Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 14 Jan 2007 15:39:30 +0100
From:      Erik Norgaard <norgaard@locolomo.org>
To:        VeeJay <maanjee@gmail.com>
Cc:        FreeBSD-Questions <freebsd-questions@freebsd.org>
Subject:   Re: Please Help! How to STOP them...
Message-ID:  <45AA40A2.2000906@locolomo.org>
In-Reply-To: <2cd0a0da0701121343g7fa2535fv4a7b201f5a03aff2@mail.gmail.com>
References:  <2cd0a0da0701121343g7fa2535fv4a7b201f5a03aff2@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
VeeJay wrote:
> I am reading many hundred lines similar to below mentioned?
> 
> Could you please advise me what to do and how can I make my box more secure?
> 
> Jan  9 17:54:42 localhost sshd[5130]: reverse mapping checking getaddrinfo
> for bbs-83-179.189.218.on-nets.com [218.189.179.83] failed - POSSIBLE
> BREAK-IN ATTEMPT!
> Jan  9 17:54:42 localhost sshd[5130]: Invalid user sysadmin from
> 218.189.179.83
> 

Please, this is possibly the most frequently asked question not in the 
FAQ. Understand that whenever you make a service available on the 
internet, someone is going to try to break in. Be it ssh, smtp, dns, 
http etc. What you need to learn is to identify which attacks constitute 
a real threat to your system.

The first log entry is no sign of break in attempt. Just because a DNS 
server is misconfigured doesn't mean that people are trying to attack you.

The second line is evidence that some illicit events are recorded. But, 
there is no reason to worry about these if you have properly configured 
your box. Please search the archives for ssh brute force - this topic 
has been discussed a zillion times.

Some mention port knocking. This doesn't make people stop trying to get 
into your box. It introduces an extra hazle to do so as you first have 
to knock on the port a secret (but shared secret) sequence. Then you 
will authenticate as previously.

If you are troubled with messages in your log, there are plenty of 
ordinary things you can do:

- enforce key authentication
- restrict access to certain users or groups of users
- deny direct access as root
- enforce strong passwords, if you can't enforce key authentication
- limit the ip address space that is allowed to connect, to the space
   where you or your users are likely to be
- limit the number of simultaneous unauthenticated connections

Cheers, Erik
-- 
Ph: +34.666334818                      web: http://www.locolomo.org

[-- Attachment #2 --]
0	*H
010	+0	*H

0p0XET+0
	*H
0110	UDK10
U
TDC10UTDC OCES CA0
061115083154Z
081115090154Z0u10	UDK1)0'U
 Ingen organisatorisk tilknytning1;0U
Erik Nrgaard0#UPID:9802-2002-2-54436976931500
	*H
0WR&5ʄ8#S^fOパBrIsPBc! >r&8hl3?\.UGB\E3Q!1MrwP*02\|\&s{b'`1&100U0+U$0"20061115083154Z20081115090154Z07U .0*0&
*P)00/+#http://www.certifikat.dk/repository0+00
TDC0For anvendelse af certifikatet glder OCES vilkr, CPS og OCES CP, der kan hentes fra www.certifikat.dk/repository. Bemrk, at TDC efter vilkrene har et begrnset ansvar ift. professionelle parter.0A+50301+0%http://ocsp.certifikat.dk/ocsp/status0 U0norgaard@locolomo.org0U}0{0KIGE0C10	UDK10
U
TDC10UTDC OCES CA10UCRL15570,*(&http://crl.oces.certifikat.dk/oces.crl0U#0`Vd~'gPKs;0U~kG'f+Q{m&0	U00	*H}A0
V7.10
	*H
OJ'|)%Ҋi`1
^nE
jJwKӼB65VSǶw`y$L=YXʷ/\E~,PW$AB\汎͙
7%$	N-ށ"/Ww#ғkMA6S0dD~\w*zPq`#	69;pS6 	뛨3:9s_.'³Q$S0yAƶlqfLi0p0XET+0
	*H
0110	UDK10
U
TDC10UTDC OCES CA0
061115083154Z
081115090154Z0u10	UDK1)0'U
 Ingen organisatorisk tilknytning1;0U
Erik Nrgaard0#UPID:9802-2002-2-54436976931500
	*H
0WR&5ʄ8#S^fOパBrIsPBc! >r&8hl3?\.UGB\E3Q!1MrwP*02\|\&s{b'`1&100U0+U$0"20061115083154Z20081115090154Z07U .0*0&
*P)00/+#http://www.certifikat.dk/repository0+00
TDC0For anvendelse af certifikatet glder OCES vilkr, CPS og OCES CP, der kan hentes fra www.certifikat.dk/repository. Bemrk, at TDC efter vilkrene har et begrnset ansvar ift. professionelle parter.0A+50301+0%http://ocsp.certifikat.dk/ocsp/status0 U0norgaard@locolomo.org0U}0{0KIGE0C10	UDK10
U
TDC10UTDC OCES CA10UCRL15570,*(&http://crl.oces.certifikat.dk/oces.crl0U#0`Vd~'gPKs;0U~kG'f+Q{m&0	U00	*H}A0
V7.10
	*H
OJ'|)%Ҋi`1
^nE
jJwKӼB65VSǶw`y$L=YXʷ/\E~,PW$AB\汎͙
7%$	N-ށ"/Ww#ғkMA6S0dD~\w*zPq`#	69;pS6 	뛨3:9s_.'³Q$S0yAƶlqfLi1*0&090110	UDK10
U
TDC10UTDC OCES CAET+0	+G0	*H
	1	*H
0	*H
	1
070114143930Z0#	*H
	1~U	=~`Z0H	+71;090110	UDK10
U
TDC10UTDC OCES CAET+0J*H
	1;90110	UDK10
U
TDC10UTDC OCES CAET+0R	*H
	1E0C0
*H
0*H
0
*H
@0+0
*H
(0
	*H
T
82Rw
V[35e)HZ}?>oP6>Bf_>ǝQU%ATeR1~Kg7RH!>;TxcB$.a

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?45AA40A2.2000906>