| | |
Ftp attack
![]() |
Hey, people have been trying to brute force my ftp. Every day ill check the log and it will say stuff like:
[5] Fri 04Jan08 16:57:06 - (000569) Closing connection
[5] Fri 04Jan08 16:57:07 - (000570) Connected to 58.211.58.2 (Local address 192.168.1.100)
[5] Fri 04Jan08 16:57:08 - (000570) Too many times wrong password for user "ADMINISTRATOR" - disconnecting
[5] Fri 04Jan08 16:57:09 - (000570) Closing connection
[5] Fri 04Jan08 16:57:09 - (000571) Connected to 58.211.58.2 (Local address 192.168.1.100)
[5] Fri 04Jan08 16:57:11 - (000571) Too many times wrong password for user "ADMINISTRATOR" - disconnecting
[5] Fri 04Jan08 16:57:11 - (000571) Closing connection
Does anyone have any suggestions for how to deal with this?
Thanks M
[5] Fri 04Jan08 16:57:06 - (000569) Closing connection
[5] Fri 04Jan08 16:57:07 - (000570) Connected to 58.211.58.2 (Local address 192.168.1.100)
[5] Fri 04Jan08 16:57:08 - (000570) Too many times wrong password for user "ADMINISTRATOR" - disconnecting
[5] Fri 04Jan08 16:57:09 - (000570) Closing connection
[5] Fri 04Jan08 16:57:09 - (000571) Connected to 58.211.58.2 (Local address 192.168.1.100)
[5] Fri 04Jan08 16:57:11 - (000571) Too many times wrong password for user "ADMINISTRATOR" - disconnecting
[5] Fri 04Jan08 16:57:11 - (000571) Closing connection
Does anyone have any suggestions for how to deal with this?
Thanks M
this.love(*);
&hea/rts;
&hea/rts;
I actually didnt have an administrator account setup. I did set one up though with a simple password and no privileges in a directory with a file that says go away [in meaner terms]. So im not worried about them actually getting in, im actually surprised they haven't. its just annoying.
this.love(*);
&hea/rts;
&hea/rts;
•
•
Join Date: Sep 2007
Posts: 2
Reputation:
Solved Threads: 0
On your firewall (if it's based on Linux's iptables), with fail2ban software it uses IP address on your FTP log files, and it update the entries on the iptables rules. Here the fail2ban software (GPL License) while may be the solution to your problem.
http://www.fail2ban.org/wiki/index.php/Main_Page
http://www.fail2ban.org/wiki/index.php/Main_Page
Last edited by dotslash; Jan 6th, 2008 at 7:58 pm. Reason: Incorrect explanation
![]() |
Similar Threads
- Why Linux doesnt need an anti virus (Getting Started and Choosing a Distro)
- What's better? Windows 2000 Server or Linux Server? (Windows Servers and IIS)
- Sql Injuction (Viruses, Spyware and other Nasties)
- Please help! Fallen to Antispylab attack (Viruses, Spyware and other Nasties)
- Cannot FTP with Windows XP with any client or to any server (Networking Hardware Configuration)
- Unmetered Web space for Reseller Web Hosting from WebHostingWith.us (Web Hosting Deals)
- Can someone please help me with my HijackThis log (Viruses, Spyware and other Nasties)
Other Threads in the Network Security Forum
- Previous Thread: VZ issues With ISS
- Next Thread: Active Connections
| Thread Tools | Search this Thread |
adobe advice antivirus apple attack barackobama blackmail bot botnet browser business cellphone china civilliberties crime cybercrime cyberwarfare daniweb data database dataloss dataprotection development email emailretention encryption exploit facebook forensic fraud google government hack hacker hacking hardware hotmail ibm identity identitytheft idtheft information infosec internet iphone kaspersky kernel law linux malware mcafee mckinnon microsoft military mobile nasa nationalsecurity network news obama olympics p2p password passwords paypal pdf pentagon phishing politics privacy realplayer report research safari satnav scam search security socialnetworking software spam survey symantec symbian terrorism terrorist trends trojan trojans twitter uk usb virtualization virus vulnerability warning web word worm yahoo






