brute force attack - tcp wrappers and iptables not helping?

"Susanne Hemker" <[email protected]> Thu, 21 Apr 2005 10:24:04 -0400
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
Hi everybody,

somebody is trying to break into one of out workstations. 
The /var/log/secure contains lots of:

 Failed password for invalid user $name  from ::ffff:$IP  port $port
ssh2

from different IPs, ports and usernames.

Since the tcp wrappers and the iptables should not allow ssh login from

any host outside our lab, I am wondering how he/she even got to the 
login. Any suggestions?

Thanks,

Susanne
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions