[TriLUG] Getting, um, probed?
Mark Fowle
mark at thefowles.com
Wed Aug 4 20:48:41 EDT 2004
I've seen a lot of these entries over the last few weeks - usually
starts around 5pm and runs until 1 or 2am -- looks like a probe. I don't
have that range
open so I'm not too worried -- unless some one tells me I should be?
Thanks,
Mark
Brian Henning wrote:
>Hi Y'all,
> I've been seeing a lot of the following in my logwatch lately:
>
>input_userauth_request: illegal user test
>input_userauth_request: illegal user test
>Failed password for illegal user test from 210.205.6.157 port 51389 ssh2
>Failed password for illegal user test from 210.205.6.157 port 51470 ssh2
>Received disconnect from 210.205.6.157: 11: Bye Bye
>Received disconnect from 210.205.6.157: 11: Bye Bye
>
>The source IP will differ from day to day, so I can't just block that
>particular IP at the firewall.. Anyone else getting a lot of this sort of
>breakin-attempt lately? Should I be concerned?
>
>Cheers,
>~Brian
>
>
>
More information about the TriLUG
mailing list