LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-09-2004, 09:41 AM   #1
mindcry
Member
 
Registered: Nov 2002
Distribution: Libranet 2.8 Debian Solaris 9
Posts: 118

Rep: Reputation: 15
many failed ssh attemps


I have a server that is fully exposed to the internet. I am seeing that there are many failed ssh connections and I am sure the same goes for other protocols. I was thinking maybe to throttle the port with iptables to like 1 connection per whatever, which I am not 100% on how to do that so, if someone could point me to the right direction that would be great. I am going to try using MaxStartups in the meantime which might help a little bit. I am open to suggestions though.
 
Old 08-09-2004, 11:46 AM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
There is some form of automated malware (a scanner or "worm") that is currently circulating around the internet. It attempts several very simple username-password combinations (like "admin" "test" etc). Unless you have extremely poor passwords, then you really have nothing to worry about. It doesn't appear to be a true brute force attack.

You can eliminate these ssh login attempts by restricting ssh access to only the hosts you need to provide access. This can be done via iptables or tcp_wrappers (hosts.allow/deny). If you cannot restrict access, then make sure you are using a sensible password policy.
 
Old 08-09-2004, 11:56 AM   #3
mindcry
Member
 
Registered: Nov 2002
Distribution: Libranet 2.8 Debian Solaris 9
Posts: 118

Original Poster
Rep: Reputation: 15
yeah thats what I am seeing. It's test guest admin and user that I am seeing, and those are not accounts on my server so they cant get in anyway. The only one I am concerned about is there were 12 failed login attempts to the root account. I have been blocking the ips as I see them and they all seem to be from either korea or taiwan.

--edit--
maybe disabling the root login from ssh might do the trick and just have one account that can su over.

Last edited by mindcry; 08-09-2004 at 12:01 PM.
 
Old 08-09-2004, 01:02 PM   #4
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
For more info on this topic, see the post I've stickied at the top of this forum.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Failed SSH login attempts Capt_Caveman Linux - Security 38 01-03-2006 03:22 PM
Daily logging attemps landuchi Linux - Security 3 01-15-2005 07:37 PM
mozilla through ssh failed eantoranz Linux - Software 5 11-18-2004 12:57 PM
failed ssh bones996 Linux - Networking 6 10-30-2004 08:46 PM
Failed Login through SSH? Help PLEASE tangman Linux - Newbie 8 03-31-2004 03:02 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:09 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration