LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 03-22-2007, 02:32 PM   #1
Bishop609
Member
 
Registered: Jul 2006
Distribution: Fedora Core 6
Posts: 30

Rep: Reputation: 15
vsftpd - Unauthorized User


Kind of a serious issue here.

I am running vsftpd on FD6. Its a small private server, and I use it for school for transfering documents when needed.

I use the server monitor gkrellm and have noticed that late at night someone logs on, and I see eth1 activity which leads me to believe they are downloading. Sometimes I think he logs on twice concurrently from the same location. This really bothers me, as I keep track of everybody who knows about the server.

I tracerouted the IP address of the person and they are in China (I am in Philadelphia)

BUT! When I go into the vsftpd.log there are no entries...and I know of no other logs.

I only have one user authorized to log on, and I changed his password many times...still this user has longged on.

I am a bit of a novice, and I really would appreciate some help on what to do here. Thank you very much.
 
Old 03-22-2007, 04:21 PM   #2
trickykid
LQ Guru
 
Registered: Jan 2001
Posts: 24,149

Rep: Reputation: 269Reputation: 269Reputation: 269
Is anonymous logins disabled? ethernet activity doesn't necessarily mean someone is logging on thru FTP or the like.. what do your logs tell you?
 
Old 03-23-2007, 08:51 AM   #3
Bishop609
Member
 
Registered: Jul 2006
Distribution: Fedora Core 6
Posts: 30

Original Poster
Rep: Reputation: 15
My logs do not record any of the unauthorized connections...only my own.

What would really be great is if I could see a log of all attempted logon attempts...something other than vsftpd.log
 
Old 03-23-2007, 10:49 AM   #4
trickykid
LQ Guru
 
Registered: Jan 2001
Posts: 24,149

Rep: Reputation: 269Reputation: 269Reputation: 269
Quote:
Originally Posted by Bishop609
My logs do not record any of the unauthorized connections...only my own.

What would really be great is if I could see a log of all attempted logon attempts...something other than vsftpd.log
Check /var/log/messages but what I think your seeing is not specific to FTP login attempts.

In any case, there are script kiddies that will hit any publicly accessible computer to attempt to login. I literally get thousands of hits or attempts on ssh on port 22 on my servers.
 
Old 03-23-2007, 03:31 PM   #5
Bishop609
Member
 
Registered: Jul 2006
Distribution: Fedora Core 6
Posts: 30

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by trickykid
Check /var/log/messages but what I think your seeing is not specific to FTP login attempts.

In any case, there are script kiddies that will hit any publicly accessible computer to attempt to login. I literally get thousands of hits or attempts on ssh on port 22 on my servers.
I am glad you mentioned that. Since turning off my FTP service I am now getting hits on my SSH. So am I to gather that attempts on these things are common place, and that I shouldnt get all bent outta shape?

Here are a few lines from my messages file...I have no idea what Im looking at...care to explain?

Mar 23 10:27:09 Sandy kernel: 4gb seg fixup, process beagled (pid 3159), cs:ip 73:0811853f
Mar 23 10:27:09 Sandy kernel: 4gb seg fixup, process beagled (pid 3159), cs:ip 73:0083d8f9


Oh and yes Anon ftp is off


He he...your page is the best buy the way

Last edited by Bishop609; 03-23-2007 at 03:55 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
VSFTPD:How to have vsftpd ask for anon user to "send email for password"? dmurray8888 Linux - Networking 1 08-31-2008 06:04 PM
Trying to get VSFTPD as a non-root user moore757 Linux - Networking 1 02-22-2006 08:41 PM
vsftpd user rights compughnet Linux - Software 0 11-09-2005 12:02 PM
server listening on port 22 and attempted logins from an unauthorized user kevinlyfellow Linux - Networking 2 03-24-2005 10:41 PM
unauthorized IP ?!? fransemail Linux - Software 1 04-24-2004 09:15 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 01:19 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration