• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Brute-force login attack

bealzz

Gawd
Joined
Jun 4, 2003
Messages
545
I'm getting the following on one of my Linux servers;
Code:
Oct 30 11:49:52 nmc sshd[5628]: User root not allowed because not listed in AllowUsers
Oct 30 11:49:53 nmc sshd[5710]: reverse mapping checking getaddrinfo for server1.goldcities.net failed - POSSIBLE BREAKIN ATTEMPT!
Oct 30 11:49:53 nmc sshd[5710]: User root not allowed because not listed in AllowUsers
Oct 30 11:49:53 nmc sshd[5834]: reverse mapping checking getaddrinfo for server1.goldcities.net failed - POSSIBLE BREAKIN ATTEMPT!
Oct 30 11:49:53 nmc sshd[5834]: User root not allowed because not listed in AllowUsers
Oct 30 11:49:54 nmc sshd[5886]: reverse mapping checking getaddrinfo for server1.goldcities.net failed - POSSIBLE BREAKIN ATTEMPT!
Oct 30 11:49:54 nmc sshd[5886]: User root not allowed because not listed in AllowUsers
Oct 30 11:49:55 nmc sshd[5914]: reverse mapping checking getaddrinfo for server1.goldcities.net failed - POSSIBLE BREAKIN ATTEMPT!
Oct 30 11:49:55 nmc sshd[5914]: User root not allowed because not listed in AllowUsers
Oct 30 11:49:56 nmc sshd[5939]: reverse mapping checking getaddrinfo for server1.goldcities.net failed - POSSIBLE BREAKIN ATTEMPT!
Oct 30 11:49:56 nmc sshd[5939]: User root not allowed because not listed in AllowUsers

I've cut out about 20 pages but its still going. I want to block whoever is doing this, but because its a fake reverse map I can't figure out this guy's IP address to block it. Anyone have any ideas?

I did the following line on my IPTABLES;
iptables -I INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent --update --seconds 60 --hitcount 4 -
j DROP

But it didnt seem to do anything. Thanks!!
 
you might look at
Code:
netstat -ntp | grep sshd
might give you some help

Another option is to edit your sshd_config to use
Code:
UseDNS no
 
Back
Top