Webmaster Forum

Bidding Directory   Improve your ranking, submit to directories   V7N Directory
Go Back   Webmaster Forum > Web Development > Web Hosting Forum
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Web Hosting Forum Discuss web hosting related stuff.

Reply
 
LinkBack Thread Tools Display Modes
Old 09-14-2007, 12:02 PM   #1 (permalink)
Inactive
 
Join Date: 09-08-07
Posts: 3
iTrader: 0 / 0%
Latest Blog:
None

neonrider is liked by many
SSH Attacks question

In my new host I have a Cpanel, which is completely different than Plesk that I had. Every day my server gets hundreds of failed login attempts. My host says it is normal and I should not pay attention. But the last sentence in this WHM warning says to investigate the even for the integrity of my host? Please help with advise. Is this normal so many login attempts? My server does not definitely host some Yahoo like websites. Thanks very much:

"The remote system 62.24.139.125 was found to have exceeded acceptable login failures on host.domain.com; there was 53 events to the service sshd. As such the attacking host has been banned from further accessing this system. For the integrity of your host you should investigate this event as soon as possible."
neonrider is offline  
Add Post to del.icio.us
Reply With Quote
Sponsored Links
SEO Hosting by HostGator  Advertise Here  Buy Blog Links
Old 09-14-2007, 01:41 PM   #2 (permalink)
Junior Member
 
Join Date: 05-28-07
Posts: 27
iTrader: 0 / 0%
Latest Blog:
None

rllunzmann is liked by many
i would just disable SSH if you feel that is strictly the issue.
__________________
--
Ryan Lunzmann
Systems Administrator
eMonsterhost.com
rllunzmann is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-14-2007, 02:55 PM   #3 (permalink)
v7n Mentor
 
BingoBalls's Avatar
 
Join Date: 12-31-05
Posts: 1,135
iTrader: 0 / 0%
BingoBalls is a highly respected web proBingoBalls is a highly respected web proBingoBalls is a highly respected web proBingoBalls is a highly respected web proBingoBalls is a highly respected web proBingoBalls is a highly respected web proBingoBalls is a highly respected web proBingoBalls is a highly respected web proBingoBalls is a highly respected web proBingoBalls is a highly respected web proBingoBalls is a highly respected web pro
It is very normal. Servers in a hosting company are a sitting duck for hackers as many people dont perform normal security tasks. Whatever you do make sure that your passwords are really strong.

Is it a dedicated server you are using? If it is then you'll want to learn iptables and the best security policies to use.

I put an unprotected box (to test) on our network and the amount of brute force attacks on a daily basis is unbelievable.
BingoBalls is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-14-2007, 11:51 PM   #4 (permalink)
Moderator
 
ToddW's Avatar
 
Join Date: 01-11-04
Location: Folsom
Posts: 2,623
iTrader: 0 / 0%
ToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest orderToddW is a web professional of the highest order
Send a message via AIM to ToddW
It's def. normal.

Bind SSH to only 1 IP, SSH Protocol 2, and you could even move it to another port if your host allows.

-Todd
__________________
Learn about Bear Grylls, Les Stroud, Man Vs. Wild & SurvivorMan at Survival TV Shows
Order Exciting Inspirational Posters from Inspirational Posters at great value.
ToddW is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-18-2007, 01:05 PM   #5 (permalink)
Contributing Member
 
Join Date: 08-14-07
Posts: 242
iTrader: 0 / 0%
Latest Blog:
None

iHubNet-Matt is on the right pathiHubNet-Matt is on the right path
It is just normal.
What firewall are you using in the server? You can try BFD if you are using APF which will block all IP's which makes failed logins above a threshold level.

Also, you can harden SSH, by making it listen on a different port and disabling the direct root login.
iHubNet-Matt is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-20-2007, 02:07 AM   #6 (permalink)
Contributing Member
 
Join Date: 07-19-06
Posts: 236
iTrader: 0 / 0%
alemcherry is a jewel in the roughalemcherry is a jewel in the roughalemcherry is a jewel in the roughalemcherry is a jewel in the roughalemcherry is a jewel in the roughalemcherry is a jewel in the rough
I get much more failed attempts daily! Running SSH on a non standard port is not a bad idea.
alemcherry is offline  
Add Post to del.icio.us
Reply With Quote
Old 09-20-2007, 09:00 AM   #7 (permalink)
Contributing Member
 
Join Date: 08-14-07
Posts: 242
iTrader: 0 / 0%
Latest Blog:
None

iHubNet-Matt is on the right pathiHubNet-Matt is on the right path
Quote:
Originally Posted by alemcherry View Post
I get much more failed attempts daily! Running SSH on a non standard port is not a bad idea.

And changing the direct root login. Make a user with a unique name for ssh.
iHubNet-Matt is offline  
Add Post to del.icio.us
Reply With Quote
Go Back   Webmaster Forum > Web Development > Web Hosting Forum

Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Google Attacks peter_d Google Forum 0 10-10-2007 08:58 PM
DDoS attacks, help! Gideon Dedicated Servers 9 03-31-2006 05:01 AM
Website attacks thing2b Coding Forum 1 08-18-2005 02:20 PM


Sponsor Links
Get exposure! Get exposure! Find Scripts Web Hosting Directory Get exposure! SEO Blog


All times are GMT -7. The time now is 03:43 AM.
© Copyright 2008 V7 Inc