From owner-freebsd-questions@FreeBSD.ORG Tue Apr 26 08:22:36 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 6304916A4CE for ; Tue, 26 Apr 2005 08:22:36 +0000 (GMT) Received: from pythagoras.zen.co.uk (pythagoras.zen.co.uk [212.23.3.140]) by mx1.FreeBSD.org (Postfix) with ESMTP id C898543D53 for ; Tue, 26 Apr 2005 08:22:35 +0000 (GMT) (envelope-from zen31722@zen.co.uk) Received: from [82.69.50.179] (helo=[10.0.1.2]) by pythagoras.zen.co.uk with esmtp (Exim 4.30) id 1DQLL0-0001VL-T2 for freebsd-questions@freebsd.org; Tue, 26 Apr 2005 08:22:34 +0000 Mime-Version: 1.0 (Apple Message framework v622) Content-Transfer-Encoding: 7bit Message-Id: Content-Type: text/plain; charset=US-ASCII; format=flowed To: freebsd-questions@freebsd.org From: Peter Kropholler Date: Tue, 26 Apr 2005 09:22:34 +0100 X-Mailer: Apple Mail (2.622) X-Originating-Pythagoras-IP: [82.69.50.179] Subject: illegal user root user failed login attempts X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 26 Apr 2005 08:22:36 -0000 I run a server at home on port 22. There are loads of illegal user attempts to login every few days. As its at home I protect myself by having only one user on the sshd AllowUsers list and with a very strong password and no admin/sysman priveleges. So essentially every failed login attempt is illegal. Is there any way to actually record what passwords the hackers' scripts are trying? I am just really intrigued to know what they are thinking might work. I realize that it's not normally appropriate to log people's passwords but in my case I am literally the only user who will ever legitimately login to my machine ______________________________ Professor Peter H Kropholler Department of Mathematics University of Glasgow University Gardens Glasgow G12 8QW Tel +44 (0)141 330 4124 Fax +44 (0)141 330 4111 email p.h.kropholler@maths.gla.ac.uk ______________________________