LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-15-2008, 04:40 AM   #1
mmilan
LQ Newbie
 
Registered: Nov 2005
Posts: 7

Rep: Reputation: 0
Problem with MySQL attack to the server


Hello all,

For last several days someone, from the same IP, is trying to connect to my MySQL server. Attempts are reopeating few time each minute. I blocked the IP in iptables, moved the mysql port to different one and nothing changed - he is still traying to connect to the old one, standard, mysql port. I sent two e-mail to the person who is responsible for that IP range and I received no answer.

The part of a log file:

Code:
May 15 10:16:58 seenet-mtp kernel: Shorewall:blacklst:DROP:IN=eth0 OUT= 
MAC=00:13:d4:6a:03:f0:00:08:7c:3e:15:80:08:00 SRC=160.75.98.* 
DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=21009 DF PROTO=TCP 
SPT=4402 DPT=3306 WINDOW=65535 RES=0x00 SYN URGP=0
Also, at almost same time started brute force attack over ssh. In this case situation is more complicated because IP is changing each time. I'm not sure if those two problems are connected.

At the moment it's not a big problem for my server, firewall takes care of everying but I'm afraid if it can make some bigger trouble.

Any help and suggestion will be welcome.

Milan

ps. I'm running Suse 10.3, kernel 2.6.22.17-0.1-default, with MySQL 5.0.45 and Apache 2.2.4

Last edited by mmilan; 05-15-2008 at 04:48 AM. Reason: more information
 
Old 05-15-2008, 05:30 AM   #2
ilikejam
Senior Member
 
Registered: Aug 2003
Location: Glasgow
Distribution: Fedora / Solaris
Posts: 3,109

Rep: Reputation: 97
Welcome to the Internet, the hostile network to end all hostile networks

My SSH gateway is scanned several times a day, and brute force attempts occur every other day. There's fairly regular vulnerability scans and attempts at SQL injections against my Apache/MySQL system, and even FTP is attacked on a not very regular basis.

Thankfully, the vast majority of this stuff is just compromised machines running scripts - as long as your passwords are good and your software is up to date, there shouldn't be anything to worry about. You might want to block persistent offenders' IPs at the firewall if you feel so inclined, or put something a little more intelligent in place to filter attacks, e.g.
http://www.la-samhna.de/library/brutessh.html

Dave
 
Old 05-15-2008, 05:39 AM   #3
mmilan
LQ Newbie
 
Registered: Nov 2005
Posts: 7

Original Poster
Rep: Reputation: 0
Thanks for the link.

For last tree years this is first time something like this happend, ten days without a minute of break - it's strange. And the main problem I can't contact the owner of host.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
mysql error Can't connect to local MySQL server through socket '/var/lib/mysql/mysql. SpellChainz Linux - Newbie 1 06-23-2007 03:35 PM
mysql error Can't connect to local MySQL server through socket '/var/lib/mysql/mysql. Dannux Linux - Software 3 03-24-2006 08:44 AM
Mysql Server ...virus Attack Found ! my-unix-dream Linux - Newbie 9 05-15-2005 11:35 AM
MySQL server problem after linking (mysql.sock) ewijaya Linux - General 4 01-19-2004 09:46 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:32 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration