spiderbatdad
November 29th, 2008, 12:04 PM
I'm curious about this type of message in /var/log/auth.log Failed password for invalid user snort from 189.6.234.118 port 61367 ssh2
sshd[16713]: Connection from 189.6.234.118 port 61577
sshd[16713]: reverse mapping checking getaddrinfo for bd06ea76.virtua.com.br [189.6.234.118] failed - POSSIBLE BREAK-IN ATTEMPT!
sshd[16713]: Invalid user radiomail from 189.6.234.118
sshd[16713]: pam_unix(sshd:auth): check pass; user unknown
pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=189.6.234.118
sshd[16713]: Failed password for invalid user radiomail from 189.6.234.118 port 61577 ssh2
sshd[16715]: Connection from 189.6.234.118 port 61975
sshd[16715]: reverse mapping checking getaddrinfo for bd06ea76.virtua.com.br [189.6.234.118] failed - POSSIBLE BREAK-IN ATTEMPT!
Of course I do not know this person or address. dig -x shows ; <<>> DiG 9.5.0-P2 <<>> -x 189.6.234.118
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 54281
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 3, ADDITIONAL: 0
;; QUESTION SECTION:
;118.234.6.189.in-addr.arpa. IN PTR
;; ANSWER SECTION:
118.234.6.189.in-addr.arpa. 3600 IN PTR bd06ea76.virtua.com.br.
;; AUTHORITY SECTION:
234.6.189.in-addr.arpa. 3600 IN NS dns1.virtua.com.br.
234.6.189.in-addr.arpa. 3600 IN NS ns.embratel.com.br.
234.6.189.in-addr.arpa. 3600 IN NS dns2.virtua.com.br.
;; Query time: 322 msec
;; SERVER: 66.189.132.4#53(66.189.132.4)
;; WHEN: Sun Nov 30 17:37:45 2008
Is it normal for unknow users to suddenly see my server. Could it be related to the fact that an authorized user previously logged in...albiet from a local network?
sshd[16713]: Connection from 189.6.234.118 port 61577
sshd[16713]: reverse mapping checking getaddrinfo for bd06ea76.virtua.com.br [189.6.234.118] failed - POSSIBLE BREAK-IN ATTEMPT!
sshd[16713]: Invalid user radiomail from 189.6.234.118
sshd[16713]: pam_unix(sshd:auth): check pass; user unknown
pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=189.6.234.118
sshd[16713]: Failed password for invalid user radiomail from 189.6.234.118 port 61577 ssh2
sshd[16715]: Connection from 189.6.234.118 port 61975
sshd[16715]: reverse mapping checking getaddrinfo for bd06ea76.virtua.com.br [189.6.234.118] failed - POSSIBLE BREAK-IN ATTEMPT!
Of course I do not know this person or address. dig -x shows ; <<>> DiG 9.5.0-P2 <<>> -x 189.6.234.118
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 54281
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 3, ADDITIONAL: 0
;; QUESTION SECTION:
;118.234.6.189.in-addr.arpa. IN PTR
;; ANSWER SECTION:
118.234.6.189.in-addr.arpa. 3600 IN PTR bd06ea76.virtua.com.br.
;; AUTHORITY SECTION:
234.6.189.in-addr.arpa. 3600 IN NS dns1.virtua.com.br.
234.6.189.in-addr.arpa. 3600 IN NS ns.embratel.com.br.
234.6.189.in-addr.arpa. 3600 IN NS dns2.virtua.com.br.
;; Query time: 322 msec
;; SERVER: 66.189.132.4#53(66.189.132.4)
;; WHEN: Sun Nov 30 17:37:45 2008
Is it normal for unknow users to suddenly see my server. Could it be related to the fact that an authorized user previously logged in...albiet from a local network?