Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Page 1 of 3 1 2 3 LastLast
Results 1 to 15 of 36
  1. #1
    Member
    Join Date
    Feb 2004
    Location
    Chicago
    Posts
    196

    Default Server being hacked?

    Hi. In my LogWatch it shows this...

    --------------------- SSHD Begin ------------------------

    Failed logins from these:
    adm/password from ::ffff:211.248.38.252: 6 Time(s)
    admin/password from ::ffff:218.3.161.2: 11 Time(s)
    apache/password from ::ffff:211.248.38.252: 3 Time(s)
    cosmin/password from ::ffff:211.248.38.252: 3 Time(s)
    cyrus/password from ::ffff:211.248.38.252: 7 Time(s)
    guest/password from ::ffff:218.3.161.2: 8 Time(s)
    horde/password from ::ffff:211.248.38.252: 7 Time(s)
    iceuser/password from ::ffff:211.248.38.252: 8 Time(s)
    irc/password from ::ffff:211.248.38.252: 6 Time(s)
    jane/password from ::ffff:211.248.38.252: 3 Time(s)
    matt/password from ::ffff:211.248.38.252: 5 Time(s)
    mysql/password from ::ffff:211.248.38.252: 4 Time(s)
    nobody/password from ::ffff:211.248.38.252: 9 Time(s)
    operator/password from ::ffff:211.248.38.252: 3 Time(s)
    pamela/password from ::ffff:211.248.38.252: 3 Time(s)
    patrick/password from ::ffff:211.248.38.252: 16 Time(s)
    rolo/password from ::ffff:211.248.38.252: 8 Time(s)
    root/password from ::ffff:211.248.38.252: 120 Time(s)
    root/password from ::ffff:218.3.161.2: 11 Time(s)
    test/password from ::ffff:211.248.38.252: 16 Time(s)
    test/password from ::ffff:218.3.161.2: 11 Time(s)
    user/password from ::ffff:218.3.161.2: 4 Time(s)
    www-data/password from ::ffff:211.248.38.252: 4 Time(s)
    www/password from ::ffff:211.248.38.252: 7 Time(s)
    wwwrun/password from ::ffff:211.248.38.252: 6 Time(s)

    Illegal users from these:
    admin/none from ::ffff:218.3.161.2: 11 Time(s)
    admin/password from ::ffff:218.3.161.2: 11 Time(s)
    apache/none from ::ffff:211.248.38.252: 3 Time(s)
    apache/password from ::ffff:211.248.38.252: 3 Time(s)
    cosmin/none from ::ffff:211.248.38.252: 3 Time(s)
    cosmin/password from ::ffff:211.248.38.252: 3 Time(s)
    cyrus/none from ::ffff:211.248.38.252: 7 Time(s)
    cyrus/password from ::ffff:211.248.38.252: 7 Time(s)
    guest/none from ::ffff:218.3.161.2: 8 Time(s)
    guest/password from ::ffff:218.3.161.2: 8 Time(s)
    horde/none from ::ffff:211.248.38.252: 7 Time(s)
    horde/password from ::ffff:211.248.38.252: 7 Time(s)
    iceuser/none from ::ffff:211.248.38.252: 8 Time(s)
    iceuser/password from ::ffff:211.248.38.252: 8 Time(s)
    irc/none from ::ffff:211.248.38.252: 6 Time(s)
    irc/password from ::ffff:211.248.38.252: 6 Time(s)
    jane/none from ::ffff:211.248.38.252: 3 Time(s)
    jane/password from ::ffff:211.248.38.252: 3 Time(s)
    matt/none from ::ffff:211.248.38.252: 5 Time(s)
    matt/password from ::ffff:211.248.38.252: 5 Time(s)
    pamela/none from ::ffff:211.248.38.252: 3 Time(s)
    pamela/password from ::ffff:211.248.38.252: 3 Time(s)
    rolo/none from ::ffff:211.248.38.252: 8 Time(s)
    rolo/password from ::ffff:211.248.38.252: 8 Time(s)
    test/none from ::ffff:211.248.38.252: 16 Time(s)
    test/none from ::ffff:218.3.161.2: 11 Time(s)
    test/password from ::ffff:211.248.38.252: 16 Time(s)
    test/password from ::ffff:218.3.161.2: 11 Time(s)
    user/none from ::ffff:218.3.161.2: 4 Time(s)
    user/password from ::ffff:218.3.161.2: 4 Time(s)
    www-data/none from ::ffff:211.248.38.252: 4 Time(s)
    www-data/password from ::ffff:211.248.38.252: 4 Time(s)
    www/none from ::ffff:211.248.38.252: 7 Time(s)
    www/password from ::ffff:211.248.38.252: 7 Time(s)
    wwwrun/none from ::ffff:211.248.38.252: 6 Time(s)
    wwwrun/password from ::ffff:211.248.38.252: 6 Time(s)


    ---------------------- SSHD End -------------------------
    How can I block those ips from the box completely? Thanks.

  2. #2
    Member
    Join Date
    Jul 2004
    Posts
    108

    Default

    Brute Force Detection( bfd) from rfx networks

  3. #3
    Member
    Join Date
    Feb 2004
    Location
    Chicago
    Posts
    196

    Default

    Sounds good, and its free, but do I need a already in place firewall for it to work with? Or does it handle everything? Thanks.

  4. #4
    Member
    Join Date
    Oct 2003
    Posts
    1,020

    Default

    You need to run APF (available from the same site) in order to run BFD.

  5. #5
    Member
    Join Date
    Nov 2003
    Location
    England, UK
    Posts
    133

    Default

    I would run
    PHP Code:
    iptables -A INPUT -s 211.248.38.252 -j DROP 
    just to block the ip from any more attempts then go about with securing your server

  6. #6
    GOT
    GOT is offline
    Get Proactive! GOT's Avatar
    Join Date
    Apr 2003
    Posts
    898

    Default

    BFD has issues with the script that adds teh ffff in front of the IP. Has this been fixed?
    Proactive Server Monitoring and Management
    http://got-management.com

  7. #7
    Member
    Join Date
    Feb 2004
    Posts
    14

    Default

    easier add it to /etc/hosts.deny

    211.248.38.252:*


    Simpole yet effective.

  8. #8
    Member
    Join Date
    Feb 2004
    Location
    Chicago
    Posts
    196

    Default

    Quote Originally Posted by GotHosting
    BFD has issues with the script that adds teh ffff in front of the IP. Has this been fixed?
    Yes, has that been fixed?

  9. #9
    Moderator cPanel Partner NOC Badge dgbaker's Avatar
    Join Date
    Sep 2002
    Location
    Toronto, Ontario Canada
    Posts
    2,773

    Default

    Quote Originally Posted by GufyMike
    easier add it to /etc/hosts.deny

    211.248.38.252:*


    Simpole yet effective.
    Easier? Maybe.. Best solution? No.

    Why do things manually when they can be automated and taken care of immediately? BFD takes care of the issue as it is happening, not when some sysadmin finds and gets around to it.
    Regards,
    David
    Forum Moderator

  10. #10
    Member
    Join Date
    Aug 2004
    Posts
    84

    Default

    my server is also attacang I try this do :
    root@host [~]# iptables -A INPUT -s 70.240.3.138 -j DROP
    bash: iptables: command not found

  11. #11
    Member
    Join Date
    Mar 2004
    Location
    This Planet
    Posts
    984

    Default

    Run following commands from ssh and paste the output.

    lsmod
    ie Determine the loaded modules

    modinfo ip_tables
    ie Determine if the iptables kernel module is installed on your system

    rpm -q iptables
    ie Determine if the iptables user-space package is installed on your system



    Anup
    Last edited by anup123; 10-11-2004 at 01:53 AM.

  12. #12
    Member
    Join Date
    Feb 2004
    Location
    Chicago
    Posts
    196

    Default

    Quote Originally Posted by anup123
    Run following commands from ssh and paste the output.

    lsmod
    ie Determine the loaded modules

    modinfo ip_tables
    ie Determine if the iptables kernel module is installed on your system

    rpm -q iptables
    ie Determine if the iptables user-space package is installed on your system



    Anup

    root@xeon1 [~]# lsmod
    Module Size Used by
    ipt_owner 7745 0
    ipt_REJECT 8897 0
    iptable_filter 6209 1
    ip_tables 18497 3 ipt_owner,ipt_REJECT,iptable_filter
    md5 7745 1
    ipv6 233701 28
    tg3 79045 0
    sg 33377 0
    scsi_mod 102025 1 sg
    microcode 10209 0
    dm_mod 49477 0
    ohci_hcd 22097 0
    button 8793 0
    battery 11085 0
    asus_acpi 13017 0
    ac 7373 0
    ext3 99497 4
    jbd 58457 1 ext3
    root@xeon1 [~]#

    root@xeon1 [~]# modinfo ip_tables
    license: GPL
    author: Netfilter Core Team <coreteam@netfilter.org>
    description: IPv4 packet filter
    vermagic: 2.6.8-1.521smp SMP 686 REGPARM 4KSTACKS gcc-3.3
    depends:
    root@xeon1 [~]#

    root@xeon1 [~]# rpm -q iptables
    iptables-1.2.9-2.3.1
    root@xeon1 [~]#

  13. #13
    Member
    Join Date
    Oct 2003
    Posts
    1,020

    Default

    Quote Originally Posted by preleaf
    my server is also attacang I try this do :
    root@host [~]# iptables -A INPUT -s 70.240.3.138 -j DROP
    bash: iptables: command not found
    What OS are you running?

    Try running using the full path to iptables or using 'su -' when su'ing to root.

  14. #14
    Member
    Join Date
    Mar 2004
    Location
    This Planet
    Posts
    984

    Default

    ThaMATRiX : I think you should be able to use iptables command. check with iptables -L

    Actually that was for preleaf who was having error running that command and SarcNBit has already replied to the same. It's either iptables not being in path or not being there at all. SarcNBit suggestion would reveal furter details.

    Anup

  15. #15
    Member
    Join Date
    Feb 2004
    Location
    Chicago
    Posts
    196

    Default

    Its Fedora Core 2

Similar Threads & Tags
Similar threads

  1. my server is hacked
    By jcaldera in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 05-02-2009, 04:23 PM
  2. server has been hacked
    By aracrew in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 01-21-2008, 06:55 PM
  3. Server get hacked
    By vishwas in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 12-02-2005, 04:49 AM
  4. my server got hacked?
    By goodgbb in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 08-25-2005, 10:18 AM
  5. new server got hacked
    By brumie in forum cPanel and WHM Discussions
    Replies: 24
    Last Post: 04-29-2004, 01:00 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube