Re: SSH server under attack...
- From: Daniel Cid <danielcid@xxxxxxxxxxxx>
- Date: Fri, 10 Feb 2006 12:48:01 -0300 (ART)
Take a look at the OSSEC HIDS. It analyses sshd logs,
firewall logs, ids logs, etc. It execute responses
based on the rules, so you can block automated scans
(via iptables ,ipfilter, hosts.deny, etc).
It also performs integrity checking and rootkit
detection..
More info: http://www.ossec.net/hids/
Thanks,
Daniel B. Cid
--- Juan Hernandez <hvjuan@xxxxxxxxx> escreveu:
Hey there...=== message truncated ===
What if there is some 'automated daemon' running
thru the logs and once
it sees an ip address doing this, add a chain to
iptables?
I did this in python about a year ago, reading the
logs once every hour
-cron process- and if someone tries to log with at
least 5 diffent
users, it adds a chain to my iptables settings and
that's it, the
attacker is blocked
Also, there are many open source tools that might do
a similar task
Juan
Isaac Perez wrote:
All of your users connect by ssh?configuration to
If only admins need to connect you can change the
only allow one ssh user to connect, with aextrange name. At least you
will be sure that the user never will be in acommon list.
And after you can su to the user you want.that attacks you, I do
Alsoo you can contact to the ISP of the servers
that, and sometimes works.similar, to close
Alsoo you can configure tcpwrapers,or any software
and discard any connection when a ip try toconnect so many times.
it!!!
En/na Dave ha escrit:
My SSH server has been under DoS and I cant stop
2222. This isnt going to
I changed the port of the SSH server from 22 to
script that attacks portreally do much but it would stop some automated
attacked again on port22. OK...within a few hours the server was being
that he is actively2222. This is an *active* attacker, active in
logs dont show anymonitoring what he is doing. The router/firewall
port of the attackdropped packets sent to port 22 so he changed the
200.55.192.29. This belongsscript. Now, the new machine to attack me is
South America Textilesto a company in south america called 'Springs
is hosting a webserverLtda.'. I scanned the machine and found that it
among other services.(Apache/2.0.52 (Fedora) Server at www.springs.cl)
me was also an apacheThe last machine the attacker used to brute_force
various webservers (mostserver (rh linux). So this attacker is cracking
order to use theselikely) or some other service on these boxes in
notified the admin of thismachines as an attack platform. Now, yes, i
going to put ancompany etc..but think of this. If this admin is
what kind of admin is*unused* and unprotected server on the net then
Calling the authoritieshe? Will he even care about my email? Who knows!
nobody...who cares if myis not going to work 'cause frankly I am a
waste resource (money) inservers are under attack! No one is going to
So what do we knowtrying to find this guy, so really its up to me.
conflicting: He has the abilityabout this guy? At first the info seems
at his disposal but heto crack a number of random servers and use them
over...why? First off, theis running the same stupid attack over and
guess a usernameattack is a brute force attack. He is trying to
server and get shellpassword combo in order to be able to log into my
dummy. So what is heaccess...but maybe not. Like I said..he is no
brute force tool is justdoing? I think DoS (denial of service) , the
by doing this. Maybe hethe means to an end. He isnt trying to break in
to the next trick up hiscoudnt break in to my server so he is resorting
to log into my serversleeve. By having all these machines attempting
bandwidth in effectover and over he might be trying to use up my
at the logs you willcausing a DoS to anyone! OR...In closely looking
::ffff:200.55.192.29 portnotice something *unusual*:
Failed password for invalid user admin from
::ffff:200.55.192.29 port34182 ssh2
Invalid user admin from ::ffff:200.55.192.29
Failed password for invalid user admin from
::ffff:200.55.192.29 port34679 ssh2
Invalid user admin from ::ffff:200.55.192.29
Failed password for invalid user admin from
::ffff:200.55.192.2934752 ssh2
Invalid user administrator from
from ::ffff:200.55.192.29Failed password for invalid user administrator
::ffff:200.55.192.29port 35253 ssh2
Invalid user administrator from
from ::ffff:200.55.192.29Failed password for invalid user administrator
::ffff:200.55.192.29port 35735 ssh2
Invalid user administrator from
from ::ffff:200.55.192.29Failed password for invalid user administrator
::ffff:200.55.192.29 portport 36237 ssh2
Invalid user tads from ::ffff:200.55.192.29
Failed password for invalid user tads from
::ffff:200.55.192.29 port36703 ssh2
Invalid user tads from ::ffff:200.55.192.29
Failed password for invalid user tads from
::ffff:200.55.192.29 port36813 ssh2
Invalid user tads from ::ffff:200.55.192.29
Failed password for invalid user tads from
::ffff:200.55.192.29 port37332 ssh2
Invalid user tip from ::ffff:200.55.192.29
Failed password for invalid user tip from
::ffff:200.55.192.29 port37820 ssh2
Invalid user tip from ::ffff:200.55.192.29
Failed password for invalid user tip from
::ffff:200.55.192.29 port38267 ssh2
Invalid user tip from ::ffff:200.55.192.29
Failed password for invalid user tip from
::ffff:200.55.192.29 port38757 ssh2
Invalid user myra from ::ffff:200.55.192.29
Failed password for invalid user myra from
::ffff:200.55.192.29 port38844 ssh2
Invalid user myra from ::ffff:200.55.192.29
Failed password for invalid user myra from
::ffff:200.55.192.29 port39333 ssh2
Invalid user myra from ::ffff:200.55.192.29
Failed password for invalid user myra from
::ffff:200.55.192.29 port39812 ssh2
Invalid user jack from ::ffff:200.55.192.29
Failed password for invalid user jack from
::ffff:200.55.192.29 port40312 ssh2
Invalid user jack from ::ffff:200.55.192.29
Failed password for invalid user jack from
::ffff:200.55.192.29 port40787 ssh2
Invalid user jack from ::ffff:200.55.192.29
Failed password for invalid user jack from
this40893 ssh2
Invalid user sya from ::ffff:200.55.192.29
Each user name was tried three times. What does
guess that he is trying tomean...I dont know but right off hand I would
servers will disallow a userlock out legit user accounts. You see some
This, strangely enough,to log in if they entered three wrong passwords.
attacker has putis used to help stop brute forcing!!! Anyway, The
*might* be found on mytogether a list of *potential* user names that
effect creating a DoS toserver and is attempting to lock them out...in
any users whose names appear on this list.
_______________________________________________________
Yahoo! doce lar. Faça do Yahoo! sua homepage.
http://br.yahoo.com/homepageset.html
---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Tailor your education to your own professional goals with degree
customizations including Emergency Management, Business Continuity Planning,
Computer Emergency Response Teams, and Digital Investigations.
http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------
- Prev by Date: RE: Linux Dial In Server (PPP) Auth To Netware RADIUS
- Next by Date: OpenOffice 1.1 password recovery or removal?
- Previous by thread: Re: SSH server under attack...
- Next by thread: Re: Securing Blackberries
- Index(es):
Relevant Pages
|