LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 01-31-2012, 08:06 AM   #1
jayakumar01
Member
 
Registered: Nov 2011
Posts: 106

Rep: Reputation: Disabled
Linux Hacking using ssh


Hi
Today i received a complaint from one of external server that my server keep on delivering ssh attempt on there server by one of my ftp user .Any help me out how can i check number of ssh attempt made by my server


I could int find out the log of my server making ssh attempt on there at partiular schedule time 17:55.


8105 Jan 30 17:52:24 loft sshd[31609]: Failed password for root from 201.45.xxx.719 port 42959 ssh2
8106 Jan 30 17:52:24 loft sshd[31610]: Received disconnect from 201.45.xxx.71: 11: Bye Bye
8107 Jan 30 17:52:26 loft sshd[31612]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=201.45.xx.71 user=root
8108 Jan 30 17:52:27 loft sshd[31612]: Failed password for root from 201.45.xxx.71 port 43768 ssh2
8109 Jan 30 17:52:28 loft sshd[31613]: Received disconnect from 201.45.xxx.71: 11: Bye Bye
8110 Jan 30 18:29:23 loft sshd[32286]: Did not receive identification string from UNKNOWN
8111 Jan 30 18:46:17 loft sshd[317]: Did not receive identification string from 188.138.xxx.168
8112 Jan 30 18:46:18 loft sshd[324]: Did not receive identification string from 188.138.xx.168
8113 Jan 30 20:53:52 loft sshd[6441]: Did not receive identification string from 46.228.1xx.146
8114 Jan 30 20:58:05 loft sshd[6594]: Invalid user minecraft from 46.228.161.146
8115 Jan 30 20:58:05 loft sshd[6595]: input_userauth_request: invalid user minecraft
8116 Jan 30 20:58:05 loft sshd[6594]: pam_unix(sshd:auth): check pass; user unknown


client side i got these log of my server attempt.But when i check out the ssh log of my server i could int find out any instant of ssh hacking

Jan 30 17:55:41: Did not receive identification string from 188.138.xx.177
Jan 30 17:55:48: Did not receive identification string from 188.138.xx.177
Jan 30 17:55:48: Did not receive identification string from 188.138.xx.177
Jan 30 17:59:10: Invalid user sanjay from 188.138.xx.177
Jan 30 17:59:10: Invalid user sanjay from 188.138.xx.177
Jan 30 17:59:14: Invalid user sanjay from 188.138.xx.177
Jan 30 17:59:14: Invalid user sanjay from 188.138.xx.177
Jan 30 17:59:14: Invalid user sanjay from 188.138.xx.177
Jan 30 17:59:14: Invalid user sanjay from 188.138.xx.177
 
Old 01-31-2012, 08:11 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
In themselves you'll never have any logs of SSH client usage. Maybe you can get a pattern of attacks from the other party, see if there is a pattern, check all cronjobs on the system for all users etc.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Hacking and Linux Atharv Patil Linux - Newbie 2 01-11-2012 04:02 AM
C coding: Hacking ssh: dynamic local port forwarding implementation? Web31337 Programming 2 02-03-2010 06:05 AM
Hacking linux? matttah Linux - General 2 11-19-2004 09:22 PM
Hacking Exposed Wireless Hacking Chapter prompt Linux - Wireless Networking 0 05-08-2004 02:44 PM
hacking in linux, and cryptography zetsui Linux - Security 31 06-10-2003 03:50 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 02:00 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration