It appears you have not registered with our community. To register please click here ...

Author Topic: Server under attack?  (Read 1157 times)

dynaweb

  • <b>Canine Deamon</b>
  • Administrator
  • Sr. Member
  • *****
  • Posts: 493
  • Karma: +10/-0
  • Generic personal text here ...
    • MSN Messenger - danno_d_manno@yahoo.com
    • View Profile
    • DynaWeb Designs
    • Email
Server under attack?
« on: January 12, 2006, 09:07:35 AM »
So I go into the office this morning and notice my mail is taking a long time to be retrieved.  After like a minute, there appears a thousand messages from the BFD (Brute Force Detection) that IP addresses are being banned for invalid number of incorrect login attempts (hacking into shell).  I have seen such emails before, either they were positive alarms from random hackers or they were a user on the server who was having a really bad day (forgot their login info and tried so many different things until they got banned), but I have never seen anything on this scale before.  Each email notification I received indicates a different IP address that got banned.  All IPs are unique.  BFD is working hard and doing it\'s job; it is at the top of #top processes.
 
So it is safe to say my server is under attack right now.  As far as I can tell, it is not having too much affect.  Web pages are loading a bit slowly, log files are filling up, but that\'s about it.
 
So I guess we just weather the storm here?  How on earth can so many unique IP addresses all be pounding my server\'s sill?  A new breed of hacking software with a database of proxy connections?
Those who cannot learn from history are doomed to repeat it. -- Linux learns.

dynaweb

  • <b>Canine Deamon</b>
  • Administrator
  • Sr. Member
  • *****
  • Posts: 493
  • Karma: +10/-0
  • Generic personal text here ...
    • MSN Messenger - danno_d_manno@yahoo.com
    • View Profile
    • DynaWeb Designs
    • Email
Resolved
« Reply #1 on: January 13, 2006, 08:38:27 PM »
The attack was on exim mail server and was relentless!
 
Found an instance of psybnc in a 777 directory.
 
Code: [Select]
# locate psybnc
Killed it, changed dir to 755 and rebooted, problem solved. Load averages returned to normal and my server is happy again :)
Those who cannot learn from history are doomed to repeat it. -- Linux learns.

 

Related Topics

  Subject / Started by Replies Last post
2 Replies
1206 Views
Last post January 01, 2006, 09:46:05 PM
by adb22791
2 Replies
4052 Views
Last post December 13, 2007, 09:06:59 PM
by Joncamp
3 Replies
3749 Views
Last post September 20, 2010, 09:44:41 AM
by dynaweb
0 Replies
1857 Views
Last post March 24, 2006, 01:34:38 AM
by dynaweb
1 Replies
1533 Views
Last post June 10, 2006, 03:05:34 AM
by dynaweb