brute force attack - tcp wrappers and iptables not helping?
"Susanne Hemker" <[email protected]> Thu, 21 Apr 2005 10:24:04 -0400
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Hi everybody, somebody is trying to break into one of out workstations. The /var/log/secure contains lots of: Failed password for invalid user $name from ::ffff:$IP port $port ssh2 from different IPs, ports and usernames. Since the tcp wrappers and the iptables should not allow ssh login from any host outside our lab, I am wondering how he/she even got to the login. Any suggestions? Thanks, Susanne _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions