XCan
October 1st, 2008, 03:19 PM
I have noticed that my auth.log is totally spammed with the following messages:
Oct 1 21:14:38 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:14:40 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:14:40 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:14:43 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:14:43 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:14:46 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:14:46 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:14:49 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:14:49 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:14:52 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:14:52 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:14:55 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:14:55 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:14:58 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:14:58 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:01 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:01 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:04 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:04 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:07 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:07 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:10 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:10 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:13 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:13 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:15 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:15 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:19 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:19 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:21 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:21 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:24 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Am I being attacked? I have set up the vnc server included in Ubuntu, and changed its port. Other than that the only service listening that I know is sshd on a non standard port as well.
Oct 1 21:14:38 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:14:40 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:14:40 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:14:43 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:14:43 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:14:46 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:14:46 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:14:49 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:14:49 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:14:52 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:14:52 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:14:55 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:14:55 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:14:58 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:14:58 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:01 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:01 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:04 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:04 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:07 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:07 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:10 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:10 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:13 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:13 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:15 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:15 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:19 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:19 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:21 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Oct 1 21:15:21 med gdm[25888]: pam_unix(gdm:auth): authentication failure; logname= uid=0 euid=0 tty=:0 ruser= rhost=
Oct 1 21:15:24 med gdm[25888]: pam_unix(gdm:auth): check pass; user unknown
Am I being attacked? I have set up the vnc server included in Ubuntu, and changed its port. Other than that the only service listening that I know is sshd on a non standard port as well.