hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : someone is scanning my server
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

someone is scanning my server

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 06-06-2004, 04:48 AM
neorder neorder is offline
Web Hosting Guru
 
Join Date: Jan 2003
Location: singapore
Posts: 292

someone is scanning my server


will you consider this is normal?

i recieved 107 email from my Broute Force Dection software this morning, it reported someone is trying to use different combination of user name and password to get into my server.

all emails are showing something like below except the user name they tried to get in is different.

Quote:
Jun 6 04:43:38 apple sshd[9215]: Illegal user support from 211.48.20.163
Jun 6 04:43:40 sv2 sshd[9209]: Failed password for illegal user support from
211.48.20.163 port 58502 ssh2
again, from my logwatch report i found:

Quote:
--------------------- SSHD Begin ------------------------

Argument "fw1" isn't numeric in numeric comparison (<=>) at
/etc/log.d//lib/Logwatch.pm line 233, <STDIN> line 39.
Argument "3essentials" isn't numeric in numeric comparison (<=>) at
/etc/log.d//lib/Logwatch.pm line 233, <STDIN> line 39.
in the end of my logwatch email:

Quote:
Scanned from these:
fw1.3essentials.com (66.179.167.245)
fw1.3essentials.com (66.179.167.245)
fw1.3essentials.com (66.179.167.245)
fw1.3essentials.com (66.179.167.245)
fw1.3essentials.com (66.179.167.245)
fw1.3essentials.com (66.179.167.245)
fw1.3essentials.com (66.179.167.245)

**Unmatched Entries**
sshd -HUP succeeded
i use directadmin and disabled end users' SSH access, if you have recieved above information, what would you do? i'm not so confident if i'm safe now...

btw, 3essentials.com is a web hosting company as well, is it alright a host scan another host?

Reply With Quote


Sponsored Links
  #2  
Old 06-06-2004, 06:11 AM
BizB BizB is offline
Web Hosting Evangelist
 
Join Date: Jul 2003
Posts: 526
email there admin and block there ip from your ssh port "dont block them totaly so you can recive there replay to your email"
it could be a hacked account on there server and its beeing used to hack other servers.

Reply With Quote
  #3  
Old 06-06-2004, 10:00 AM
pizzaboy_au pizzaboy_au is offline
Web Hosting Evangelist
 
Join Date: Dec 2003
Location: Brisbane, Queensland, Australia
Posts: 547
Quote:
Jun 6 04:43:38 apple sshd[9215]: Illegal user support from 211.48.20.163
Jun 6 04:43:40 sv2 sshd[9209]: Failed password for illegal user support from
211.48.20.163 port 58502 ssh2
I had the same ip scanning my boxes. It is a hacked box in korea. The ip resolves to www.7view.com . I have sent an email to the admins however i do not expect anything back from them. It kept scanning my boxes from 6:00am to 6:24am for 2 days in a row. I got 357 emails the first day from BFD.

All you can do is ban the ip address.

Reply With Quote
Sponsored Links
  #4  
Old 06-06-2004, 10:07 AM
Informity Informity is offline
Web Hosting Master
 
Join Date: Jul 2002
Location: UK
Posts: 2,026
just block the IP from your machine.

It's most likely just some script kiddie screwing about with a compromised server (or their own computer if they're stupid)

__________________
Gone.

Reply With Quote
  #5  
Old 06-06-2004, 10:12 AM
pizzaboy_au pizzaboy_au is offline
Web Hosting Evangelist
 
Join Date: Dec 2003
Location: Brisbane, Queensland, Australia
Posts: 547
Quote:
Argument "fw1" isn't numeric in numeric comparison (<=> ) at
/etc/log.d//lib/Logwatch.pm line 233, <STDIN> line 39.
Argument "3essentials" isn't numeric in numeric comparison (<=> ) at
/etc/log.d//lib/Logwatch.pm line 233, <STDIN> line 39.
In regards to this is logwatch installed properly.
Did you ever get the above quotes in your email before the BFD emails started to arrive?

Quote:
3essentials.com is a web hosting company as well, is it alright a host scan another host?
Usually hosts do not scan other webhosters computers unless they have been comprimised.

Reply With Quote
  #6  
Old 06-06-2004, 09:34 PM
Daniel53 Daniel53 is offline
New Member
 
Join Date: Jun 2004
Posts: 4
Block the IP address for your SSH port (default 22) and e-mail the admin. If you dont get any response, I'd go ahead and block the whole IP. It's probably a hacked box, not the actual web-company trying to scan you.

Reply With Quote
  #7  
Old 06-07-2004, 12:35 PM
SiSHCO SiSHCO is offline
Junior Guru Wannabe
 
Join Date: Jun 2004
Posts: 91
Also change to SSH port to 1000 or something like that. They never know that : ). And of course block ip address.

__________________
SiSHCO SERVERS SINCE 2004
█ 100MBIT • 1GBIT DEDICATED SERVERS | PHP • ASP WEB HOSTING | DOMAIN REGISTER
SiSHCOCLIENT CENTER


Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Web Host 1&1 Internet Adds Server Restoration Tool for Virtual Machines Web Hosting News 2012-11-07 15:45:16
Security Firm nCircle Finds 24 Percent of SMB Networks have Weak SSL Encryption Web Hosting News 2012-06-22 13:37:00
WHIR Demo: SiteLock Website Malware Scanning Whir Tv 2012-02-20 12:59:15
Security Provider HostingArmor Releases Server Scanning cPanel Plugin Web Hosting News 2011-07-25 19:33:26
Certificate Authority Comodo Releases Free E-commerce Site Scanning Tool Web Hosting News 2011-06-23 17:27:14


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?