SSH Scams Update - Hello from Podlaskie
This latest scammer has been attempting to gain access to my dev server…I don’t know why, nothing good in there, and the mail system is disabled, so there’s really no incentive other than the conquest I guess.
Since I use this server for not much more than development, it is part of the Office Internet Package I recieve from Telus, which blocks all ports, accept for SSH. Kind of them, since they realized their customers still sometimes need to access their boxes remotely, or, as in my case, have the box installed with no graphical server onboard(why chew up precious memory and resources if you aren’t using them?)
Illegal users from these:
155.158.103.87 (p2a07.nuph.us.edu.pl): 571 times
Unmatched Entries
User postgres from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
User root from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
User root from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
User uucp from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
User root from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
User smmsp from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
User root from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
User root from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
User root from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
User root from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
User root from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
User mysql from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
User lp from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
User lp from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
User postgres from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
User postgres from p2a07.nuph.us.edu.pl not allowed because not listed in AllowUsers
As you can see, with allow users, you can globally deny any login from a Unix user other than the list, so try as they might, the server won’t budge.
IIS Hacks Continued
Mexican Government Site portal latest SSH Abuser
|