G
Gelöschtes Mitglied 141048
Guest
Guten Tag 
ich habe gestern mal einen Blick in meine auth.log geworfen.
Irgendwelche Kotnascher versuchen mehrmals pro Sekunde sich mit dem user root anzumelden.
Ist das ein normales Phänomen?
Grüße mieper

ich habe gestern mal einen Blick in meine auth.log geworfen.
Irgendwelche Kotnascher versuchen mehrmals pro Sekunde sich mit dem user root anzumelden.
Ist das ein normales Phänomen?
Code:
Jan 12 01:49:08 localhost sshd[30781]: Address 94.**.***.*** maps to hosted-by.leaseweb.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Jan 12 01:49:08 localhost sshd[30781]: Invalid user a from 94.**.***.***
Jan 12 01:49:08 localhost sshd[30781]: input_userauth_request: invalid user a [preauth]
Jan 12 01:49:08 localhost sshd[30781]: pam_unix(sshd:auth): check pass; user unknown
Jan 12 01:49:08 localhost sshd[30781]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=94.**.***.***
Jan 12 01:49:10 localhost sshd[30781]: Failed password for invalid user a from 94.**.***.*** port 36240 ssh2
Jan 12 01:49:10 localhost sshd[30781]: Received disconnect from 94.**.***.***: 11: Bye Bye [preauth]
Jan 12 01:49:10 localhost sshd[30783]: error: Could not load host key: /etc/ssh/ssh_host_ecdsa_key
Jan 12 01:49:10 localhost sshd[30783]: Address 94.**.***.*** maps to hosted-by.leaseweb.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Jan 12 01:49:10 localhost sshd[30783]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=94.**.***.*** user=root
Jan 12 01:49:13 localhost sshd[30783]: Failed password for root from 94.**.***.*** port 37287 ssh2
Jan 12 01:49:13 localhost sshd[30783]: Received disconnect from 94.**.***.***: 11: Bye Bye [preauth]
Jan 12 01:49:13 localhost sshd[30785]: error: Could not load host key: /etc/ssh/ssh_host_ecdsa_key
Jan 12 01:49:13 localhost sshd[30785]: Address 94.**.***.*** maps to hosted-by.leaseweb.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Jan 12 01:49:13 localhost sshd[30785]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=94.**.***.*** user=root
Grüße mieper