possible hack thoughts please

epicwinter_at_hotmail.com
Date: 06/17/05


Date: 16 Jun 2005 17:50:19 -0700

I work on a computer and I often ssh to another to do maintenance and
various tasks on it. The computer i ssh into was mysteriously rebooted
today and as far as I know there was no power outage and now major
errors in the logs. Both computers are pretty locked down except for
needed services using iptables.
So this wierded me out a bit and I started looking through the logs. I
noticed the normal script kiddie action. But the wierd thing i see a
lot of hits from the same ip on both computers:
218.188.2.4
With this type of crap:
Failed password for illegal user amy from 218.188.2.4 port 43774 ssh2

This seems too much of a coincidence to me. Other than that everything
is running normal. I don't know what else to check.



Relevant Pages

  • Re: SSH compiled with backdoor
    ... backdoor passwd into the ssh and wont show up in wtmp, ... ever he logs in as) invisible, so say u login with the username root and ... your use the global hidden passwd it will allow him on as root. ... the file that logs all the logins with time stamps and src ips is "dev/saux" ...
    (Incidents)
  • RE: How to display IP of ssh user in message?
    ... How to display IP of ssh user in message? ... - Have a warning banner enabled at log in. ... do a lastb and it logs it by, ...
    (RedHat)
  • Re: how to react on ssh attacks?
    ... > to view the logs. ... The huge amount of ssh probes that have been going on for the last year or ... enforced routine password changes and password selection rules since the ...
    (Fedora)
  • Re: [Full-disclosure] Distributed SSH username/password brute forceattack
    ... logs and killing this type of attack is to reconfigure your OpenSSH ... Although key-based logins are easier on your ... logs, they also generate the problem of transitive access to the server. ... Although you can control how the SSH server on your side works, ...
    (Full-Disclosure)
  • Re: Help -- Have I been rooted?
    ... I only allowed ssh, httpd, and ftp port forwarding to my ... machine for the past few days while I used a store bought router. ... I checked the router logs and was greeted by pages of stuff like this: ...
    (comp.os.linux.security)