From owner-freebsd-questions@FreeBSD.ORG Mon Oct 18 05:51:28 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 902F816A4CE for ; Mon, 18 Oct 2004 05:51:28 +0000 (GMT) Received: from ns2.wananchi.com (ns2.wananchi.com [62.8.64.4]) by mx1.FreeBSD.org (Postfix) with ESMTP id 0FF6D43D41 for ; Mon, 18 Oct 2004 05:51:27 +0000 (GMT) (envelope-from wash@wananchi.com) Received: from wash by ns2.wananchi.com with local (Exim 4.42 #0 (FreeBSD 4.10-STABLE)) id 1CJQQU-000Jfj-6r by authid for ; Mon, 18 Oct 2004 08:51:22 +0300 Date: Mon, 18 Oct 2004 08:51:22 +0300 From: Odhiambo Washington To: FBSD-Q Message-ID: <20041018055122.GB35360@ns2.wananchi.com> Mail-Followup-To: Odhiambo Washington , FBSD-Q Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline X-Disclaimer: Any views expressed in this message,where not explicitly attributed otherwise, are mine alone!. X-Mailer: Mutt 1.5.6i (2004-02-01) X-Designation: Systems Administrator, Wananchi Online Ltd. X-Location: Nairobi, KE, East Africa. User-Agent: Mutt/1.5.6i Subject: Are these attempts by password crackers?? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 18 Oct 2004 05:51:28 -0000 Hello users. I run several 5.2.1 boxes (in production). For weeks now, I have seen alot of notifications from periodic/daily with the output below and I have questions: 1. Is this some virus or some crackers playing around? 2. Why only on 5.2.1 systems and not on any of the 4.10 boxes that I also run? 3. Am I supposed to be worried at all? Well, I am not ;) I hate the messages though and there must be something here that I need to do. Oct 17 10:44:10 gw sshd[4170]: Failed password for nobody from 210.80.96.185 port 52215 ssh2 Oct 17 10:44:19 gw sshd[4172]: Failed password for patrick from 210.80.96.185 port 52337 ssh2 Oct 17 10:44:28 gw sshd[4174]: Failed password for patrick from 210.80.96.185 port 52455 ssh2 Oct 17 10:44:37 gw sshd[4176]: Failed password for root from 210.80.96.185 port 52568 ssh2 Oct 17 10:44:47 gw sshd[4178]: Failed password for root from 210.80.96.185 port 52691 ssh2 Oct 17 10:44:56 gw sshd[4180]: Failed password for root from 210.80.96.185 port 52807 ssh2 Oct 17 10:45:04 gw sshd[4182]: Failed password for root from 210.80.96.185 port 52916 ssh2 Oct 17 10:45:13 gw sshd[4187]: Failed password for root from 210.80.96.185 port 53024 ssh2 Oct 17 10:45:48 gw sshd[4196]: Failed password for cyrus from 210.80.96.185 port 53430 ssh2 Oct 17 10:45:57 gw sshd[4198]: Failed password for www from 210.80.96.185 port 53541 ssh2 Oct 17 10:47:08 gw sshd[4218]: Failed password for mysql from 210.80.96.185 port 55557 ssh2 Oct 17 10:47:17 gw sshd[4220]: Failed password for operator from 210.80.96.185 port 56448 ssh2 Oct 17 10:48:09 gw sshd[4232]: Failed password for root from 210.80.96.185 port 60881 ssh2 Oct 17 10:48:18 gw sshd[4234]: Failed password for root from 210.80.96.185 port 33508 ssh2 Oct 17 10:48:27 gw sshd[4236]: Failed password for root from 210.80.96.185 port 34356 ssh2 Oct 17 10:48:36 gw sshd[4239]: Failed password for jane from 210.80.96.185 port 34809 ssh2 Oct 17 10:48:54 gw sshd[4243]: Failed password for root from 210.80.96.185 port 36507 ssh2 Oct 17 10:49:08 gw sshd[4245]: Failed password for root from 210.80.96.185 port 37354 ssh2 Oct 17 19:28:05 gw sshd[5759]: Failed password for nobody from 200.251.13.5 port 50990 ssh2 Oct 17 19:28:12 gw sshd[5761]: Failed password for patrick from 200.251.13.5 port 51106 ssh2 Oct 17 19:28:19 gw sshd[5763]: Failed password for patrick from 200.251.13.5 port 51210 ssh2 Oct 17 19:28:26 gw sshd[5765]: Failed password for root from 200.251.13.5 port 51321 ssh2 Oct 17 19:28:33 gw sshd[5767]: Failed password for root from 200.251.13.5 port 51421 ssh2 Oct 17 19:28:40 gw sshd[5769]: Failed password for root from 200.251.13.5 port 51518 ssh2 Oct 17 19:28:47 gw sshd[5771]: Failed password for root from 200.251.13.5 port 51618 ssh2 Oct 17 19:28:54 gw sshd[5773]: Failed password for root from 200.251.13.5 port 51716 ssh2 Oct 17 19:29:22 gw sshd[5781]: Failed password for cyrus from 200.251.13.5 port 52077 ssh2 Oct 17 19:29:29 gw sshd[5783]: Failed password for www from 200.251.13.5 port 52166 ssh2 http://www.netmeister.org/news/learn2quote.html -- +======================================================================+ |\ _,,,---,,_ | Odhiambo Washington Zzz /,`.-'`' -. ;-;;,_ | Wananchi Online Ltd. www.wananchi.com |,4- ) )-,_. ,\ ( `'-'| Tel: +254 20 313985-9 +254 20 313922 '---''(_/--' `-'\_) | GSM: +254 722 743223 +254 733 744121 +======================================================================+ Eighty percent of air pollution comes from plants and trees. -- Ronald Reagan, famous movie star