LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-14-2010, 07:43 AM   #1
supanatral
LQ Newbie
 
Registered: Mar 2010
Posts: 19

Rep: Reputation: 0
"possible break-in attempt!"


Everyday logwatch emails me with the latest statistics on the server and all the logs. Today I looked at the logs and here's what I found:

Quote:
**Unmatched Entries**
reverse mapping checking getaddrinfo for 221-143-48-7.tongkni.co.kr failed - POSSIBLE BREAK-IN ATTEMPT! : 2 time(s) Excess permission or bad ownership on file /var/log/btmp : 33 time(s) reverse mapping checking getaddrinfo for 34.174.164.60.broad.jq.gs.dynamic.163data.com.cn failed - POSSIBLE BREAK-IN ATTEMPT! : 23 time(s)
This sounds like something to worry about....
 
Old 05-14-2010, 08:33 AM   #2
AlucardZero
Senior Member
 
Registered: May 2006
Location: USA
Distribution: Debian
Posts: 4,824

Rep: Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615
"reverse mapping checking getaddrinfo for xxxxx failed" is a red herring; it just means that the forward and reverse DNS don't match which means the ISP sucks and nothing else.

You should fix /var/log/btmp, but that's also not important.

Now, the count of 23 SSH login attempts from one host is. Look around at topics here and Google on SSH security. Start by installing DenyHosts or Fail2Ban, to prevent people from getting more than (e.g.) 5 login attempts before being blocked.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Troubleshooting large partition "attempt to access beyond end of device" dear mr. trout Linux - Server 4 10-21-2008 09:02 AM
How can I reinstall xine engine when updater says "BREAK" (in red) ? mosthigh Linux - Software 0 06-12-2008 04:19 AM
Trying webmin, getting "attempt to connect to 127.0.0.1:10000 (localhost) failed" jeffreybluml Linux - General 1 08-16-2007 11:16 AM
cgi-bin: "attempt to invoke directory as script" hamish Linux - Software 0 12-09-2004 12:45 PM
php ide with "break" and "trace" Kayaker Programming 3 04-25-2003 02:52 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:56 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration