Re: security question

From: ynotssor (ynotssor_at_example.net)
Date: 06/09/05


Date: Thu, 9 Jun 2005 09:37:06 -0700


"Paul O'Donnell" <odonnellp@rogers.com> wrote in message
news:gYadnR44xu1M1zXfRVn-pw@rogers.com...

> Jun 8 11:58:01 cpe0010dcfc5db5-cm024350002546 sshd[4146]: Failed
> password for root from 202.134.124.150 port 51550 ssh2
>
> Does this mean that someone from 202.134.124.150 is trying to hack into
> my system? Out of curiosity I visited the ip address and found it to be
> http://www.wmg-group.com/index.asp. I have never visited this site in my
> life.
>
> What does this mean?

The IP address 202.134.124.150 probably redirects HTTP requests on port 80
to some webserver which is hosting a web presence for wmg-group.com. The
address may be just a NAT for a larger network behind it, any of which
machines may be the guilty party for the ssh root login attempts of your
machine.

As another poster pointed out, the address belongs to:
Domain Name: UNISITE.NET
Registrant:
Unisite Internet Presence Provider
   6A, Hang Seng Building,
   289 Sha Tsui Road,
   Tsuen Wan,
   N.T.,, - -
   HK

As long as you open your port 22 to the world, you will have endless numbers
of these attempts. You should only open the ports for access to specific
machines or networks that need the access.



Relevant Pages

  • Re: Update: UDP 770 Potential Worm
    ... > I still believe that the packets may be the result ... with the goal of knocking machines ... the network immediately after the 'attack', ... destined to port if you haven't sniffed it somehow? ...
    (Incidents)
  • Re: all ip addresses of machines in the local network
    ... database onto different machines residing in the same network. ... I expect that you would know the IP range for your network. ... the particular port. ... Amit Khemka -- onyomo.com ...
    (comp.lang.python)
  • Re: A Lot of Traffic on Network
    ... have you checked out the machines that are ... bigger switches and hubs i have seen there is usually a port activity light ... > Actually our network administrator quit. ...
    (microsoft.public.win2000.security)
  • RE: Blocking SMT Connections by clients
    ... > worthy of a blacklisting. ... The network is regularly ... > to construct a packet filter to do this - block any machines INSIDE ... > the network from making TCP connections to REMOTE hosts on port 25.. ...
    (microsoft.public.isa.configuration)
  • Re: Can find Vista box, cant share folders or printers.
    ... When I click 'Network' on the laptop the ... I've disabled Norton and Windows firewall entirely to make sure that's not ... public folder sharing - on ... start by running the Network Setup Wizard on all machines (see ...
    (microsoft.public.windows.vista.networking_sharing)