Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Mon Jun 09, 2008 1:58 am 
Offline
Newbie

Joined: Thu Apr 17, 2008 1:16 am
Posts: 4
Location: California
Did anyone else see a massive ssh brute force attack from 70.87.222.213?

I have a massive burst of attacks from this IP which is apparently a linode in the early hours of June 6 before my system locked them out.

If you own the linode with this IP and you aren't doing this yourself, your system has been compromised.


Top
   
 Post subject:
PostPosted: Fri Jun 13, 2008 12:00 pm 
Offline
Linode Staff
User avatar

Joined: Tue Apr 15, 2003 10:32 pm
Posts: 246
Location: NJ, USA
An e-mail to abuse@linode.com with a portion of your logs would be helpful.

Thanks,
-Tom


Top
   
PostPosted: Mon Jun 16, 2008 12:02 am 
Offline
Newbie

Joined: Wed May 21, 2008 8:59 pm
Posts: 4
ICQ: 160235155
Website: http://www.RavaSolutions.com
Yahoo Messenger: ychonry
Location: Stamford, CT
Install fail2ban

Also if you're running apache, suggest installing geoip module and block all the unwanted countries.

Just like any security measure - both of these will keep the script kiddies away and buy you some time during the premeditated attacks.

- G

Scottso wrote:
Did anyone else see a massive ssh brute force attack from 70.87.222.213?

I have a massive burst of attacks from this IP which is apparently a linode in the early hours of June 6 before my system locked them out.

If you own the linode with this IP and you aren't doing this yourself, your system has been compromised.


Top
   
 Post subject:
PostPosted: Sat Jun 28, 2008 1:55 am 
Offline
Newbie

Joined: Thu Apr 17, 2008 1:16 am
Posts: 4
Location: California
I run a large farm of servers for a publicly traded corporation as my day job and this was really just a courtesy notice (I happen to use Linode for my personal stuff). These IP's get immediately locked out of our network at the firewall so I don't generally bother to follow up on them more so than this. So do with the information as you will. In the future I will send info to abuse@linode.com with the log snippets. Most companies seem to ignore the abuse@ emails so I didn't try that avenue first.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 5 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group