Linux - SecurityThis forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
i get an email sent to me each day from my server for a system check, the first part of it is the security violations.
this is my question. i notice that i get someone trying to crack into me each day. i.e.-
Sep 19 17:32:23 cerberus sshd[11293]: Failed password for illegal user test from 80.53.45.254 port 32778 ssh2
Sep 19 17:32:25 cerberus sshd[2939]: Illegal user guest from 80.53.45.254
Sep 19 17:32:25 cerberus sshd(pam_unix)[2939]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser=
rhost=ft254.internetdsl.tpnet.pl
Sep 19 17:32:27 cerberus sshd[2939]: Failed password for illegal user guest from 80.53.45.254 port 32861 ssh2
Sep 19 17:32:30 cerberus sshd[24054]: Illegal user admin from 80.53.45.254
Sep 19 17:32:30 cerberus sshd(pam_unix)[24054]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser=
rhost=ft254.internetdsl.tpnet.pl
should i send the abuse line an email stating that someone on their network is trying to crack me? should i put the ip into my hosts.deny? should i do both, or just let it fly knowing that my system is doing what it should be doing?
i've ran the ip through whois and have the abuse address. when looking at the whois output, they are pretty particular or what they only want to see sent to that address. i feel i'm would be complying with their ideals. -
remarks: In case of abuse (intrusion attempts, hacking,
remarks: spamming or other unaccepted behavior) from
remarks: TP S.A. address space, please mail only to:
any thoughts?
i would think that putting the ip into the hosts.deny would drop the whole class since it's a broadcast address that i'm seeing.
Don't know if it helps, but the above is the result of host (ip address) and dig (ip address). Definitely report them to their and your ISP and try to block that particular ip address from your server.
i sent the isp an email. same with another ip that i noticed in my log. i've put them into my fw actions file to deny them from 22. i figure it's not real fair to block a whole broadcast range from using my http site.
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.