RE: brute force ssh attack

From: Jeff Vian (jvian10_at_charter.net)
Date: 05/05/05

  • Next message: Gene Smith: "Re: (perl update clash) FC3 x86_64 Important Announcement"
    To: For users of Fedora Core releases <fedora-list@redhat.com>
    Date: Wed, 04 May 2005 20:47:07 -0500
    
    

    On Wed, 2005-05-04 at 18:23 -0700, Daniel B. Thurman wrote:
    > Folks,
    >
    > Seems that I am getting daily brute-force ssl attacks --
    > Anything I can or should do?
    >
    > Here is the System Logs:
    > =======================================
    > May 4 01:01:50 linux sshd[10438]: Did not receive identification string from ::ffff:194.65.138.98
    > May 4 01:04:44 linux sshd[10448]: Illegal user temp from ::ffff:194.65.138.98
    > May 4 01:04:57 linux sshd[10448]: Failed password for illegal user temp from ::ffff:194.65.138.98 port 52888 ssh2

    snip

    > May 4 13:07:04 linux sshd[24906]: Failed password for illegal user admins from ::ffff:209.76.72.12 port 52516 ssh2
    > May 4 13:07:04 linux sshd[24908]: Illegal user admins from ::ffff:209.76.72.12
    > May 4 13:07:07 linux sshd[24908]: Failed password for illegal user admins from ::ffff:209.76.72.12 port 52610 ssh2
    >

    I set my firewall to block ssh from everywhere except the few places I
    might use for remote access. It drastically cut down the attempts to
    get in. I now only get hit from one or 2 IPs a day.

    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: Gene Smith: "Re: (perl update clash) FC3 x86_64 Important Announcement"

    Relevant Pages

    • Re: XP Less Secure than 98 for Sharing Files
      ... Ever tried chasing up settings ... > that and/or your firewall supports it) or running with no firewall. ... If you have TCP/IP loaded at all, regardless of NetBEUI, and have Internet ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Firewall Comparisons
      ... > I admit to a predjudice towards firmware-based firewalls, ... > underlying OS's of an OS-based firewall may or may not be properly hardened. ...
      (Security-Basics)
    • Re: some reality about iptables, please
      ... He also links it to adaptive firewall rules ... harsh critical review by security professionals, ... BTW, my previous post should have indicated PRE-up and POST-down clauses ...
      (Debian-User)
    • RE: Wireless access
      ... I think the DMZ interface of a firewall is probably ... on the dmz interface, and in a perfect world, an IDS sensor listening. ... to facilitate one-on-one interaction with one of our expert instructors. ...
      (Security-Basics)
    • Re: Router/Firewall Recommendation
      ... he wants to know his options with linux firewall. ... just by reading this threads I learn what my options are ...
      (RedHat)