buckshotbarlow
12-02-2010, 09:24
So i run a unix server out of the house. Use comcast as my ISP. Watch out, kenyan's, chinese and tawainians are hitting your network. Make sure you have strong passwords and firewalls...
Here's a snippet from my firewall:
my deny list on the firewall after updates:
accesskenya.co 41.215.63.148
broad.km.yn.dyn 116.55.227.91
linode.com 173.255.236.188
leadfusion.com 216.151.185.129
218.64.215.239 218.64.215.239
This is from my syslog. Basically they just keep running attacks using usernames and default passwords. Make sure all your passwords have been changed to 10 character alpha numeric, and all your default passwords have been changed.
Dec 4 05:12:01 elnino sshd[13939]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:03 elnino sshd[13941]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:05 elnino sshd[13943]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:06 elnino sshd[13945]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:08 elnino sshd[13947]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:10 elnino sshd[13949]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:12 elnino sshd[13951]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:14 elnino sshd[13953]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:16 elnino sshd[13955]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:18 elnino sshd[13957]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:20 elnino sshd[13959]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:21 elnino sshd[13961]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:23 elnino sshd[13963]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:25 elnino sshd[13965]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:27 elnino sshd[13967]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:29 elnino sshd[13969]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:31 elnino sshd[13971]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 02:08:30 elnino sshd[20817]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:33 elnino sshd[20819]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:35 elnino sshd[20821]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:38 elnino sshd[20823]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:41 elnino sshd[20825]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:44 elnino sshd[20827]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:46 elnino sshd[20829]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:49 elnino sshd[20831]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:53 elnino sshd[20833]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:56 elnino sshd[20835]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:58 elnino sshd[20837]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:09:01 elnino sshd[20839]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:07 elnino sshd[20398]: Invalid user servicioalcliente from 41.215.63.148
Dec 4 02:01:08 elnino sshd[20402]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:11 elnino sshd[20404]: Invalid user serviciocliente from 41.215.63.148
Dec 4 02:01:11 elnino sshd[20406]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:14 elnino sshd[20408]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:17 elnino sshd[20410]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:18 elnino sshd[20411]: Invalid user servicio from 41.215.63.148
Dec 4 02:01:20 elnino sshd[20414]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:23 elnino sshd[20418]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:23 elnino sshd[20416]: Invalid user sales from 41.215.63.148
Dec 4 02:01:25 elnino sshd[20420]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:27 elnino sshd[20422]: Invalid user info from 41.215.63.148
Dec 4 02:01:28 elnino sshd[20424]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:30 elnino sshd[20426]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:33 elnino sshd[20428]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:35 elnino sshd[20430]: Invalid user ventas from 41.215.63.148
Dec 4 02:01:36 elnino sshd[20432]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:39 elnino sshd[20436]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:40 elnino sshd[20434]: Invalid user compras from 41.215.63.148
Dec 4 02:01:42 elnino sshd[20438]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:44 elnino sshd[20440]: Invalid user news from 41.215.63.148
Dec 4 02:01:45 elnino sshd[20442]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:47 elnino sshd[20445]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:48 elnino sshd[20444]: Invalid user repuestos from 41.215.63.148
Dec 4 02:01:50 elnino sshd[20448]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:52 elnino sshd[20450]: Invalid user postmast from 41.215.63.148
Dec 4 02:01:52 elnino sshd[20452]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:55 elnino sshd[20454]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:56 elnino sshd[20455]: Invalid user postmaster from 41.215.63.148
Dec 4 02:01:58 elnino sshd[20458]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:00 elnino sshd[20462]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:03 elnino sshd[20464]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:05 elnino sshd[20466]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:06 elnino sshd[20460]: Invalid user webmast from 41.215.63.148
Dec 4 02:02:08 elnino sshd[20468]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:10 elnino sshd[20470]: Invalid user webmaster from 41.215.63.148
Dec 4 02:02:11 elnino sshd[20472]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:13 elnino sshd[20474]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:17 elnino sshd[20477]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:17 elnino sshd[20476]: Invalid user almacen from 41.215.63.148
Dec 4 02:02:20 elnino sshd[20480]: User root from 116.55.227.91 not allowed b
Here's a snippet from my firewall:
my deny list on the firewall after updates:
accesskenya.co 41.215.63.148
broad.km.yn.dyn 116.55.227.91
linode.com 173.255.236.188
leadfusion.com 216.151.185.129
218.64.215.239 218.64.215.239
This is from my syslog. Basically they just keep running attacks using usernames and default passwords. Make sure all your passwords have been changed to 10 character alpha numeric, and all your default passwords have been changed.
Dec 4 05:12:01 elnino sshd[13939]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:03 elnino sshd[13941]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:05 elnino sshd[13943]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:06 elnino sshd[13945]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:08 elnino sshd[13947]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:10 elnino sshd[13949]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:12 elnino sshd[13951]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:14 elnino sshd[13953]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:16 elnino sshd[13955]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:18 elnino sshd[13957]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:20 elnino sshd[13959]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:21 elnino sshd[13961]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:23 elnino sshd[13963]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:25 elnino sshd[13965]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:27 elnino sshd[13967]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:29 elnino sshd[13969]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 05:12:31 elnino sshd[13971]: User root from 218.64.215.239 not allowed because listed in DenyUsers
Dec 4 02:08:30 elnino sshd[20817]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:33 elnino sshd[20819]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:35 elnino sshd[20821]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:38 elnino sshd[20823]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:41 elnino sshd[20825]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:44 elnino sshd[20827]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:46 elnino sshd[20829]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:49 elnino sshd[20831]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:53 elnino sshd[20833]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:56 elnino sshd[20835]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:08:58 elnino sshd[20837]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:09:01 elnino sshd[20839]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:07 elnino sshd[20398]: Invalid user servicioalcliente from 41.215.63.148
Dec 4 02:01:08 elnino sshd[20402]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:11 elnino sshd[20404]: Invalid user serviciocliente from 41.215.63.148
Dec 4 02:01:11 elnino sshd[20406]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:14 elnino sshd[20408]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:17 elnino sshd[20410]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:18 elnino sshd[20411]: Invalid user servicio from 41.215.63.148
Dec 4 02:01:20 elnino sshd[20414]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:23 elnino sshd[20418]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:23 elnino sshd[20416]: Invalid user sales from 41.215.63.148
Dec 4 02:01:25 elnino sshd[20420]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:27 elnino sshd[20422]: Invalid user info from 41.215.63.148
Dec 4 02:01:28 elnino sshd[20424]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:30 elnino sshd[20426]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:33 elnino sshd[20428]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:35 elnino sshd[20430]: Invalid user ventas from 41.215.63.148
Dec 4 02:01:36 elnino sshd[20432]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:39 elnino sshd[20436]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:40 elnino sshd[20434]: Invalid user compras from 41.215.63.148
Dec 4 02:01:42 elnino sshd[20438]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:44 elnino sshd[20440]: Invalid user news from 41.215.63.148
Dec 4 02:01:45 elnino sshd[20442]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:47 elnino sshd[20445]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:48 elnino sshd[20444]: Invalid user repuestos from 41.215.63.148
Dec 4 02:01:50 elnino sshd[20448]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:52 elnino sshd[20450]: Invalid user postmast from 41.215.63.148
Dec 4 02:01:52 elnino sshd[20452]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:55 elnino sshd[20454]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:01:56 elnino sshd[20455]: Invalid user postmaster from 41.215.63.148
Dec 4 02:01:58 elnino sshd[20458]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:00 elnino sshd[20462]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:03 elnino sshd[20464]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:05 elnino sshd[20466]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:06 elnino sshd[20460]: Invalid user webmast from 41.215.63.148
Dec 4 02:02:08 elnino sshd[20468]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:10 elnino sshd[20470]: Invalid user webmaster from 41.215.63.148
Dec 4 02:02:11 elnino sshd[20472]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:13 elnino sshd[20474]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:17 elnino sshd[20477]: User root from 116.55.227.91 not allowed because listed in DenyUsers
Dec 4 02:02:17 elnino sshd[20476]: Invalid user almacen from 41.215.63.148
Dec 4 02:02:20 elnino sshd[20480]: User root from 116.55.227.91 not allowed b