catching a hacker?

RobertW_at_danjonengineering.com
Date: 02/25/05


Date: Thu, 24 Feb 2005 15:31:02 -0800

I am looking through my Security Event Logs in SBS2000, and I am seeing
groups of "Failure Audit" lines. As I am looking through them, I notice that
the attempts are being made from a network connection (from where I don't
know). The hacker is trying user names like "windows", "crack", "cracker",
etc. so I know he's an idiot, but my question is how can I catch the little
F*@(er in the act? And how can I get his IP Address? I do keep logs on all
of this, I also keep logs on all of my SMTP, W3SCV, and MSFTP services. Is
there a way to cross reference this sort of information?

Thanks, Rob



Relevant Pages

  • Re: Online Shared Observation Logs???
    ... Sort of like a astronomy blog of logs? ... There are almost certainly some offline observation logging tools around that will generate some html for you to upload to a website, ...
    (sci.astro)
  • RE: Unusual port scan?
    ... are you able to tell us via your logs what sort of timing there was between ... does the log dump shown here show all of the instances of this port ... being hit by this intruder? ... I am thinking this might be some sort of DOS or attempted DOS attack on your ...
    (Incidents)
  • Re: Pam access.conf and host access
    ... was only used as a sort of wildcard. ... > restricting ssh access to a box using the following for my ... > When I try to ssh in from that IP, I get the following in the logs. ...
    (Focus-Linux)
  • Re: BSDstats Project v2.0 ...
    ... the logs will be set to /dev/null ... ... setup bsdstats.org as a more 'neutral' site ... ... emails to the NetBSD, OpenBSD *and* DragonFlyBSD camps, and the only one that answered back with any sort of interest was the DF-BSD camp, and I have some mods to add to v3.0 to satisfy Matt's requirements to have it actually put into their base operating system ... ... he just wants some sort of 'connectivity check' put in place .... ...
    (freebsd-questions)
  • Re: FREE SYSADMIN SEARCH TOOL
    ... Splunk does not throw your logs into one file, ... Some logs are placed in databases or in some sort of archives. ... The log entry wich do care are saved in a email format. ...
    (linux.redhat)