LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-05-2007, 02:15 AM   #1
johnvoisey
Member
 
Registered: Jun 2002
Location: UK
Distribution: Used many over the years, main ones now "CentOS", Slackware and Arch
Posts: 31

Rep: Reputation: 15
Centos 5 vsftpd /var/log/secure question


Hi

This is going to sound REALLY dumb but here goes.

I have just updated my server to Centos 5. According to a swift "yum list" I am running version 2.0.5-10.el5 of vsftpd.i386

My 'logwatch' shows repeated failed attemots to log in to my server's vsftpd daemon as 'root', 'admin' and 'administrator' from a machine identified as 'astroplasma.Berkeley.Edu'

Scrutiny of /var/log/secure shows multiple entries similar to this

"Sep 4 05:40:57 velvetwood vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=Administrator rhost=astroplasma.Berkeley.EDU"

(There are hundreds like this)

My question is this ...

Is there really a hacker inside the Berkeley.Edu domain doing his best to climb into my server in violation of the UK Computer Misuse Act 1990 or can the /var/log/secure entries be 'spoofed' / 'forged' in the same way that email headers can be. Is the /var/log/secure entry created from some sort of reverse dns lookup of is it just the text from their "username" prompt

You see, if someone inside Berkeley.EDU really *IS* trying to grope my server's bits them I feel the need to have him/her spanked, or at least have it pointed out to them that such behaviour, if perpetrated in the UK, gets you prison time.

However I don't want to look a damn fool emailing the abuse department of what is arguably one of the serious computer centres of the world if what's actually happenned is some two-bit romanian or brazilian has tried to climb in using their domain name in his repose to my ftp 'login' prompt !

Any pointers to where I should be looking for answers gratefully received (!)
 
Old 09-05-2007, 09:50 AM   #2
TBKDan
Member
 
Registered: Dec 2005
Location: NY, USA
Distribution: Ubuntu
Posts: 44

Rep: Reputation: 16
I have been looking into a similar issue with fail2ban and banning failed vsftpd entries. Basically either somebody has access to their reverse DNS records and spoofed that they are from Berkeley, someone is using a compromised Berkeley computer as a launch point, or someone in Berkeley is actually trying to get into your system. Most likely it's #2, and I would report it to their abuse department (if there was a security breach, they will be happy you did). I also advise you to look into Fail2ban (I have it running on CentOS 5 as well). It does work, but occasionally somebody can screw with their reverse DNS records and you will be unable to ban them. Make sure you disable root logins in vsftpd also.
 
Old 09-06-2007, 12:32 AM   #3
johnvoisey
Member
 
Registered: Jun 2002
Location: UK
Distribution: Used many over the years, main ones now "CentOS", Slackware and Arch
Posts: 31

Original Poster
Rep: Reputation: 15
Thanks TBKDan I'll send that email right now !
 
Old 09-06-2007, 06:45 AM   #4
TBKDan
Member
 
Registered: Dec 2005
Location: NY, USA
Distribution: Ubuntu
Posts: 44

Rep: Reputation: 16
I take back the second-to-last sentence in my first post; it turns out that there was some issues with 0.8.0 of Fail2ban's regex, so now 0.8.1 bans everything Highly recommended, and pretty easy to setup. Simplest instructions: download it, extract it, run the install script, change the "enabled" to true in jail.conf, and then fail2ban-client start You should have some way to do that every bootup though (rc.local works fine).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
/var/log/secure format Latem Linux - Security 1 07-24-2005 08:00 PM
/var/log/secure ??? MikeFoo1 Linux - Security 2 06-22-2005 03:42 AM
APF and /var/log/secure.1... tilt32 Linux - Security 5 03-28-2005 07:19 AM
/var/log/secure allelopath SUSE / openSUSE 3 02-15-2005 08:56 AM
/var/log/secure dragon Linux - Security 6 12-02-2003 08:45 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:02 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration