Toggle navigation
Koozali.org: home of the SME Server
Community
Forums
Bugs
Lists
Forum Help
Download
SME Server ISOs
Contribs
Documentation
Manual
Wiki
FAQ
HowTo
Donate
Search
Login
Register
Login
Register
×
Close
Login
Remember me
Koozali.org: home of the SME Server
Legacy Forums
General Discussion (Legacy)
Topic:
POSSIBLE BREAKIN ATTEMPT
« previous
next »
+
Print
Pages: [
1
]
Go Down
POSSIBLE BREAKIN ATTEMPT
4 Replies
1209 Views
Matt
63
+0/-0
POSSIBLE BREAKIN ATTEMPT
«
on:
August 18, 2004, 10:48:55 AM »
Help
I am quite new to e-smith and find these log files a bit confusing. I have just tried logging into the root account but my usual password does not work anymore so I checked the message log and found the following:
08:42:12 cranbrook sshd[20493]: reverse mapping checking getaddrinfo for 137-002.cbici.net failed - POSSIBLE BREAKIN ATTEMPT!
Aug 15 08:42:12 cranbrook sshd[20493]: Failed password for root from 192.217.137.2 port 1574 ssh2
Aug 15 08:42:13 cranbrook sshd[20495]: Illegal user test from 192.217.137.2
Aug 15 08:42:13 cranbrook sshd[20495]: reverse mapping checking getaddrinfo for 137-002.cbici.net failed - POSSIBLE BREAKIN ATTEMPT!
Aug 15 08:42:13 cranbrook sshd[20495]: Failed password for illegal user test from 192.217.137.2 port 1596 ssh2
Aug 15 08:42:47 cranbrook sshd[20497]: Accepted password for root from 194.102.145.11 port 1086
Aug 15 08:42:47 cranbrook sshd(pam_unix)[20499]: session opened for user root by root(uid=0)
Aug 15 08:46:52 cranbrook PAM_pwdb[20871]: password for (root/0) changed by ((null)/0)
I am guessing that someone has broken into my server and changed the root password. Could anyone enlighten me about the above messages. I guess there is nothing I can do but reinstall e-smith and use a more secure password and stop remote access.
[/quote]
Logged
raem
3,972
+4/-0
POSSIBLE BREAKIN ATTEMPT
«
Reply #1 on:
August 18, 2004, 03:44:29 PM »
Was your root passwword weak ?
Logged
...
Matt
63
+0/-0
POSSIBLE BREAKIN ATTEMPT
«
Reply #2 on:
August 18, 2004, 06:51:47 PM »
Yes it was a pretty weak password, only letters and an eas to guess word, my own fault, so has someone really got in a changed things?
Logged
raem
3,972
+4/-0
POSSIBLE BREAKIN ATTEMPT
«
Reply #3 on:
August 19, 2004, 07:32:57 AM »
> ......so has someone really got in a changed things?
You will need to review the logs to answer that question.
A search on
change root password
found this amongst many other posts. Learn to search
http://forums.contribs.org/index.php?topic=22842.0
Logged
...
byte
2,183
+2/-0
POSSIBLE BREAKIN ATTEMPT
«
Reply #4 on:
August 19, 2004, 09:20:33 AM »
Hi,
You might wish to run the rkhunter to see if they modified any files or dropped anything in.
Do a search you will find lots of info
HTH
Logged
--[byte]--
Have you filled in a Bug Report over @
http://bugs.contribs.org
? Please don't wait to be told this way you help us to help you/others - Thanks!
+
Print
Pages: [
1
]
Go Up
« previous
next »
Koozali.org: home of the SME Server
Legacy Forums
General Discussion (Legacy)
Topic:
POSSIBLE BREAKIN ATTEMPT