Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Oct 2005
    Posts
    14

    Default Logwatch report

    Hello I received a log watch report this morning and found all these entries from the same ip , can anyone explain what it is please :

    **Unmatched Entries**
    Invalid user rfmngr from ::ffff:200.248.97.3
    input_userauth_request: invalid user rfmngr
    Failed password for invalid user rfmngr from ::ffff:200.248.97.3 port 37946 ssh2
    Invalid user sales from ::ffff:200.248.97.3
    input_userauth_request: invalid user sales
    Failed password for invalid user sales from ::ffff:200.248.97.3 port 38069 ssh2
    Invalid user recruit from ::ffff:200.248.97.3
    input_userauth_request: invalid user recruit
    Failed password for invalid user recruit from ::ffff:200.248.97.3 port 38185 ssh2
    Invalid user alias from ::ffff:200.248.97.3
    input_userauth_request: invalid user alias


    Plus a lot more

    Kind regards
    Dave

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Oct 2003
    Posts
    1,931

    Default

    that IP is brute forcing SSH

    best to move your ssh port to a higher unused port and use some brute force detection
    Last edited by dalem; 03-17-2008 at 07:16 AM.
    Lowest Host/Empire Technology LLC
    Affordable hosting solutions http://empire-hosting.net
    List Your hosting site FREE in http://hostgeneration.com

  3. #3
    Member
    Join Date
    Oct 2005
    Posts
    14

    Default

    Thankyou for the quick reply , I am new to this could you explain in detail how I can do that please

  4. #4
    Registered User
    Join Date
    Oct 2006
    Posts
    3

    Default I also got this attack

    I also got hundreds of this today:

    Invalid user www from ::ffff:84.244.161.38
    input_userauth_request: invalid user www
    Invalid user www from ::ffff:84.244.161.38
    input_userauth_request: invalid user www
    Invalid user www from ::ffff:84.244.161.38
    input_userauth_request: invalid user www
    Failed password for invalid user www from ::ffff:84.244.161.38 port 4136 ssh2
    Failed password for invalid user www from ::ffff:84.244.161.38 port 3065 ssh2
    Failed password for invalid user www from ::ffff:84.244.161.38 port 3852 ssh2

Similar Threads & Tags
Similar threads

  1. LogWatch for ******.****.***.**
    By FeeL in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 07-07-2009, 11:24 AM
  2. Logwatch - Remove Parts of Report
    By nurseryboy in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 03-28-2005, 12:03 PM
  3. need some advice with logwatch error report
    By GuiPos in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 05-19-2004, 09:51 AM
  4. Logwatch Report - something out of the norm
    By nappa in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 03-30-2004, 03:17 AM
  5. LogWatch. What does this mean?
    By skymedia in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 11-11-2003, 07:47 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube