Quantcast

Forums | MacLife

You are not logged in.

#1 2009-02-28 7:18 am

Fatum
Member
Registered: 2004-06-04
Posts: 117

Hacking attempted???

I have a server running from my desktop on 10.5.6. I have firewall turned on for blocking everything except for the applications that I authenticate and standard ports for SSH, FTP, File Sharing and Web Sharing. I run geektool which I have showing firewall log, ssh log, windowssharing log. This morning I woke up to messages everywhere saying "failed password attempt for invalid user root from 66.167.***.*** port 40581 ssh2" First off going for an unusual port and going for root access. I do not have root access enabled. My question is without it enabled it will just say invalid user the entire time correct? I should not enable it and create an extremely weird password for it since without that account either way they wouldn't be able to connect? Now if they had the admin account and got in that way they would be able to create a root user or at least use su root knowing the admin password. I already have a long complicated password for my admin account, have guest access turned off and no other accounts on the server. Is there anything else that I could be doing to deter someone trying to get in?

Update:

I did a little snooping and found that the IP originated from the San Jose, CA area. And looking through my logs more they had been attempting most of the night on different port numbers but always SSH protocol.

Last edited by Fatum (2009-02-28 7:49 am)

Offline

 

#2 2009-02-28 8:31 am

Fracai
Evacipate
From: St. Elsewhere
Registered: 2000-05-25
Posts: 2835

Re: Hacking attempted???

Attempt?  Yes.  Success?  No.
Changing to use non-standard ports would help, but I wouldn't say this is anything to worry about.  Aside from it being a consistent attempt from the US.  Most of my attacks come from Asia and went away when I changed my external ssh port.  They'd also generally try standard or sequential usernames (user, a, aa, bbb, etc.).  root came up rarely.


   i am jack's amusing sig file
        http://alum.wpi.edu/~arno/i/s.png
Satellite Lot :: Second Summer

Offline

 

#3 2009-02-28 8:34 am

Fracai
Evacipate
From: St. Elsewhere
Registered: 2000-05-25
Posts: 2835

Re: Hacking attempted???

Also, I'm pretty sure that the port number is the randomly generated originating port number on their end.  Unless you really do have ssh running on multiple ports.  Which I think is unlikely.


   i am jack's amusing sig file
        http://alum.wpi.edu/~arno/i/s.png
Satellite Lot :: Second Summer

Offline

 

#4 2009-02-28 10:20 pm

Fatum
Member
Registered: 2004-06-04
Posts: 117

Re: Hacking attempted???

For some reason I have been getting bombarded on attempts in the past day. Also had connection attempts from Amsterdam, Japan and Indonesia. I have done some changes to my set-up to seal it up more. Each connection attempt will only except two password tries then disconnects and the IP address only gets two connection attempts (4 tries at the password) then it gets blacklisted for 10 days from connecting at all. Anything else I could do? Already have SSH on a non-standard port

Offline

 

#5 2009-03-02 9:15 pm

Fatum
Member
Registered: 2004-06-04
Posts: 117

Re: Hacking attempted???

I've been trying to figure out how to do it so now I ask here. With the attempts that have been going on the secure.log shows what names they are trying to use but I'm wondering if there is a way I can capture the passwords that they are trying?

Offline

 

Board footer

Powered by PunBB 1.2.6
© Copyright 2002–2005 Rickard Andersson