#1 (permalink)  
Old 10-07-2004, 10:38 PM
Registered User
 
Join Date: Feb 2004
Location: Chicago
Posts: 196
ThaMATRiX
Server being hacked?

Hi. In my LogWatch it shows this...

Quote:
--------------------- SSHD Begin ------------------------

Failed logins from these:
adm/password from ::ffff:211.248.38.252: 6 Time(s)
admin/password from ::ffff:218.3.161.2: 11 Time(s)
apache/password from ::ffff:211.248.38.252: 3 Time(s)
cosmin/password from ::ffff:211.248.38.252: 3 Time(s)
cyrus/password from ::ffff:211.248.38.252: 7 Time(s)
guest/password from ::ffff:218.3.161.2: 8 Time(s)
horde/password from ::ffff:211.248.38.252: 7 Time(s)
iceuser/password from ::ffff:211.248.38.252: 8 Time(s)
irc/password from ::ffff:211.248.38.252: 6 Time(s)
jane/password from ::ffff:211.248.38.252: 3 Time(s)
matt/password from ::ffff:211.248.38.252: 5 Time(s)
mysql/password from ::ffff:211.248.38.252: 4 Time(s)
nobody/password from ::ffff:211.248.38.252: 9 Time(s)
operator/password from ::ffff:211.248.38.252: 3 Time(s)
pamela/password from ::ffff:211.248.38.252: 3 Time(s)
patrick/password from ::ffff:211.248.38.252: 16 Time(s)
rolo/password from ::ffff:211.248.38.252: 8 Time(s)
root/password from ::ffff:211.248.38.252: 120 Time(s)
root/password from ::ffff:218.3.161.2: 11 Time(s)
test/password from ::ffff:211.248.38.252: 16 Time(s)
test/password from ::ffff:218.3.161.2: 11 Time(s)
user/password from ::ffff:218.3.161.2: 4 Time(s)
www-data/password from ::ffff:211.248.38.252: 4 Time(s)
www/password from ::ffff:211.248.38.252: 7 Time(s)
wwwrun/password from ::ffff:211.248.38.252: 6 Time(s)

Illegal users from these:
admin/none from ::ffff:218.3.161.2: 11 Time(s)
admin/password from ::ffff:218.3.161.2: 11 Time(s)
apache/none from ::ffff:211.248.38.252: 3 Time(s)
apache/password from ::ffff:211.248.38.252: 3 Time(s)
cosmin/none from ::ffff:211.248.38.252: 3 Time(s)
cosmin/password from ::ffff:211.248.38.252: 3 Time(s)
cyrus/none from ::ffff:211.248.38.252: 7 Time(s)
cyrus/password from ::ffff:211.248.38.252: 7 Time(s)
guest/none from ::ffff:218.3.161.2: 8 Time(s)
guest/password from ::ffff:218.3.161.2: 8 Time(s)
horde/none from ::ffff:211.248.38.252: 7 Time(s)
horde/password from ::ffff:211.248.38.252: 7 Time(s)
iceuser/none from ::ffff:211.248.38.252: 8 Time(s)
iceuser/password from ::ffff:211.248.38.252: 8 Time(s)
irc/none from ::ffff:211.248.38.252: 6 Time(s)
irc/password from ::ffff:211.248.38.252: 6 Time(s)
jane/none from ::ffff:211.248.38.252: 3 Time(s)
jane/password from ::ffff:211.248.38.252: 3 Time(s)
matt/none from ::ffff:211.248.38.252: 5 Time(s)
matt/password from ::ffff:211.248.38.252: 5 Time(s)
pamela/none from ::ffff:211.248.38.252: 3 Time(s)
pamela/password from ::ffff:211.248.38.252: 3 Time(s)
rolo/none from ::ffff:211.248.38.252: 8 Time(s)
rolo/password from ::ffff:211.248.38.252: 8 Time(s)
test/none from ::ffff:211.248.38.252: 16 Time(s)
test/none from ::ffff:218.3.161.2: 11 Time(s)
test/password from ::ffff:211.248.38.252: 16 Time(s)
test/password from ::ffff:218.3.161.2: 11 Time(s)
user/none from ::ffff:218.3.161.2: 4 Time(s)
user/password from ::ffff:218.3.161.2: 4 Time(s)
www-data/none from ::ffff:211.248.38.252: 4 Time(s)
www-data/password from ::ffff:211.248.38.252: 4 Time(s)
www/none from ::ffff:211.248.38.252: 7 Time(s)
www/password from ::ffff:211.248.38.252: 7 Time(s)
wwwrun/none from ::ffff:211.248.38.252: 6 Time(s)
wwwrun/password from ::ffff:211.248.38.252: 6 Time(s)


---------------------- SSHD End -------------------------
How can I block those ips from the box completely? Thanks.
__________________
Paul B
President/CEO
OneReseller.net Webhosting Services
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 10-07-2004, 11:02 PM
Registered User
 
Join Date: Jul 2004
Posts: 108
cguimont is an unknown quantity at this point
Brute Force Detection( bfd) from rfx networks
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 10-07-2004, 11:14 PM
Registered User
 
Join Date: Feb 2004
Location: Chicago
Posts: 196
ThaMATRiX
Sounds good, and its free, but do I need a already in place firewall for it to work with? Or does it handle everything? Thanks.
__________________
Paul B
President/CEO
OneReseller.net Webhosting Services
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 10-07-2004, 11:17 PM
Registered User
 
Join Date: Oct 2003
Posts: 1,020
SarcNBit is on a distinguished road
You need to run APF (available from the same site) in order to run BFD.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 10-08-2004, 07:32 PM
Registered User
 
Join Date: Nov 2003
Location: England, UK
Posts: 133
bullethost696 is an unknown quantity at this point
I would run
PHP Code:
iptables -A INPUT -s 211.248.38.252 -j DROP 
just to block the ip from any more attempts then go about with securing your server
__________________
Chris Smith - My Cheap cPanel hosting reviews
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 10-08-2004, 07:47 PM
GOT's Avatar
GOT GOT is offline
Get Proactive!
 
Join Date: Apr 2003
Posts: 882
GOT is on a distinguished road
BFD has issues with the script that adds teh ffff in front of the IP. Has this been fixed?
__________________
Proactive Server Monitoring and Management
http://got-management.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 10-09-2004, 03:36 AM
Registered User
 
Join Date: Feb 2004
Posts: 14
GufyMike
easier add it to /etc/hosts.deny

211.248.38.252:*


Simpole yet effective.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 10-09-2004, 09:21 AM
Registered User
 
Join Date: Feb 2004
Location: Chicago
Posts: 196
ThaMATRiX
Quote:
Originally Posted by GotHosting
BFD has issues with the script that adds teh ffff in front of the IP. Has this been fixed?
Yes, has that been fixed?
__________________
Paul B
President/CEO
OneReseller.net Webhosting Services
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 10-09-2004, 10:13 AM
dgbaker's Avatar
Moderator
Advanced cPanel/WHM User
 
Join Date: Sep 2002
Location: Toronto, Ontario Canada
Posts: 2,768
dgbaker is on a distinguished road
Quote:
Originally Posted by GufyMike
easier add it to /etc/hosts.deny

211.248.38.252:*


Simpole yet effective.
Easier? Maybe.. Best solution? No.

Why do things manually when they can be automated and taken care of immediately? BFD takes care of the issue as it is happening, not when some sysadmin finds and gets around to it.
__________________
Regards,
David
Forum Moderator

Alternate Support? http://www.cpanelhosts.com
Looking for a server? http://www.myvirtualhosting.com
Get Dedicated in Toronto at MVH.
We are a licensed cPanel PartnerNoc
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 10-11-2004, 12:35 AM
Registered User
 
Join Date: Aug 2004
Posts: 84
preleaf is on a distinguished road
my server is also attacang I try this do :
root@host [~]# iptables -A INPUT -s 70.240.3.138 -j DROP
bash: iptables: command not found
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #11 (permalink)  
Old 10-11-2004, 01:13 AM
Registered User
 
Join Date: Mar 2004
Location: This Planet
Posts: 984
anup123 is on a distinguished road
Run following commands from ssh and paste the output.

lsmod
ie Determine the loaded modules

modinfo ip_tables
ie Determine if the iptables kernel module is installed on your system

rpm -q iptables
ie Determine if the iptables user-space package is installed on your system



Anup

Last edited by anup123; 10-11-2004 at 01:53 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #12 (permalink)  
Old 10-11-2004, 10:48 AM
Registered User
 
Join Date: Feb 2004
Location: Chicago
Posts: 196
ThaMATRiX
Quote:
Originally Posted by anup123
Run following commands from ssh and paste the output.

lsmod
ie Determine the loaded modules

modinfo ip_tables
ie Determine if the iptables kernel module is installed on your system

rpm -q iptables
ie Determine if the iptables user-space package is installed on your system



Anup

root@xeon1 [~]# lsmod
Module Size Used by
ipt_owner 7745 0
ipt_REJECT 8897 0
iptable_filter 6209 1
ip_tables 18497 3 ipt_owner,ipt_REJECT,iptable_filter
md5 7745 1
ipv6 233701 28
tg3 79045 0
sg 33377 0
scsi_mod 102025 1 sg
microcode 10209 0
dm_mod 49477 0
ohci_hcd 22097 0
button 8793 0
battery 11085 0
asus_acpi 13017 0
ac 7373 0
ext3 99497 4
jbd 58457 1 ext3
root@xeon1 [~]#

root@xeon1 [~]# modinfo ip_tables
license: GPL
author: Netfilter Core Team <coreteam@netfilter.org>
description: IPv4 packet filter
vermagic: 2.6.8-1.521smp SMP 686 REGPARM 4KSTACKS gcc-3.3
depends:
root@xeon1 [~]#

root@xeon1 [~]# rpm -q iptables
iptables-1.2.9-2.3.1
root@xeon1 [~]#
__________________
Paul B
President/CEO
OneReseller.net Webhosting Services
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #13 (permalink)  
Old 10-11-2004, 12:20 PM
Registered User
 
Join Date: Oct 2003
Posts: 1,020
SarcNBit is on a distinguished road
Quote:
Originally Posted by preleaf
my server is also attacang I try this do :
root@host [~]# iptables -A INPUT -s 70.240.3.138 -j DROP
bash: iptables: command not found
What OS are you running?

Try running using the full path to iptables or using 'su -' when su'ing to root.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #14 (permalink)  
Old 10-11-2004, 12:48 PM
Registered User
 
Join Date: Mar 2004
Location: This Planet
Posts: 984
anup123 is on a distinguished road
ThaMATRiX : I think you should be able to use iptables command. check with iptables -L

Actually that was for preleaf who was having error running that command and SarcNBit has already replied to the same. It's either iptables not being in path or not being there at all. SarcNBit suggestion would reveal furter details.

Anup
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #15 (permalink)  
Old 10-11-2004, 02:21 PM
Registered User
 
Join Date: Feb 2004
Location: Chicago
Posts: 196
ThaMATRiX
Its Fedora Core 2
__________________
Paul B
President/CEO
OneReseller.net Webhosting Services
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 11:30 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© cPanel Inc