Results 1 to 5 of 5
  1. #1

    Default Why were you trying to login to my server???

    I received a email notice that someone on the eUKHost IP range was trying to gain access as root to my server. My server is NOT located on eUKHost so there is no reason why any of your staff would be trying to do so. Also to that point, none of your customers should be doing so either.

    I would require this matter be attended to and dealt with as a high priority from eUKHost before I consider further action.

    Details are :

    Time: Fri Jun 3 10:42:46 2011 +0100
    IP: 213.175.212.224 (GB/United Kingdom/-)
    Failures: 5 (sshd)
    Interval: 300 seconds
    Blocked: Permanent Block

    Log entries:

    Jun 3 10:42:38 server sshd[27817]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.175.212.224 user=root
    Jun 3 10:42:40 server sshd[27817]: Failed password for root from 213.175.212.224 port 45859 ssh2
    Jun 3 10:42:41 server sshd[27821]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.175.212.224 user=root
    Jun 3 10:42:43 server sshd[27821]: Failed password for root from 213.175.212.224 port 45965 ssh2
    Jun 3 10:42:44 server sshd[27825]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.175.212.224 user=root

  2. #2
    Join Date
    Nov 2007
    Location
    United Kingdom
    Posts
    648

    Default

    Quote Originally Posted by Qube View Post
    I received a email notice that someone on the eUKHost IP range was trying to gain access as root to my server. My server is NOT located on eUKHost so there is no reason why any of your staff would be trying to do so. Also to that point, none of your customers should be doing so either.

    I would require this matter be attended to and dealt with as a high priority from eUKHost before I consider further action.

    Details are :

    Time: Fri Jun 3 10:42:46 2011 +0100
    IP: 213.175.212.224 (GB/United Kingdom/-)
    Failures: 5 (sshd)
    Interval: 300 seconds
    Blocked: Permanent Block

    Log entries:

    Jun 3 10:42:38 server sshd[27817]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.175.212.224 user=root
    Jun 3 10:42:40 server sshd[27817]: Failed password for root from 213.175.212.224 port 45859 ssh2
    Jun 3 10:42:41 server sshd[27821]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.175.212.224 user=root
    Jun 3 10:42:43 server sshd[27821]: Failed password for root from 213.175.212.224 port 45965 ssh2
    Jun 3 10:42:44 server sshd[27825]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=213.175.212.224 user=root
    Hello Qube,

    Not to worry, we have forwarded this to our abuse department for them to investigate.
    Kind Regards,
    John - Managing Director

  3. #3

    Post

    The IP belongs to one of our client's VPS which is found to be compromised.
    The hacking scripts has been located and it is now removed from the source.
    This will be notified to the client right now.

  4. #4

    Default

    Thank you for your swift response. I hope they now up their VPS security a little

  5. #5
    Join Date
    Oct 2006
    Location
    localhost
    Posts
    3,375

    Smile

    Quote Originally Posted by Qube View Post
    Thank you for your swift response. I hope they now up their VPS security a little
    Hi, Thank you for reporting this incident, it has been taken care of now....

    Rock _a.k.a._ Jack
    Windows Hosting || Windows Reseller Hosting
    Cloud Hosting 100% UPTIME! || Powerful Dedicated Servers
    Follow eUKhost on Twitter || Join eUKhost Community on Facebook

    For complaints, grievances or suggestions kindly email our FeedBack Dept.
    Proper action will be taken accordingly & instantaneously!

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •