RE: brute force attack - tcp wrappers and iptables nothelping?

"Tim Walraven" <[email protected]> Fri, 22 Apr 2005 09:38:00 -0400
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
Susanne, I see your concern.  Properly configured IPTables rules and
TCPWrappers should prevent this.  Have you actually attempted to access
the ssh service from a host outside of the lab yourself?

Tim Walraven,CISSP,CISM,CISA
Counterpane Internet Security

-----Original Message-----
From: [email protected]
[mailto:[email protected]] On Behalf Of Susanne Hemker
Sent: Thursday, April 21, 2005 10:24 AM
To: [email protected]
Subject: [Intrusions] brute force attack - tcp wrappers and iptables
nothelping?

Hi everybody,

somebody is trying to break into one of out workstations. 
The /var/log/secure contains lots of:

 Failed password for invalid user $name  from ::ffff:$IP  port $port
ssh2

from different IPs, ports and usernames.

Since the tcp wrappers and the iptables should not allow ssh login from

any host outside our lab, I am wondering how he/she even got to the 
login. Any suggestions?

Thanks,

Susanne
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions