Possible probe of account ????

Rund um die Sicherheit des Systems und die Applikationen
sosy
Posts: 67
Joined: 2002-09-30 21:07
 

Possible probe of account ????

Post by sosy »

Hallo zusammen, habe gegoogled, hier aufs board geschauht aber finde nichts was mir weiterhilft. Seit einige tagen bekomme ich im log (Srvreport) jede menge warnings, ich kann wenig damit anfangen, kann mir jemanden auf den sprung helfen...
Mar 31 23:41:02 p15153084 popper[28796]: Possible probe of account web0p1 from host p508206F0.dip0.t-ipconnect.de (80.130.6.240) [pop_quit.c:29]
Mar 31 23:42:02 p15153084 popper[28809]: Possible probe of account web0p1 from host p508206F0.dip0.t-ipconnect.de (80.130.6.240) [pop_quit.c:29]
Mar 31 23:43:02 p15153084 popper[28821]: Possible probe of account web0p1 from host p508206F0.dip0.t-ipconnect.de (80.130.6.240) [pop_quit.c:29]
Mar 31 23:44:02 p15153084 popper[28838]: Possible probe of account web0p1 from host p508206F0.dip0.t-ipconnect.de (80.130.6.240) [pop_quit.c:29]
Mar 31 23:45:02 p15153084 popper[28868]: Possible probe of account web0p1 from host p508206F0.dip0.t-ipconnect.de (80.130.6.240) [pop_quit.c:29]
Mar 31 23:46:02 p15153084 popper[28880]: Possible probe of account web0p1 from host p508206F0.dip0.t-ipconnect.de (80.130.6.240) [pop_quit.c:29]
Mar 31 23:47:02 p15153084 popper[28894]: Possible probe of account web0p1 from host p508206F0.dip0.t-ipconnect.de (80.130.6.240) [pop_quit.c:29]
Mar 31 23:48:02 p15153084 popper[28905]: Possible probe of account web0p1 from host p508206F0.dip0.t-ipconnect.de (80.130.6.240) [pop_quit.c:29]
Mar 31 23:49:02 p15153084 popper[28919]: Possible probe of account web0p1 from host p508206F0.dip0.t-ipconnect.de (80.130.6.240) [pop_quit.c:29]
Mar 31 23:50:02 p15153084 popper[28929]: Possible probe of account web0p1 from host p508206F0.dip0.t-ipconnect.de (80.130.6.240) [pop_quit.c:29]
Mar 31 23:51:02 p15153084 popper[28943]: Possible probe of account web0p1 from host p508206F0.dip0.t-ipconnect.de (80.130.6.240) [pop_quit.c:29]
Die liste ist natürlich wesentlich länger, den ganzen tag jede minute kommt diese warnung...

Im var/log/messages finde ich jede menge versuche für das fehlerhafte einloggen auf unser server... hängt das irgendwie damit zusammen?
Apr 1 02:18:15 p15153084 sshd[11492]: Illegal user test from ::ffff:211.121.153.27
Apr 1 02:18:20 p15153084 sshd[11492]: Failed password for illegal user test from ::ffff:211.121.153.27 port 1312 ssh2
Apr 1 02:18:23 p15153084 sshd[11497]: Illegal user guest from ::ffff:211.121.153.27
Apr 1 02:18:28 p15153084 sshd[11497]: Failed password for illegal user guest from ::ffff:211.121.153.27 port 1511 ssh2
Apr 1 02:18:30 p15153084 sshd[11508]: Illegal user admin from ::ffff:211.121.153.27
Apr 1 02:18:35 p15153084 sshd[11508]: Failed password for illegal user admin from ::ffff:211.121.153.27 port 1880 ssh2
Apr 1 02:18:38 p15153084 sshd[11510]: Illegal user admin from ::ffff:211.121.153.27
Apr 1 02:18:43 p15153084 sshd[11510]: Failed password for illegal user admin from ::ffff:211.121.153.27 port 2063 ssh2
Apr 1 02:18:46 p15153084 sshd[11513]: Illegal user user from ::ffff:211.121.153.27
Apr 1 02:18:50 p15153084 sshd[11513]: Failed password for illegal user user from ::ffff:211.121.153.27 port 2246 ssh2
Apr 1 02:18:54 p15153084 sshd[11515]: Failed password for root from ::ffff:211.121.153.27 port 2384 ssh2
Apr 1 02:18:57 p15153084 sshd[11517]: Failed password for root from ::ffff:211.121.153.27 port 2465 ssh2
Wäre über jeder tipp echt dankbar...
captaincrunch
Userprojekt
Userprojekt
Posts: 7066
Joined: 2002-10-09 14:30
Location: Dorsten
 

Re: Possible probe of account ????

Post by captaincrunch »

Mar 31 23:51:02 p15153084 popper[28943]: Possible probe of account web0p1 from host p508206F0.dip0.t-ipconnect.de (80.130.6.240) [pop_quit.c:29]
Einer deiner User ruft zu oft seine Mails per POP3 ab.
Apr 1 02:18:15 p15153084 sshd[11492]: Illegal user test from ::ffff:211.121.153.27
1. Hat die IP nichts mit der aus dem anderen Logfile zu tun.
2. Alter Hut. Die Forensuche quillt schon fast über davon.
DebianHowTo
echo "[q]sa[ln0=aln256%Pln256/snlbx]sb729901041524823122snlbxq"|dc
sosy
Posts: 67
Joined: 2002-09-30 21:07
 

Re: Possible probe of account ????

Post by sosy »

Oke, danke für deine antwort, das mit dem pop3 werde ich verfolgen und ändern, aber wie kann jemanden seine mails zu oft abholen??? Wusste gar nicht das da restrictions dran sind...
pfalzpower
Posts: 90
Joined: 2003-10-28 22:37
Location: Karlsruhe
 

Re: Possible probe of account ????

Post by pfalzpower »

sosy
Posts: 67
Joined: 2002-09-30 21:07
 

Re: Possible probe of account ????

Post by sosy »

Aha... also doch nicht nur zu oft mails abholen, und ein einfacher quit, sondern könnte auch ein break in sein...

Mmmm.... auf jeden fall besten dank
User avatar
Joe User
Project Manager
Project Manager
Posts: 11183
Joined: 2003-02-27 01:00
Location: Hamburg
 

Re: Possible probe of account ????

Post by Joe User »

Dein "Kunde" möchte begreifen, dass SMTP/POP3/IMAP im Gegensatz zu IRC kein Echtzeitmedium ist.
PayPal.Me/JoeUserFreeBSD Remote Installation
Wings for LifeWings for Life World Run

„If there’s more than one possible outcome of a job or task, and one
of those outcomes will result in disaster or an undesirable consequence,
then somebody will do it that way.“ -- Edward Aloysius Murphy Jr.