Add to Favorites     Get Paid to Participate     Twitter     Facebook     Google+
Hosting Discussion
 

forgot password?


Reply


Old
  Post #1 (permalink)   11-30-2008, 06:03 AM
HD Addict
 
mfwl's Avatar
 
Join Date: Sep 2008
Posts: 144

Status: mfwl is offline
We have had the logs through on several occasions from cPanel (logwatch) that tells us we have over 2000 'Unknown' failed logins.

Is someone attempting to hack our server? I shall post the worrying part of that email below and see if anyone here can let us know what to do about it or if we are worrying about nothing?

Regards

Matt

--------------------- SSHD Begin ------------------------


Failed logins from:
60.220.218.88: 2750 times
203.114.112.99 (203-114-112-99.totisp.net): 32 times

Illegal users from:
60.220.218.88: 6470 times


Received disconnect:
11: Bye Bye : 9252 Time(s)

**Unmatched Entries**
pam_succeed_if(sshd:auth): error retrieving information about user subhadeep : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user danna : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user dchakrabarti : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user space : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user diablo : 12 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user boris : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user paradise : 11 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user webmaster : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user cmcoperator : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user craig : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user usr : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user sacvishal : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user magdalena : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user 123 : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user jyotprasaddeka : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user ihqmoddnom : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user hom : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user simbol : 10 time(s)


Cont.
__________________
Online Hosting and Webdesign solutions with a reliability and price you will like..
Shared / Reseller / Master Reseller Accounts / Web Design / Licensing
[color="Blue"]www.ACE4SPACE.com
 
 
 


Old
  Post #2 (permalink)   11-30-2008, 06:04 AM
HD Addict
 
mfwl's Avatar
 
Join Date: Sep 2008
Posts: 144

Status: mfwl is offline
Cont.

......................blah blah blah..

pam_succeed_if(sshd:auth): error retrieving information about user account : 150 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user invitado : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user sitymoon : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user ls : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user drcababu : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user pt : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user hrhatwar : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user fong : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user susanty : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user baluchandran : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user benliu : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user Terminator : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user oscar : 20 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user doolph : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user xl : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user wirote : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user discovery : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user syamsankar : 20 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user lol : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user master : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user gomsluft : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user office : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user abcd : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user logic : 12 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user yearaj : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user abril : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user install : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user gwaliormet : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user suprin : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user kcc : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user download : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user vkdadhwal : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user spam : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user blmadhavan : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user porno : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user karmegam : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user word : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user dwi : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user bill : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user ray : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user sample : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user ripals : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user pink : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user joao : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user megamax : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user jvsubbarao : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user abby : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user selva : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user elaine : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user sasha : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user rameshkumar : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user tarendra : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user flo : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user de : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user rajasekharmeka : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user sumitkumar : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user erin : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user helen : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user vkgarg : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user rksarangi : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user denis : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user radhika : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user venice : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user yakuza : 10 time(s)
pam_succeed_if(sshd:auth): error retrieving information about user manager01 : 20 time(s)

---------------------- SSHD End -------------------------

I left out over 2/3 of the entries!
__________________
Online Hosting and Webdesign solutions with a reliability and price you will like..
Shared / Reseller / Master Reseller Accounts / Web Design / Licensing
[color="Blue"]www.ACE4SPACE.com
 
 
 


Old
  Post #3 (permalink)   11-30-2008, 07:31 AM
HD Addict
 
mfwl's Avatar
 
Join Date: Sep 2008
Posts: 144

Status: mfwl is offline
I would still like an explaination of the above however we have taken the following action:

http://www.ace4space.com/clients/ann...wnews&newsid=1

Hope this helps anyone with the same problem when using cPanel/WHM
__________________
Online Hosting and Webdesign solutions with a reliability and price you will like..
Shared / Reseller / Master Reseller Accounts / Web Design / Licensing
[color="Blue"]www.ACE4SPACE.com
 
 
 


Old
  Post #4 (permalink)   11-30-2008, 09:00 PM
HD Wizard
 
romes's Avatar
 
Join Date: Feb 2007
Location: IL
Posts: 1,398
Send a message via MSN to romes

Status: romes is offline
Looks like someone wants to get in bad. Got ne enemies?
__________________
RomesBlog.net | Xbox 360 Gaming Articles, Add-ons, New Releases and Much More!
GMNetworks | Quality Service | Quality Support | Friendly Staff | Much More!
 
 
 


Old
  Post #5 (permalink)   12-01-2008, 12:57 AM
HD Amateur
 
Join Date: Oct 2008
Posts: 66

Status: hzSari is offline
It does seem like someone is bruteforcing to the server, if you have BFD installed, it should have tried to block the ip. In case you can get hold of the ip in this case, may be you should add the same to your firewall to block.
__________________
hzSari | HostingZoom.com
ModVPS.com | ResellerZoom.com
Power Speed Reliability
 
 
 


Old
  Post #6 (permalink)   12-01-2008, 02:03 AM
HD Addict
 
mfwl's Avatar
 
Join Date: Sep 2008
Posts: 144

Status: mfwl is offline
Quote:
Originally Posted by hzSari View Post
It does seem like someone is bruteforcing to the server, if you have BFD installed, it should have tried to block the ip. In case you can get hold of the ip in this case, may be you should add the same to your firewall to block.
I have added the IP it is in china!

I have also created authentication keys for ssh and removed the password option!

Low and behold today the logwatch states a reduction in attempts with all attempts by the said IP being failed!

NICE! I wish people hacking like this would just crawl away somewhere quiet and die!
__________________
Online Hosting and Webdesign solutions with a reliability and price you will like..
Shared / Reseller / Master Reseller Accounts / Web Design / Licensing
[color="Blue"]www.ACE4SPACE.com
 
 
 


Old
  Post #7 (permalink)   12-04-2008, 12:46 AM
HD Amateur
 
Join Date: Oct 2008
Posts: 66

Status: hzSari is offline
Glad to know you sorted it out, Matt.
__________________
hzSari | HostingZoom.com
ModVPS.com | ResellerZoom.com
Power Speed Reliability
 
 
 


Old
  Post #8 (permalink)   12-04-2008, 03:40 AM
HD Addict
 
mfwl's Avatar
 
Join Date: Sep 2008
Posts: 144

Status: mfwl is offline
So am I - hope this advice helps someone else!

Regards
__________________
Online Hosting and Webdesign solutions with a reliability and price you will like..
Shared / Reseller / Master Reseller Accounts / Web Design / Licensing
[color="Blue"]www.ACE4SPACE.com
 
 
 


Old
  Post #9 (permalink)   12-08-2008, 02:07 PM
HD Addict
 
LaneHost's Avatar
 
Join Date: Mar 2007
Location: Houston, TX
Posts: 153

Status: LaneHost is offline
Good thing to hear you are on top of it!

Hacking attempts are sadly becoming common and these threads are always a good reminder to keep a close eye on your servers. A server is only secure at it's weakest link.
__________________
LaneHost Solutions, Inc. | Professional Web Hosting Solutions
Affordable Shared Hosting, Reseller Hosting & Dedicated Servers at Great Prices!
Complete Solution To Affordable Reseller Web Hosting

Follow us on Twitter! | The LaneHost Blog | LaneHost Forums
 
 
 


Old
  Post #10 (permalink)   12-12-2008, 01:16 PM
VPS Wizard
 
Digitallinx's Avatar
 
Join Date: Sep 2008
Posts: 55
Send a message via AIM to Digitallinx Send a message via MSN to Digitallinx

Status: Digitallinx is offline
You might want to consider using a different port for sshd by editing /etc/init.d/sshd_config Port variable.
__________________
VPS Hosting
VPS Affiliate Program 110% Commission
New VPS reseller program available
The opinions expressed on this site are my own and do not necessarily represent those of my employer
 
 
 


Old
  Post #11 (permalink)   12-14-2008, 12:33 PM
HD Community Advisor
 
handsonhosting's Avatar
 
Join Date: Mar 2005
Location: Omaha, NE
Posts: 1,853

Status: handsonhosting is online now
If you're using WHM and cPanel, load up CSF rather than APF and BFD - it's a MUCH better program!

As for the logs, it looks like someone is trying to hit your site hard, however the bigger concern is the usernames in that list, are they the usernames from your server? If so, how did they get a complete list of your users on the server? Would seem like your passwd file or group file has been exposed somewhere.
 
 
 


Old
  Post #12 (permalink)   12-14-2008, 09:29 PM
HD Addict
 
mfwl's Avatar
 
Join Date: Sep 2008
Posts: 144

Status: mfwl is offline
Quote:
Originally Posted by handsonhosting View Post
If you're using WHM and cPanel, load up CSF rather than APF and BFD - it's a MUCH better program!

As for the logs, it looks like someone is trying to hit your site hard, however the bigger concern is the usernames in that list, are they the usernames from your server? If so, how did they get a complete list of your users on the server? Would seem like your passwd file or group file has been exposed somewhere.
No it was a form of brute force I dont have any of those users on my server - they are random names ...
__________________
Online Hosting and Webdesign solutions with a reliability and price you will like..
Shared / Reseller / Master Reseller Accounts / Web Design / Licensing
[color="Blue"]www.ACE4SPACE.com
 
 
 


Old
  Post #13 (permalink)   12-14-2008, 10:51 PM
HD Community Advisor
 
handsonhosting's Avatar
 
Join Date: Mar 2005
Location: Omaha, NE
Posts: 1,853

Status: handsonhosting is online now
Well at least that's some good out of the deal.
 
 
 


Old
  Post #14 (permalink)   12-16-2008, 07:51 AM
HD Addict
 
Join Date: Dec 2008
Location: Florida,Tampa
Posts: 101
Send a message via MSN to HivelocityLB

Status: HivelocityLB is offline
Glad to know this issue has been ironed out.
__________________
Dedicated Servers - sales@hivelocity.net - 1-888-869-HOST(4678)
Viva Hivelocity "THE SERVER STUD" - Award Winning Hosting
Managed Dedicated Servers. Reseller Discounts. 24/7 Impressive Tech Support.
 
 
 


Old
  Post #15 (permalink)   12-19-2008, 04:21 AM
HD Addict
 
mfwl's Avatar
 
Join Date: Sep 2008
Posts: 144

Status: mfwl is offline
Is there a way of protecting POP3 from being brute forced? It seems that now SSH is locked down they are attempting to bruteforce the POP3 logins with random users@ace4space.com
__________________
Online Hosting and Webdesign solutions with a reliability and price you will like..
Shared / Reseller / Master Reseller Accounts / Web Design / Licensing
[color="Blue"]www.ACE4SPACE.com
 
 
 
Reply
Previous Thread Next Thread


Thread Tools

New Post New Post   Old Post Old Post
Posting Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Sponsored By: