RE: brute force attack - tcp wrappers and iptables nothelping?

"Smith, Donald" <[email protected]> Fri, 22 Apr 2005 08:30:43 -0600
Newsgroups gmane.comp.security.intrusions
Message-ID <9921AB57EA49D242A076864C5F473D3C0180D226@itdene2km08.AD.QINTRA.COM>
Can you do a couple of reverse lookups to see what is getting returned
on the attack ips.
We have seen one dns server that was returning something that MIGHT get
past your filters based on the name being returned.


[email protected] giac 

> -----Original Message-----
> From: [email protected] 
> [mailto:[email protected]] On Behalf Of Susanne Hemker
> Sent: Thursday, April 21, 2005 8:24 AM
> To: [email protected]
> Subject: [Intrusions] brute force attack - tcp wrappers and 
> iptables nothelping?
> 
> 
> Hi everybody,
> 
> somebody is trying to break into one of out workstations. 
> The /var/log/secure contains lots of:
> 
>  Failed password for invalid user $name  from ::ffff:$IP  
> port $port ssh2
> 
> from different IPs, ports and usernames.
> 
> Since the tcp wrappers and the iptables should not allow ssh 
> login from
> 
> any host outside our lab, I am wondering how he/she even got to the 
> login. Any suggestions?
> 
> Thanks,
> 
> Susanne
> _______________________________________________
> Intrusions mailing list
> [email protected] 
> http://www.dshield.org/mailman/listinfo/intrusions
> 

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions