POSSIBLE BREAKIN ATTEMPT in syslog

From: Justin Finkelstein (justin_at_redwiredesign.com)
Date: 10/25/04


Date: Mon, 25 Oct 2004 11:07:19 +0100

Hi kids

I get daily LogWatch messages from my servers and one of them came up with a
shedload of messages as follows:

reverse mapping checking getaddrinfo for db2.tallion.com failed - POSSIBLE
BREAKIN ATTEMPT!

I had about a hundred of these now; I think my server is secure, as it only
accepts Version 2 connections and doesn't accept password authentication.

Any suggestions as to what else I can do to lock this down and [if possible]
not have to see/worry about these messages?

Conveniently, there's no documentation on this on the openssh site nor any
mention of it except for bug reports in the mailing lists.

Any ideas?

j.