LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-02-2009, 07:49 PM   #1
MQMan
Member
 
Registered: Jan 2004
Location: Los Angeles
Distribution: Slack64 14.1
Posts: 581

Rep: Reputation: 38
Increase in ssh "probes" with user admin


Just recently, I've been seeing a number of attempts to log into my box, using the user "admin".

These are not part of the usual brute force attacks that I see, when they try hundreds of user names. These are just a single attempt, always with "admin".

Is there some new exploit that they're trying to use.

Cheers.
 
Old 12-02-2009, 09:45 PM   #2
kbp
Senior Member
 
Registered: Aug 2009
Posts: 3,790

Rep: Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653
Maybe someone is looking for a specific type of device with a known default password set ...
 
Old 12-02-2009, 10:06 PM   #3
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,308

Rep: Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744
Could an MS guy; expecting admin to exist instead of 'root'.
Alternatively, I believe some people create an admin with root privs user so they can happily block remote root logins, but still get superuser work done.
It's an obvious choice of name for an alternate eg like 'mgr'.
 
Old 12-03-2009, 10:58 AM   #4
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
System-level accounts can actually be given any name. The name of the account shouldn't define the severity of the attack.

I'd be concerned whether it was 'admin', 'root', or 'httpd'. This is more than likely an automated bruteforcing attempt. It's looking for all combinations of usernames and passwords, more than likely. Not all such attacks look for default usernames and passwords. Some actually run dictionary attacks (which are more exhaustive, but slower in duration). It depends on the persistence of the attack.

This is why I always use key-based authentication. The attacker can guess all they want, but their attempts are rejected when they don't present the proper key.
 
Old 12-05-2009, 03:48 PM   #5
MQMan
Member
 
Registered: Jan 2004
Location: Los Angeles
Distribution: Slack64 14.1
Posts: 581

Original Poster
Rep: Reputation: 38
Quote:
Originally Posted by unixfool View Post
It's looking for all combinations of usernames and passwords, more than likely. Not all such attacks look for default usernames and passwords.
That's what I'm more used to, where it tries hundreds, or thousands of names. None of which are ever going to work, because I only allow "public key", and disable password authentication.

It's just this sudden spate of "single" attempts that I find strange.

Cheers.
 
Old 12-06-2009, 10:39 PM   #6
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,308

Rep: Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744Reputation: 2744
Sounds like a 'slow brute force distributed attack' eg see http://bsdly.blogspot.com/2009/10/th...uncharmed.html
http://www.linuxquestions.org/questi...ttacks-771978/

An attempt to get around tools like fail2ban.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LogWatch: "possible successful probes"? Quip11 Linux - Security 1 07-20-2009 04:39 PM
"SSH tunneling" is a confusing Joke solving anything because you have to be admin frenchn00b General 11 05-28-2009 12:35 PM
Where do "Admin" and "User" guides live? Swan1 SUSE / openSUSE 1 07-07-2006 12:53 PM
What's this in LogWatch: "!!!! 1 possible successful probes" ? bomix Linux - Security 1 07-29-2005 10:23 PM
[Redhat] make "admin" account same privledges as "root" Bi0haZarD Linux - Networking 20 01-12-2005 10:47 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:33 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration