Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Oct 2005
    Posts
    15

    Thumbs up Urgent !!!!! Server Under Attack

    Hi, One of my webpage has been haked ........

    How i can deny access to one or more IP to my server ?

    this is a log:

    The remote system 193.202.89.64 was found to have exceeded acceptable login failures on your server; there was 204 events to the service sshd. As such the attacking host has been banned from further accessing this system. For the integrity of your host you should investigate this event as soon as possible.


    THIS IS OTHER LOG !!! :


    Security Violations
    =-=-=-=-=-=-=-=-=-=
    Apr 4 16:58:15 matrix1 sshd(pam_unix)[23289]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=217.156.103.134 user=root
    Apr 4 16:58:15 matrix1 sshd(pam_unix)[23288]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=217.156.103.134 user=root
    Apr 4 16:58:15 matrix1 sshd(pam_unix)[23290]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=217.156.103.134 user=root
    Apr 4 16:58:15 matrix1 sshd(pam_unix)[23286]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=217.156.103.134 user=root
    Apr 4 16:58:15 matrix1 sshd(pam_unix)[23285]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=217.156.103.134 user=root
    Apr 4 16:58:17 matrix1 kernel: audit(1144184297.923:7722084): user pid=23288 uid=0 auid=0 msg='PAM authentication: user=root exe="/usr/sbin/sshd" (hostname=217.156.103.134, addr=217.156.103.134, terminal=ssh result=Authentication failure)'
    Apr 4 16:58:17 matrix1 kernel: audit(1144184297.924:7722106): user pid=23290 uid=0 auid=0 msg='PAM authentication: user=root exe="/usr/sbin/sshd" (hostname=217.156.103.134, addr=217.156.103.134, terminal=ssh result=Authentication failure)'
    Apr 4 16:58:17 matrix1 kernel: audit(1144184297.934:7722166): user pid=23286 uid=0 auid=0 msg='PAM authentication: user=root exe="/usr/sbin/sshd" (hostname=217.156.103.134, addr=217.156.103.134, terminal=ssh result=Authentication failure)'
    Apr 4 16:58:17 matrix1 kernel: audit(1144184297.935:7722188): user pid=23285 uid=0 auid=0 msg='PAM authentication: user=root exe="/usr/sbin/sshd" (hostname=217.156.103.134, addr=217.156.103.134, terminal=ssh result=Authentication

    THIS IS OTHER LOG:

    The remote system 217.156.103.134 was found to have exceeded acceptable login failures on your server; there was 40 events to the service sshd. As such the attacking host has been banned from further accessing this system. For the integrity of your host you should investigate this event as soon as possible.

    PLEASE HELP !!!!!!!!!

  2. #2
    Member Murtaza_t's Avatar
    Join Date
    Jan 2005
    Location
    Earth
    Posts
    471

    Default

    run this command :
    Code:
    ]# iptables -A INPUT -s 217.156.103.134 -j DROP
    Code:
    ]# service iptables save
    this will parmanently block that IP.

    But the best would be install APF anf BFD to deal with these bad guys automatically.

    http://forums.cpanel.net/showthread.php?t=30159

  3. #3
    Member dave9000's Avatar
    Join Date
    Apr 2003
    Location
    arkansas
    Posts
    891
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    And to add to the above post

    change the ssh port from port 22 to a unused port

    This in itself will stop almost all of the login attempts
    Dave Browning
    Intersite Technologies
    Greenbrier Ar
    dave@isitetech.com

  4. #4
    Member
    Join Date
    Oct 2005
    Posts
    15

    Default

    Thanks Murtaza and Dave !!!

Similar Threads & Tags
Similar threads

  1. Urgent Formmail Attack
    By claudio in forum cPanel and WHM Discussions
    Replies: 12
    Last Post: 05-18-2008, 04:08 PM
  2. server under attack need to stop now
    By fishfreek in forum cPanel and WHM Discussions
    Replies: 15
    Last Post: 02-05-2008, 05:08 AM
  3. Server under Virus Attack - Please help it's URGENT !!!
    By checked in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 08-03-2004, 01:44 PM
  4. Server Attack, every day, help:(
    By x-man in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 07-16-2004, 02:47 PM
  5. My server under attack
    By Jackmaninov in forum cPanel and WHM Discussions
    Replies: 9
    Last Post: 04-04-2004, 04:43 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube