vbrookie
9th March 2009, 18:22
Hello all I've just upgraded my server few days ago from Etch to Lenny, and my fail2ban is not working. And for the past few days somebody is trying to break in to my server.
There are 100s of these entry on my auth.log.
Mar 9 09:42:33 ns1 sshd[15779]: Invalid user custom from 210.51.171.74
Mar 9 09:42:36 ns1 sshd[15781]: Invalid user custom from 210.51.171.74
Mar 9 09:42:39 ns1 sshd[15783]: Invalid user paula from 210.51.171.74
Mar 9 09:42:41 ns1 sshd[15785]: Invalid user tony from 210.51.171.74
Mar 9 09:42:44 ns1 sshd[15789]: Invalid user angie from 210.51.171.74
Mar 9 11:30:01 ns1 CRON[17155]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 9 11:30:01 ns1 CRON[17155]: pam_unix(cron:session): session closed for user root
Mar 9 11:39:01 ns1 CRON[17269]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 9 11:39:01 ns1 CRON[17269]: pam_unix(cron:session): session closed for user root
Mar 9 12:00:01 ns1 CRON[17827]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 9 12:00:01 ns1 CRON[17827]: pam_unix(cron:session): session closed for user root
Mar 9 12:01:28 ns1 sshd[17897]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:01:30 ns1 sshd[17900]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:01:32 ns1 sshd[17903]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:01:34 ns1 sshd[17906]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:01:36 ns1 sshd[17911]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:01:38 ns1 sshd[17913]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:01:39 ns1 sshd[17916]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:01:41 ns1 sshd[17919]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:04:10 ns1 sshd[18190]: Invalid user netdump from 134.159.122.26
Mar 9 12:04:12 ns1 sshd[18193]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:04:12 ns1 sshd[18193]: Invalid user user1 from 134.159.122.26
Mar 9 12:04:14 ns1 sshd[18196]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:04:14 ns1 sshd[18196]: Invalid user user1 from 134.159.122.26
Mar 9 12:04:16 ns1 sshd[18201]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:04:16 ns1 sshd[18201]: Invalid user student from 134.159.122.26
Mar 9 12:04:17 ns1 sshd[18204]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:04:18 ns1 sshd[18204]: Invalid user student1 from 134.159.122.26
Help.
There are 100s of these entry on my auth.log.
Mar 9 09:42:33 ns1 sshd[15779]: Invalid user custom from 210.51.171.74
Mar 9 09:42:36 ns1 sshd[15781]: Invalid user custom from 210.51.171.74
Mar 9 09:42:39 ns1 sshd[15783]: Invalid user paula from 210.51.171.74
Mar 9 09:42:41 ns1 sshd[15785]: Invalid user tony from 210.51.171.74
Mar 9 09:42:44 ns1 sshd[15789]: Invalid user angie from 210.51.171.74
Mar 9 11:30:01 ns1 CRON[17155]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 9 11:30:01 ns1 CRON[17155]: pam_unix(cron:session): session closed for user root
Mar 9 11:39:01 ns1 CRON[17269]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 9 11:39:01 ns1 CRON[17269]: pam_unix(cron:session): session closed for user root
Mar 9 12:00:01 ns1 CRON[17827]: pam_unix(cron:session): session opened for user root by (uid=0)
Mar 9 12:00:01 ns1 CRON[17827]: pam_unix(cron:session): session closed for user root
Mar 9 12:01:28 ns1 sshd[17897]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:01:30 ns1 sshd[17900]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:01:32 ns1 sshd[17903]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:01:34 ns1 sshd[17906]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:01:36 ns1 sshd[17911]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:01:38 ns1 sshd[17913]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:01:39 ns1 sshd[17916]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:01:41 ns1 sshd[17919]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:04:10 ns1 sshd[18190]: Invalid user netdump from 134.159.122.26
Mar 9 12:04:12 ns1 sshd[18193]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:04:12 ns1 sshd[18193]: Invalid user user1 from 134.159.122.26
Mar 9 12:04:14 ns1 sshd[18196]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:04:14 ns1 sshd[18196]: Invalid user user1 from 134.159.122.26
Mar 9 12:04:16 ns1 sshd[18201]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:04:16 ns1 sshd[18201]: Invalid user student from 134.159.122.26
Mar 9 12:04:17 ns1 sshd[18204]: reverse mapping checking getaddrinfo for unknown.net.reach.com [134.159.122.26] failed - POSSIBLE BREAK-IN ATTEMPT!
Mar 9 12:04:18 ns1 sshd[18204]: Invalid user student1 from 134.159.122.26
Help.