LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 09-20-2004, 07:45 PM   #1
emetib
Member
 
Registered: Feb 2003
Posts: 482

Rep: Reputation: 33
abuse@email.com security warnings


thanks for taking the time to read this.

i get an email sent to me each day from my server for a system check, the first part of it is the security violations.

this is my question. i notice that i get someone trying to crack into me each day. i.e.-
Sep 19 17:32:23 cerberus sshd[11293]: Failed password for illegal user test from 80.53.45.254 port 32778 ssh2
Sep 19 17:32:25 cerberus sshd[2939]: Illegal user guest from 80.53.45.254
Sep 19 17:32:25 cerberus sshd(pam_unix)[2939]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser=
rhost=ft254.internetdsl.tpnet.pl
Sep 19 17:32:27 cerberus sshd[2939]: Failed password for illegal user guest from 80.53.45.254 port 32861 ssh2
Sep 19 17:32:30 cerberus sshd[24054]: Illegal user admin from 80.53.45.254
Sep 19 17:32:30 cerberus sshd(pam_unix)[24054]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser=
rhost=ft254.internetdsl.tpnet.pl

should i send the abuse line an email stating that someone on their network is trying to crack me? should i put the ip into my hosts.deny? should i do both, or just let it fly knowing that my system is doing what it should be doing?

i've ran the ip through whois and have the abuse address. when looking at the whois output, they are pretty particular or what they only want to see sent to that address. i feel i'm would be complying with their ideals. -
remarks: In case of abuse (intrusion attempts, hacking,
remarks: spamming or other unaccepted behavior) from
remarks: TP S.A. address space, please mail only to:


any thoughts?

i would think that putting the ip into the hosts.deny would drop the whole class since it's a broadcast address that i'm seeing.
 
Old 09-20-2004, 07:51 PM   #2
micxz
Senior Member
 
Registered: Sep 2002
Location: CA
Distribution: openSuSE, Cent OS, Slackware
Posts: 1,127

Rep: Reputation: 75
http://www.linuxquestions.org/questi...hreadid=215431

Yep it's most likely 80.53.45.254 is infected or some kiddie is using this box to scan/test your server.
 
Old 09-20-2004, 09:34 PM   #3
emetib
Member
 
Registered: Feb 2003
Posts: 482

Original Poster
Rep: Reputation: 33
thanks for the link.

cheers.
 
Old 09-21-2004, 12:30 PM   #4
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Lubuntu
Posts: 19,068
Blog Entries: 4

Rep: Reputation: 385Reputation: 385Reputation: 385Reputation: 385
Code:
$ host 80.53.45.254
254.45.53.80.in-addr.arpa domain name pointer ft254.internetdsl.tpnet.pl.
$ dig 80.53.45.254

; <<>> DiG 9.2.3 <<>> 80.53.45.254
;; global options:  printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 30612
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0

;; QUESTION SECTION:
;80.53.45.254.                  IN      A

;; AUTHORITY SECTION:
.                       10800   IN      SOA     A.ROOT-SERVERS.NET. NSTLD.VERISIGN-GRS.COM. 2004092100 1800 900 604800 86400

;; Query time: 162 msec
;; SERVER: 192.168.2.1#53(192.168.2.1)
;; WHEN: Tue Sep 21 18:30:06 2004
;; MSG SIZE  rcvd: 105
Don't know if it helps, but the above is the result of host (ip address) and dig (ip address). Definitely report them to their and your ISP and try to block that particular ip address from your server.
 
Old 09-21-2004, 01:36 PM   #5
micxz
Senior Member
 
Registered: Sep 2002
Location: CA
Distribution: openSuSE, Cent OS, Slackware
Posts: 1,127

Rep: Reputation: 75
Or you could call eh?:

Holder's Contact object:
company: TP S.A. - "POLPAK"
street: UL. NOWOGRODZKA 47a
city: 00-695 WARSZAWA
location: PL
handle: nsk80879
phone: +48.225850800
last modified: 2004.01.17
registrar: nask

just kidding'
 
Old 09-24-2004, 06:39 PM   #6
emetib
Member
 
Registered: Feb 2003
Posts: 482

Original Poster
Rep: Reputation: 33
i sent the isp an email. same with another ip that i noticed in my log. i've put them into my fw actions file to deny them from 22. i figure it's not real fair to block a whole broadcast range from using my http site.

cheers.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
email abuse ice99 General 3 11-20-2005 09:55 AM
low disk space email warnings pyroman59 Linux - Software 3 10-19-2005 04:21 PM
Email abuse Jon Doe Linux - Security 25 07-01-2005 03:59 PM
Fake Redhat Security Update Email Capt_Caveman Linux - Security 1 10-26-2004 12:22 AM
Security problems with email Sarcha Linux - Security 4 02-05-2004 11:47 AM


All times are GMT -5. The time now is 05:13 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration