RE: brute force attack - tcp wrappers and iptables nothelping?
"Tim Walraven" <[email protected]> Fri, 22 Apr 2005 09:38:00 -0400
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Susanne, I see your concern. Properly configured IPTables rules and TCPWrappers should prevent this. Have you actually attempted to access the ssh service from a host outside of the lab yourself? Tim Walraven,CISSP,CISM,CISA Counterpane Internet Security -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Susanne Hemker Sent: Thursday, April 21, 2005 10:24 AM To: [email protected] Subject: [Intrusions] brute force attack - tcp wrappers and iptables nothelping? Hi everybody, somebody is trying to break into one of out workstations. The /var/log/secure contains lots of: Failed password for invalid user $name from ::ffff:$IP port $port ssh2 from different IPs, ports and usernames. Since the tcp wrappers and the iptables should not allow ssh login from any host outside our lab, I am wondering how he/she even got to the login. Any suggestions? Thanks, Susanne _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions