From owner-freebsd-questions@freebsd.org Thu Sep 27 19:13:55 2018 Return-Path: Delivered-To: freebsd-questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id BE67D10B67C2 for ; Thu, 27 Sep 2018 19:13:55 +0000 (UTC) (envelope-from freebsd@edvax.de) Received: from mailman.ysv.freebsd.org (mailman.ysv.freebsd.org [IPv6:2001:1900:2254:206a::50:5]) by mx1.freebsd.org (Postfix) with ESMTP id 5049F72B8F for ; Thu, 27 Sep 2018 19:13:55 +0000 (UTC) (envelope-from freebsd@edvax.de) Received: by mailman.ysv.freebsd.org (Postfix) id 111F010B67C1; Thu, 27 Sep 2018 19:13:55 +0000 (UTC) Delivered-To: questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id F3D5510B67C0 for ; Thu, 27 Sep 2018 19:13:54 +0000 (UTC) (envelope-from freebsd@edvax.de) Received: from mout.kundenserver.de (mout.kundenserver.de [217.72.192.73]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "mout.kundenserver.de", Issuer "TeleSec ServerPass DE-2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 41B6172B8E for ; Thu, 27 Sep 2018 19:13:54 +0000 (UTC) (envelope-from freebsd@edvax.de) Received: from r56.edvax.de ([92.195.59.48]) by mrelayeu.kundenserver.de (mreue108 [212.227.15.183]) with ESMTPA (Nemesis) id 1MCbR7-1fx2sC3wDj-009jB8; Thu, 27 Sep 2018 21:13:40 +0200 Received: from r56.edvax.de ([92.195.59.48]) by mrelayeu.kundenserver.de (mreue108 [212.227.15.183]) with ESMTPA (Nemesis) id 1MCbR7-1fx2sC3wDj-009jB8; Thu, 27 Sep 2018 21:13:40 +0200 Date: Thu, 27 Sep 2018 21:13:39 +0200 From: Polytropon To: David Banning Cc: questions@freebsd.org Subject: Re: dictionary attacks check Message-Id: <20180927211339.63a65ae6.freebsd@edvax.de> In-Reply-To: <20180926135329.GA24139@skytracker.ca> References: <20180926135329.GA24139@skytracker.ca> Reply-To: Polytropon Organization: EDVAX X-Mailer: Sylpheed 3.1.1 (GTK+ 2.24.5; i386-portbld-freebsd8.2) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Provags-ID: V03:K1:WpffonogG3uxKmMFpgC7OU5nmO3c/ywrJ66dh1WySa7INlhABSv ZaDTvUB57eU9H0pGPWQb5ifZI3t5BAVkZKjLD+4IRxoZTOXngOvdfviFOBkyhTo5LDmnYWV A6HcJhu61kw7Js3auTksiiQp/k8BXyZMhjxhJHsm5ZCHKOL0GVRDem1l/jFDAK/rH+3wmt2 Qsm1/5Jn/Du5NaOFBFkbA== X-UI-Out-Filterresults: notjunk:1;V01:K0:pteXea2ZqIU=:JRJ9vTLPkiFAO9X54uqy+5 FS8xffOaPOg06aaoKnkpdTfoDVrVi8mGB/Qjpxo+ksQot9WuoEs3t4eVVdbcsP6D0nfj+QWJC ACrAi2wmFxLMwRdJKoyoCLYdiijpPzG+mJqQ6Xm33EcLhoGEHv1h9SBjDQugC8KSCH6pvuy1d FKoiW7VfkPbtZBIkW/rmFsmSEfRcNjt+OIH6+pjZZ0832/n1hOTxGUfjBznK+GLCSaIljwQMr kIPaN1F6ClwOpQPWez9icoWMntNwjPhDsUP4AMAGxLIitP3kvWCUf32eiudP62Ha8JgtXZgAL iBZvzplJLJ+h1nC+qB9T5yhcj6Y6ueFTBKv6KjRJJQ0xlBIuAPtilIOYcceQn1sxR3VfHr/Ea QAtvQ59wgP/Ql6pnsAmlqiG8Oj15JeWSGKHiTnsMSpLyDhHjGxztdbrJ8pdsnVVrMqnjrZO2V FvpyL3VE6sTBRjdvt7eikzx27WVJRi42kZcAxCbBE9bK3lbCgNJshIpoYl/ObV/Vjsa4ZewwH g7721VjkEDijlp512IeNPyk8qaPnZ5aRr8uMiUZPwbhGhfKamM/+GVij5oS5PMFf7W+Q0cNKG WGfEO0cWKoVkA793mgSBgu+TZJ6cSz5dNyXjc45h3vNWz0MQUFt6X+IyLmeWLE5TczuHdr+Zw HJuT2l3Us8xUEHDUVYObfnSfGvA8Q35EyMTm30SYMwcE0EIOFyXZ4RkBmvickvMXomCB/2lMY sE35GJX/97dKYvFb X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.27 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 27 Sep 2018 19:13:55 -0000 On Wed, 26 Sep 2018 09:53:29 -0400, David Banning wrote: > I wonder what the best way is of checking my system to see > if it is commiting these dictionary attacks. > > My system it somewhat older; > > FreeBSD 3s1.com 9.3-RELEASE FreeBSD 9.3-RELEASE #0 > > Any pointers would be helpful. First of all, check the information you have in the logs; /var/log/security is a good point to start. Also check the log files for services you run, maybe /var/log/maillog, /var/log/xfer.log, /var/log/ftpd.log. Also check if the services you run start exhibiting strange behaviour. In case you notice _that_ - problems have already started... -- Polytropon Magdeburg, Germany Happy FreeBSD user since 4.0 Andra moi ennepe, Mousa, ...