hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : Someone broke into my server?
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

Someone broke into my server?

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 03-27-2006, 02:11 AM
baocaosuok baocaosuok is offline
Junior Guru Wannabe
 
Join Date: Oct 2005
Posts: 78

Someone broke into my server?


hello everyone,

i've been getting email from logwatch of this connections:

--------------------- Connections (secure-log) Begin
------------------------


Changed users GID:
mailman: 41 -> 41

Connections:
Service smtp:
12.4.146.234: 1 Time(s)
60.9.146.154: 1 Time(s)
61.198.109.181: 1 Time(s)
66.127.239.106: 1 Time(s)
66.163.179.83: 1 Time(s)
82.21.95.247: 20 Time(s)
200.126.114.135: 1 Time(s)
203.98.189.83: 4 Time(s)
206.190.48.90: 1 Time(s)
207.69.200.171: 1 Time(s)
209.191.88.121: 1 Time(s)
219.91.64.181: 5 Time(s)

Does that mean some people broke into my server via smtp service?

if not, i wonder what are those connections?

i'm very appreciate any comment.

Thanks

Reply With Quote


Sponsored Links
  #2  
Old 03-27-2006, 11:00 AM
Lsupport Lsupport is offline
Junior Guru
 
Join Date: Mar 2006
Posts: 241
Hello,

This result for service SMTP is connections to the server via these Ips for the mail service . Check to see in the logs if there are any failed logins for the server.

__________________
LiquidSupport - A subsidiary of I-Fort Technologies (Pvt.) Ltd
Server Administration | Technical Support | Web Development

Reply With Quote
  #3  
Old 03-27-2006, 05:40 PM
baocaosuok baocaosuok is offline
Junior Guru Wannabe
 
Join Date: Oct 2005
Posts: 78
Thanks maximus,

i checked the log and it's normal. No failed logins

So does that mean my server has not been broken in?

Reply With Quote
Sponsored Links
  #4  
Old 03-27-2006, 05:42 PM
Energizer Bunny Energizer Bunny is offline
-=Quits Here=-
 
Join Date: Sep 2005
Location: In canada, Saskatoon
Posts: 3,200
Guess not.

Reply With Quote
  #5  
Old 03-27-2006, 05:45 PM
haynesdavis haynesdavis is offline
New Member
 
Join Date: Jan 2006
Posts: 2
Hello,

Then in that case your box is not comprimised and it is safe. To be more safe , try installing on the server apf and bfd.

Reply With Quote
  #6  
Old 03-27-2006, 10:01 PM
baocaosuok baocaosuok is offline
Junior Guru Wannabe
 
Join Date: Oct 2005
Posts: 78
Thanks everyone,

I do have APF, BFD, rkhunter, chkrootkit installed.

So hope it helps :d

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Web Host 1&1 Internet Adds Server Restoration Tool for Virtual Machines Web Hosting News 2012-11-07 15:45:16
Web Host OrcsWeb Offers Support for Windows Server 2012 Web Hosting News 2012-08-24 11:08:35
MochaHost Enhances Server Performance with Tomcat Native Library Accelerator Web Hosting News 2012-08-01 15:35:20
Web Host 1&1 Enhances Dedicated Server Line with 32 Core, 64 GB RAM Server Web Hosting News 2011-12-20 15:30:05
DiscountASP.NET Launches Free Beta for Microsoft SQL Server 2012 Hosting Web Hosting News 2011-12-13 22:02:03


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?