LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-19-2005, 08:33 PM   #1
jonfa
Member
 
Registered: Mar 2001
Location: FL
Posts: 257

Rep: Reputation: 30
Possible breakin attempt


Hi all,

After checking my log files I came across the following in my /var/log/secure file on my FC3 Box:

Jul 17 17:26:04 computer1 sshd[12390]: Address 66.230.209.161 maps to closetcase.candidhosting.com, but this does not map back to the address - POSSIBLE BREAKIN ATTEMPT!

I had SSH enabled on my router, but quickly closed the port. How can I ban this address? Should I be worried?
 
Old 07-19-2005, 08:51 PM   #2
juanbobo
Member
 
Registered: Mar 2005
Location: Chicago
Distribution: Gentoo AMD64
Posts: 365

Rep: Reputation: 30
I don't think you should be too worried, someone apparently forged their address when trying to connect to your SSH server. It doesn't look like they are repeatedly trying to connet and regardless, the pause between login attempts with SSH makes it really difficult to brute force your password.


I think you can add the real IP to your /etc/hosts.deny file...

http://linux.about.com/od/commands/l...l5_hostsde.htm

Last edited by juanbobo; 07-19-2005 at 08:53 PM.
 
Old 07-19-2005, 09:35 PM   #3
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
That warning can also be generated by NATed hosts behind a firewall due to the IP not resolving to the same hostname. Either way, If that host has no reason to be accessing your SSHd server it's still a good idea to ban it anyway.
 
Old 07-19-2005, 10:58 PM   #4
juanbobo
Member
 
Registered: Mar 2005
Location: Chicago
Distribution: Gentoo AMD64
Posts: 365

Rep: Reputation: 30
Check out fwlogwatch: http://fwlogwatch.inside-security.de

It is cabable of realtime log analysis, so it may help you to block unwelcome peeps.
 
Old 07-20-2005, 09:05 AM   #5
[bc]paddy.hm
LQ Newbie
 
Registered: Jun 2003
Location: Hameln / Germany
Posts: 8

Rep: Reputation: 0
Re: Possible breakin attempt

Quote:
Originally posted by jonfa
Hi all,

After checking my log files I came across the following in my /var/log/secure file on my FC3 Box:

Jul 17 17:26:04 computer1 sshd[12390]: Address 66.230.209.161 maps to closetcase.candidhosting.com, but this does not map back to the address - POSSIBLE BREAKIN ATTEMPT!

I had SSH enabled on my router, but quickly closed the port. How can I ban this address? Should I be worried?
Maybe DNS not setup correctly?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Attempt#2: Help...?? lostinpurdy Linux - Newbie 17 10-17-2005 08:23 PM
A possible breakin? dinolinux Linux - Security 4 08-31-2005 07:14 PM
Going To Attempt Linux sotch Linux - Software 6 04-02-2005 04:46 AM
Failed attempt at 2.6.10 icpsvt Slackware 6 02-08-2005 08:25 PM
Having trouble with first attempt cothrige Linux - Networking 9 04-28-2004 06:20 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:51 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration