[phpBB Debug] PHP Notice: in file /includes/db/dbal.php on line 110: Undefined array key "cached"
[phpBB Debug] PHP Notice: in file /includes/db/dbal.php on line 111: Undefined array key "normal"
[phpBB Debug] PHP Notice: in file /includes/db/dbal.php on line 112: Undefined array key "total"
[phpBB Debug] PHP Notice: in file /includes/session.php on line 885: Cannot modify header information - headers already sent by (output started at /includes/functions.php:2922)
[phpBB Debug] PHP Notice: in file /includes/session.php on line 885: Cannot modify header information - headers already sent by (output started at /includes/functions.php:2922)
[phpBB Debug] PHP Notice: in file /includes/session.php on line 885: Cannot modify header information - headers already sent by (output started at /includes/functions.php:2922)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3391: Cannot modify header information - headers already sent by (output started at /includes/functions.php:2922)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3393: Cannot modify header information - headers already sent by (output started at /includes/functions.php:2922)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3394: Cannot modify header information - headers already sent by (output started at /includes/functions.php:2922)
[phpBB Debug] PHP Notice: in file /includes/functions.php on line 3395: Cannot modify header information - headers already sent by (output started at /includes/functions.php:2922)
Cabrillo College Linux Classes • View topic - UNIX systems on the Internet

UNIX systems on the Internet

UNIX/Linux Network Administration

UNIX systems on the Internet

Postby Rich Simms on Thu May 07, 2009 9:58 am

It doesn't take very long!

I temporarily opened port 22 (used port forwarding) on my home network to allow incoming ssh connections to my Arwen VM. This was the contingency plan in case I was unable to use Hershey for the POP, SMTP and IMAP exercises Tuesday night.

I started getting logwatch reports the very next day of attempts to break into the VM from the Internet!

Failed logins from:
62.140.23.205 (s5205.evanzo-server.de): 8 times
66.7.212.31 (66.7.212.31.static.dimenoc.com): 9 times
195.206.96.30 (smtpproxy.easyserver.at): 1 time
200.184.182.205 (200-184-182-205.convex.com.br): 5 times

Illegal users from:
66.7.212.31 (66.7.212.31.static.dimenoc.com): 273 times
195.206.96.30 (smtpproxy.easyserver.at): 78 times
200.184.182.205 (200-184-182-205.convex.com.br): 135 times
201.0.145.106 (201-0-145-106.dial-up.telesp.net.br): 1 time

Here are some of the bad user ID's they tried:

[root@arwen ~]# lastb | sort | cut -f1 -d' ' | grep -v ^$ | uniq -c | sort -g | tail -25
4 install
4 invite
4 leo
4 luciana
4 monika
4 next
4 nicole
4 oscar
4 paul
4 simona
4 start
4 t1na
4 temp
4 transfer
6 admin
6 test
8 hlds
10 shoutcas
10 teamspea
10 zabbix
12 informix
14 root
18 bwadmin
20 PlcmSpIp
20 ts
[root@arwen ~]#

If you have port 22 open on your home network (via port forwarding through the NAT) then be sure and read those logwatch reports using /bin/mail!

- Rich
User avatar
Rich Simms
Site Admin
 
Posts: 640
Joined: Thu May 15, 2008 2:44 pm

Re: UNIX systems on the Internet

Postby marcromansky on Thu May 07, 2009 10:36 pm

It's great how this internet thing has allowed people from all over the world to attempt to get into your bits!
marcromansky
 
Posts: 94
Joined: Tue Nov 04, 2008 7:55 pm


Return to CIS 192 - Spring 2009

Who is online

Users browsing this forum: No registered users and 0 guests

cron