LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-03-2009, 01:44 AM   #1
asad83
LQ Newbie
 
Registered: Mar 2009
Posts: 5

Rep: Reputation: 0
user trying to login but failed


Hi,

I have 2 servers A & B. both installed on different locations. both can ping and traceroute each other but there is no load shareing (both performing same functionality but independently). when i checked of server B /var/adm/messages, i can see that server A is trying to connect to server B but getting failed. and this is going on for long time. i mean it's not like someone manually try to enter but automatically its happening. i have already checked in cronjob but there is nothing. here are the logs,

May 3 11:01:27 Server A sshd[19269]: [ID 800047 auth.info] Failed password for user_id from 10.xxx.xxx.xxx port 53350 ssh2
May 3 11:01:27 Server A sshd[19271]: [ID 800047 auth.info] Failed password for user_id from 10.xxx.xxx.xxx port 53351 ssh2
May 3 11:01:27 Server A last message repeated 2 times

I would really appriciate some help on this. btw, there is no id_rsa or id_dsa file.

BR /asad
 
Old 05-03-2009, 04:04 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Can you check on server A what kind of user (system or human) "user_id" is? If it is a system user, is it for some monitoring or syncing application? If that doesn't reveal anything, is there sufficient network and process logging on server A to correlate logline times to reconstruct something?
 
Old 05-03-2009, 04:29 AM   #3
asad83
LQ Newbie
 
Registered: Mar 2009
Posts: 5

Original Poster
Rep: Reputation: 0
Hi Spawn,

well, the user is the default user of the system. and i checked yesterday's logging, and it revealed that last time i got this failed login message was 1544hrs and that time i was logged into the system and i left system at 1730hrs. and this message again started coming this morning at 10044hrs. now, point s, if there is no script running and there is no entry in cronjob, how can i find what's going on?

BR /asad
 
Old 05-03-2009, 07:02 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by asad83 View Post
well, the user is the default user of the system.
Please be more specific. The name of the user might be a clue.


Quote:
Originally Posted by asad83 View Post
if there is no script running and there is no entry in cronjob, how can i find what's going on?
Please be more specific. Crontab as in "crontab -l" or /etc/crontab or 'cat /var/spool/cron/*'? Also post the distribution and major kernel version (as in 2.4 or 2.6). And do you have a list of networked software on server A? You could continuously run 'netstat -antpe' to show the PID and UID of networked processes, 'lsof -P -n -i tcp:22' would do the same, run Auditd if your distro allows it or just block traffic to the host/port and see what breaks. Also see 'last', 'who', 'lastlog', 'lastb' to get a fix on human/system users. Posting back verbosely would be appreciated.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
New user failed to login using GUI, But for root it is working kcarun Solaris / OpenSolaris 8 07-29-2007 03:07 AM
Gnome: Cannot login as default user, sends back to login, works as root Danny-T Linux - Newbie 2 05-27-2006 03:44 AM
Suse 9.3 User Login Failed LinuxAgogo SUSE / openSUSE 11 11-09-2005 09:55 PM
Crazy blank dialog boxes and windows at login. Can't login as user soren625 Linux - General 2 08-11-2004 06:30 AM
I have re-installed MK 9.2 but cannot login as user, login as root works. bobinglis Mandriva 2 02-22-2004 11:39 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:38 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration