair sshd(pam_unix)[26332]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=218.89.164.18  user=root
May  7 11:12:03 ramair sshd(pam_unix)[26334]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=218.89.164.18  user=root
May  7 11:12:13 ramair sshd(pam_unix)[26336]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=218.89.164.18  user=root
May  7 11:12:25 ramair sshd(pam_unix)[26338]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=218.89.164.18  user=root
May 13 12:00:43 ramair sshd(pam_unix)[5796]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=218.28.168.85  user=ftp
May 13 12:01:07 ramair sshd(pam_unix)[5806]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=218.28.168.85  user=postfix
May 13 12:01:15 ramair sshd(pam_unix)[5808]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=218.28.168.85  user=postgres
May 13 12:01:28 ramair sshd(pam_unix)[5812]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=218.28.168.85  user=root
 
Old 05-13-2006, 08:29 PM   #2
btmiller
Senior Member
 
Registered: May 2004
Location: In the DC 'burbs
Distribution: Arch, Scientific Linux, Debian, Ubuntu
Posts: 4,290

Rep: Reputation: 378Reputation: 378Reputation: 378Reputation: 378
Take a look at the "failed SSH login" thread stickied at the top of this forum.
 
Old 05-16-2006, 09:44 AM   #3
lucktsm
Member
 
Registered: May 2004
Location: Atlanta, GA USA
Distribution: Redhat ES4, FC4, FC5, slax, ubuntu, knoppix
Posts: 155

Rep: Reputation: 30
Change the port of the SSH server to listen on something other than the default port. This will reduce the number of bots that are bruteforce attacking you.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
kbluetoothd authentication failure Law1213 Linux - Software 0 12-28-2005 08:40 PM
UT2004 Authentication failure darkaudti Linux - Games 9 08-31-2004 04:31 PM
authentication failure mendiratta Linux - Security 1 07-03-2004 03:20 AM
POP3 authentication failure J_Szucs Linux - Software 8 07-25-2003 07:14 AM
CHAP Authentication failure reader Linux - Networking 2 04-30-2001 10:08 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:43 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration