RE: brute force attack - tcp wrappers and iptables nothelping?
"Smith, Donald" <[email protected]> Fri, 22 Apr 2005 08:30:43 -0600
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <9921AB57EA49D242A076864C5F473D3C0180D226@itdene2km08.AD.QINTRA.COM> |
Can you do a couple of reverse lookups to see what is getting returned on the attack ips. We have seen one dns server that was returning something that MIGHT get past your filters based on the name being returned. [email protected] giac > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of Susanne Hemker > Sent: Thursday, April 21, 2005 8:24 AM > To: [email protected] > Subject: [Intrusions] brute force attack - tcp wrappers and > iptables nothelping? > > > Hi everybody, > > somebody is trying to break into one of out workstations. > The /var/log/secure contains lots of: > > Failed password for invalid user $name from ::ffff:$IP > port $port ssh2 > > from different IPs, ports and usernames. > > Since the tcp wrappers and the iptables should not allow ssh > login from > > any host outside our lab, I am wondering how he/she even got to the > login. Any suggestions? > > Thanks, > > Susanne > _______________________________________________ > Intrusions mailing list > [email protected] > http://www.dshield.org/mailman/listinfo/intrusions > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions