ubuntu-users@lists.ubuntu.com
[Top] [All Lists]

Re: auth.log showing attempted access

Subject: Re: auth.log showing attempted access
From: sktsee
Date: Tue, 14 Aug 2007 22:37:20 -0500
On Tue, 2007-08-14 at 20:46 -0400, Yuelin Li wrote: 
> I see many entries like this in /var/log/auth.log
> 
> sshd[15144]: Failed password for invalid user josh from::ffff:89.123.234.25 
> port 2092 ssh2
> 
> How can I trace this computer's location?  More importantly, how can I
> report this person to his/her ISP?  "host 89.123.234.25" showed that
> this DNS entry can not be reversed.  Traceroute stops at
> FR1-Frankfurt.teleglobe.net (80.231.64.6).  I have added iptables
> rules (see http://www.debian-administration.org/articles/187) to try
> to tighten SSH access.  I feel I should do something about it because
> I get a few hundred entries a day coming from the same IP address.
> 
> Yuelin.
> 
>  

Try

$ whois 89.123.234.25 

and go from there.

-- 
sktsee


-- 
ubuntu-users mailing list
ubuntu-users@xxxxxxxxxxxxxxxx
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-users

<Prev in Thread] Current Thread [Next in Thread>