John wrote:
On Thursday 29 July 2004 21:16, C Hamel wrote:
I have never before seen this. I have the firewall engaged. Not certain what ot make of it. All I know is that my internet connection went down the last two times of the three this happened , and has been a little flakey all day long. ==== Jul 29 05:30:53 linux sshd[6054]: Illegal user test from 163.19.207.248 Jul 29 05:30:53 linux sshd[6054]: input_userauth_request: illegal user test Jul 29 05:30:53 linux sshd[6054]: Failed password for illegal user test from 163.19.207.248 port 55657 ssh2 Jul 29 05:30:53 linux sshd[6054]: Received disconnect from 163.19.207.248: 11: Bye Bye Jul 29 05:30:59 linux sshd[6055]: Illegal user guest from 163.19.207.248 Jul 29 05:30:59 linux sshd[6055]: input_userauth_request: illegal user guest Jul 29 05:30:59 linux sshd[6055]: Failed password for illegal user guest from 163.19.207.248 port 55662 ssh2 Jul 29 05:31:00 linux sshd[6055]: Received disconnect from 163.19.207.248: 11: Bye Bye
Along with what everyone else is saying, remember too, I believe I read somewhere that there is or is going to be some kind of attack on SSH ports(?) (wish I could remember where I read it, sorry)
Don't feel lonely ... or special. If it's hitting this little box, it's most likely an automated attempt. Jul 29 20:02:03 server sshd[28496]: Illegal user test from ::ffff:66.37.140.11 Jul 29 20:02:03 server sshd[28496]: reverse mapping checking getaddrinfo for host11.unused.colo.firstlink.com failed - POSSIBLE BREAKIN ATTEMPT! Jul 29 20:02:04 server sshd[28498]: Illegal user guest from ::ffff:66.37.140.11 Jul 29 20:02:04 server sshd[28498]: reverse mapping checking getaddrinfo for host11.unused.colo.firstlink.com failed - POSSIBLE BREAKIN ATTEMPT! Louis