RE: brute force attack - tcp wrappers and iptables not helping?
"Susanne Hemker" <[email protected]> Tue, 26 Apr 2005 10:07:47 -0400
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Hi everybody, thanks for your suggestions and sorry I did not get back to you earlier. 1) I tried to ssh from a host that is not on in my /etc/hosts.allow and I do not get an ssh login, only : ssh_exchange_identification: Connection closed by remote host. 2) The attacks come from different machines, some in Asia and some in the U.S., but those look to me as if they were hacked already in and are used to attack other computers. None of those IPs are in any way allowed to log onto my workstation. 3) In the Iptables I have everything from the outside set to REJECT (both IPv4 and IPv6). 4) My "inside" hosts are on two subnets and those are listed in the /etc/hosts.allow and set to" ACCEPT all" in the Iptables 5) I do not have the hosts listed in the sshd_config, perhaps I should change this and also change the authentication method (which is PasswordAuthentication right now) Any further suggestions on how they might have gotten to the ssh-login? Thanks, Susanne >>> [email protected] 04/22/05 9:38 AM >>> Susanne, I see your concern. Properly configured IPTables rules and TCPWrappers should prevent this. Have you actually attempted to access the ssh service from a host outside of the lab yourself? Tim Walraven,CISSP,CISM,CISA Counterpane Internet Security -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Susanne Hemker Sent: Thursday, April 21, 2005 10:24 AM To: [email protected] Subject: [Intrusions] brute force attack - tcp wrappers and iptables nothelping? Hi everybody, somebody is trying to break into one of out workstations. The /var/log/secure contains lots of: Failed password for invalid user $name from ::ffff:$IP port $port ssh2 from different IPs, ports and usernames. Since the tcp wrappers and the iptables should not allow ssh login from any host outside our lab, I am wondering how he/she even got to the login. Any suggestions? Thanks, Susanne _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions