[TriLUG] Getting, um, probed?

Mark Fowle mark at thefowles.com
Wed Aug 4 20:48:41 EDT 2004


I've seen a lot of these entries over the last few weeks - usually 
starts around 5pm and runs until 1 or 2am -- looks like a probe. I don't 
have that range
open so I'm not too worried -- unless some one tells me I should be?

Thanks,
Mark


Brian Henning wrote:

>Hi Y'all,
>  I've been seeing a lot of the following in my logwatch lately:
>
>input_userauth_request: illegal user test
>input_userauth_request: illegal user test
>Failed password for illegal user test from 210.205.6.157 port 51389 ssh2
>Failed password for illegal user test from 210.205.6.157 port 51470 ssh2
>Received disconnect from 210.205.6.157: 11: Bye Bye
>Received disconnect from 210.205.6.157: 11: Bye Bye
>
>The source IP will differ from day to day, so I can't just block that
>particular IP at the firewall..  Anyone else getting a lot of this sort of
>breakin-attempt lately?  Should I be concerned?
>
>Cheers,
>~Brian
>
>  
>



More information about the TriLUG mailing list