Tower Dweller
06-12-2005, 02:54 PM
Hey,
I have sshd running on my Linux box (Debian distro). The router routs all ssh requests to that box only. I was looking in my logs for some reason, and I saw the following in auth.log:
Jun 12 14:13:04 localhost sshd[16686]: Illegal user play from 203.230.151.91
Jun 12 14:13:05 localhost sshd[16688]: Illegal user open from 203.230.151.91
Jun 12 14:13:07 localhost sshd[16690]: Illegal user dulap from 203.230.151.91
Jun 12 14:13:09 localhost sshd[16692]: Illegal user if from 203.230.151.91
Jun 12 14:13:10 localhost sshd[16694]: Illegal user uk from 203.230.151.91
Jun 12 14:13:12 localhost sshd[16696]: Illegal user us from 203.230.151.91
Jun 12 14:13:14 localhost sshd[16698]: Illegal user alinus from 203.230.151.91
Jun 12 14:13:15 localhost sshd[16700]: Illegal user rumeno from 203.230.151.91
Jun 12 14:13:17 localhost sshd[16702]: Illegal user it from 203.230.151.91
It goes on and on. Looking back, this happens to me a lot, and not always from the same IP. runnig grep on the whole log directory, the lame-ass scripts don't try any of my actual user names, so I don't even know what it would try to do if it found a valid username - brute force the password maybe?
Anyway, this annoys me, and it seems like this would be against most provider's terms and conditions. Is there any way I can try to notify the providers that there are users not playing nice? I would love to get some of these punks kicked off of their service or something. Or is it not even worth the hassle?
I have sshd running on my Linux box (Debian distro). The router routs all ssh requests to that box only. I was looking in my logs for some reason, and I saw the following in auth.log:
Jun 12 14:13:04 localhost sshd[16686]: Illegal user play from 203.230.151.91
Jun 12 14:13:05 localhost sshd[16688]: Illegal user open from 203.230.151.91
Jun 12 14:13:07 localhost sshd[16690]: Illegal user dulap from 203.230.151.91
Jun 12 14:13:09 localhost sshd[16692]: Illegal user if from 203.230.151.91
Jun 12 14:13:10 localhost sshd[16694]: Illegal user uk from 203.230.151.91
Jun 12 14:13:12 localhost sshd[16696]: Illegal user us from 203.230.151.91
Jun 12 14:13:14 localhost sshd[16698]: Illegal user alinus from 203.230.151.91
Jun 12 14:13:15 localhost sshd[16700]: Illegal user rumeno from 203.230.151.91
Jun 12 14:13:17 localhost sshd[16702]: Illegal user it from 203.230.151.91
It goes on and on. Looking back, this happens to me a lot, and not always from the same IP. runnig grep on the whole log directory, the lame-ass scripts don't try any of my actual user names, so I don't even know what it would try to do if it found a valid username - brute force the password maybe?
Anyway, this annoys me, and it seems like this would be against most provider's terms and conditions. Is there any way I can try to notify the providers that there are users not playing nice? I would love to get some of these punks kicked off of their service or something. Or is it not even worth the hassle?