zeke676
07-01-2005, 01:44 PM
I have a linux box running slackware, just set up for me to mess around with. It sits behind a linksys router in a DMZ setup where i can access this pc from anywhere. I checked a log file today with access attempts and part of it contained:
Jun 30 18:55:36 tuxBox sshd[1723]: Invalid user test from 66.235.160.30
Jun 30 18:55:36 tuxBox sshd[1723]: error: Could not get shadow information for NOUSER
Jun 30 18:55:36 tuxBox sshd[1723]: Failed password for invalid user test from 66.235.160.30 port 36428 ssh2
Jun 30 18:55:37 tuxBox sshd[1726]: Invalid user guest from 66.235.160.30
Jun 30 18:55:37 tuxBox sshd[1726]: error: Could not get shadow information for NOUSER
Jun 30 18:55:37 tuxBox sshd[1726]: Failed password for invalid user guest from 66.235.160.30 port 36587 ssh2
Jun 30 18:55:37 tuxBox sshd[1729]: Invalid user admin from 66.235.160.30
Jun 30 18:55:37 tuxBox sshd[1729]: error: Could not get shadow information for NOUSER
Jun 30 18:55:37 tuxBox sshd[1729]: Failed password for invalid user admin from 66.235.160.30 port 36638 ssh2
Jun 30 18:55:38 tuxBox sshd[1732]: Invalid user admin from 66.235.160.30
Jun 30 18:55:38 tuxBox sshd[1732]: error: Could not get shadow information for NOUSER
Jun 30 18:55:38 tuxBox sshd[1732]: Failed password for invalid user admin from 66.235.160.30 port 36670 ssh2
Jun 30 18:55:39 tuxBox sshd[1735]: Invalid user user from 66.235.160.30
Jun 30 18:55:39 tuxBox sshd[1735]: error: Could not get shadow information for NOUSER
Jun 30 18:55:39 tuxBox sshd[1735]: Failed password for invalid user user from 66.235.160.30 port 36792 ssh2
Jun 30 18:55:39 tuxBox sshd[1738]: Failed password for root from 66.235.160.30 port 36906 ssh2
Jun 30 18:55:40 tuxBox sshd[1741]: Failed password for root from 66.235.160.30 port 36943 ssh2
Jun 30 18:55:40 tuxBox sshd[1744]: Failed password for root from 66.235.160.30 port 37067 ssh2
Jun 30 18:55:41 tuxBox sshd[1747]: Invalid user test from 66.235.160.30
Jun 30 18:55:41 tuxBox sshd[1747]: error: Could not get shadow information for NOUSER
Jun 30 18:55:41 tuxBox sshd[1747]: Failed password for invalid user test from 66.235.160.30 port 37107 ssh2
Ive read that someone is trying to crack in my box but i dunno if they did or not. The /var/log/wtmp file was empty. And issueing "lastlog" command doesnt contain any information about a user being logged in yesterday.
Also in the lastlog command i got all these user names:
bin **Never logged in**
daemon **Never logged in**
adm **Never logged in**
lp **Never logged in**
sync **Never logged in**
shutdown **Never logged in**
halt **Never logged in**
mail **Never logged in**
news **Never logged in**
uucp **Never logged in**
operator **Never logged in**
games **Never logged in**
ftp **Never logged in**
smmsp **Never logged in**
mysql **Never logged in**
rpc **Never logged in**
sshd **Never logged in**
gdm **Never logged in**
pop **Never logged in**
nobody **Never logged in**
can someone tell me why i have all these users? They look like something for the services, but the user nobody makes me wonder?
Jun 30 18:55:36 tuxBox sshd[1723]: Invalid user test from 66.235.160.30
Jun 30 18:55:36 tuxBox sshd[1723]: error: Could not get shadow information for NOUSER
Jun 30 18:55:36 tuxBox sshd[1723]: Failed password for invalid user test from 66.235.160.30 port 36428 ssh2
Jun 30 18:55:37 tuxBox sshd[1726]: Invalid user guest from 66.235.160.30
Jun 30 18:55:37 tuxBox sshd[1726]: error: Could not get shadow information for NOUSER
Jun 30 18:55:37 tuxBox sshd[1726]: Failed password for invalid user guest from 66.235.160.30 port 36587 ssh2
Jun 30 18:55:37 tuxBox sshd[1729]: Invalid user admin from 66.235.160.30
Jun 30 18:55:37 tuxBox sshd[1729]: error: Could not get shadow information for NOUSER
Jun 30 18:55:37 tuxBox sshd[1729]: Failed password for invalid user admin from 66.235.160.30 port 36638 ssh2
Jun 30 18:55:38 tuxBox sshd[1732]: Invalid user admin from 66.235.160.30
Jun 30 18:55:38 tuxBox sshd[1732]: error: Could not get shadow information for NOUSER
Jun 30 18:55:38 tuxBox sshd[1732]: Failed password for invalid user admin from 66.235.160.30 port 36670 ssh2
Jun 30 18:55:39 tuxBox sshd[1735]: Invalid user user from 66.235.160.30
Jun 30 18:55:39 tuxBox sshd[1735]: error: Could not get shadow information for NOUSER
Jun 30 18:55:39 tuxBox sshd[1735]: Failed password for invalid user user from 66.235.160.30 port 36792 ssh2
Jun 30 18:55:39 tuxBox sshd[1738]: Failed password for root from 66.235.160.30 port 36906 ssh2
Jun 30 18:55:40 tuxBox sshd[1741]: Failed password for root from 66.235.160.30 port 36943 ssh2
Jun 30 18:55:40 tuxBox sshd[1744]: Failed password for root from 66.235.160.30 port 37067 ssh2
Jun 30 18:55:41 tuxBox sshd[1747]: Invalid user test from 66.235.160.30
Jun 30 18:55:41 tuxBox sshd[1747]: error: Could not get shadow information for NOUSER
Jun 30 18:55:41 tuxBox sshd[1747]: Failed password for invalid user test from 66.235.160.30 port 37107 ssh2
Ive read that someone is trying to crack in my box but i dunno if they did or not. The /var/log/wtmp file was empty. And issueing "lastlog" command doesnt contain any information about a user being logged in yesterday.
Also in the lastlog command i got all these user names:
bin **Never logged in**
daemon **Never logged in**
adm **Never logged in**
lp **Never logged in**
sync **Never logged in**
shutdown **Never logged in**
halt **Never logged in**
mail **Never logged in**
news **Never logged in**
uucp **Never logged in**
operator **Never logged in**
games **Never logged in**
ftp **Never logged in**
smmsp **Never logged in**
mysql **Never logged in**
rpc **Never logged in**
sshd **Never logged in**
gdm **Never logged in**
pop **Never logged in**
nobody **Never logged in**
can someone tell me why i have all these users? They look like something for the services, but the user nobody makes me wonder?