Log messages - "Failed password", "Invalid User", "User .. from .. not allowed"

From: Avinash Chopde (avinashc_at_yahoo.com)
Date: 07/26/05

  • Next message: Johan De Meersman: "Re: sftp redirect to common folder"
    Date: Tue, 26 Jul 2005 11:36:39 -0700 (PDT)
    To: secureshell@securityfocus.com
    
    

    For atleast certain users (that includes me!), locking
    out IP addresses on SSH failures is acceptable, and it
    works fine to block out script-kiddies.

    Most people have used the script I have with no
    problems.
    http://www.aczoom.com/cms/blockhosts
    The script assumes that the sshd install (atleast on
    Fedora) always prints out a "Failed <method> for ..."
    on a failed password, for example. It may print out an
    additional line in the log, such as "Illegal user..".
    Looking for IP addresses in the "Failed..." line is
    what I use to count and then block that IP address.

    But some people have reported that some OpenSSH
    installs do not print that "Failed ... " line.
    Instead, those installs print out a "Invalid user" or
    a "User ... from ... not allowed" line.
    For example, see this comment thread:
    http://www.aczoom.com/cms/blockhosts#comment-22

    I am trying to figure out if this is because of the
    configuration, or if this changed between OpenSSH
    releases.

    I certainly understand that parsing logs is not an
    exact science, and log lines are bound to change, etc,
    and the issues of denial-of-service, etc.

    Any info on this appreciated!

                    
    ____________________________________________________
    Start your day with Yahoo! - make it your home page
    http://www.yahoo.com/r/hs
     


  • Next message: Johan De Meersman: "Re: sftp redirect to common folder"

    Relevant Pages

    • Re: option argument length
      ... Ritesh Raj Sarraf wrote: ... > But I want the user to pass atleast one "option argument" for the program ... > required code. ... your script together with a description ...
      (comp.lang.python)
    • Re: User Account Setup
      ... opting for a dedicated server (atleast not yet). ... cron needs to run at ... So while the normal account creation is going on the script could run, ...
      (alt.php)
    • Re: Ill probably get the finger on this one.
      ... > Atleast, I hope, it's a good one. ... > Is there a command or script to get the ... Use GNU pinky. ...
      (comp.unix.sco.misc)
    • User Account Properties last accessed
      ... with a notification to administrator. ... Is there any script available to run and atleast we can find the user names ...
      (microsoft.public.windows.server.active_directory)
    • Re: Switch between AccessXP and Access2003
      ... kills the shell, creates an instance of Access, sets its automationsecurity ... The script successfully installs 2003, ... Repair on 2003 and keep it installed, then my script will work because it is ... Dim PathToMDE ...
      (microsoft.public.access.security)