LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 04-24-2019, 10:53 AM   #1
jayotah
LQ Newbie
 
Registered: Apr 2019
Posts: 1

Rep: Reputation: Disabled
security


what is the best explanation for the following please

Mar 13 04:10:10 shell su(pam_unix)[26013]: session opened for user news by (uid=0)

Mar 13 04:10:10 shell su(pam_unix)[26013]: session closed for user news


Mar 13 22:51:38 shell sshd(pam_unix)[9364]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=hst-67-101-12-73.man-linx09.sky.net user=root

Mar 14 00:27:47 shell sshd(pam_unix)[9555]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=chem173.columbia.edu
user=nobody

Mar 15 00:34:51 shell sshd(pam_unix)[12755]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=207.188.80.171 user=root

Mar 15 12:53:37 shell sshd(pam_unix)[14402]: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=61-222-184-228.fast-link.hinet.net user=root
 
Old 04-24-2019, 08:04 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,323
Blog Entries: 28

Rep: Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142Reputation: 6142
Based on the little bit you've told us, I suspect it's probably random port scans. https://krebsonsecurity.com/2015/05/...rk-a-everyone/
 
1 members found this post helpful.
Old 04-24-2019, 08:13 PM   #3
scasey
LQ Veteran
 
Registered: Feb 2013
Location: Tucson, AZ, USA
Distribution: CentOS 7.9.2009
Posts: 5,727

Rep: Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211
frankbell could be right.
I'd guess the su to news was done by a cron job, perhaps...or someone logged in as root.
The other sshd entries look like login attempts from several random places...could be bots, could be people hacking about.
Maybe fail2ban would help?
 
Old 04-26-2019, 03:46 PM   #4
joe_2000
Senior Member
 
Registered: Jul 2012
Location: Aachen, Germany
Distribution: Void, Debian
Posts: 1,016

Rep: Reputation: 308Reputation: 308Reputation: 308Reputation: 308
Unless you did so already you may also want to disable root login and password authentication in your sshd_config.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[Security Questions] Last Login, how good is this feature for security breach info? t3gah Linux - Security 2 06-14-2005 01:02 AM
todays requirements regarding security (not limited to linux security) markus1982 Linux - Security 8 04-25-2004 10:58 PM
Linux security Vs Windows security keene General 50 11-01-2003 11:22 PM
Slackware Security Update: GDM security update phoeniXflame Slackware 2 08-26-2003 04:21 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 05:23 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration