atom feed12 messages in org.freebsd.freebsd-securitysequences in the auth.log
FromSent OnAttachments
Sandor BertaAug 13, 2004 7:05 am 
Dan LangilleAug 13, 2004 7:14 am 
Nikolaj I. PotaninAug 13, 2004 7:14 am 
Mohacsi JanosAug 13, 2004 7:15 am 
Jan MuentherAug 13, 2004 7:55 am 
Craig EdwardsAug 13, 2004 10:48 am 
Peter C. LaiAug 13, 2004 11:52 am 
Gregory KuhnAug 13, 2004 12:35 pm 
JustinAug 17, 2004 9:01 pm 
Allen/Gore/SlackWareWolfAug 17, 2004 9:39 pm 
Nikolay PavlovAug 18, 2004 2:54 am 
Devon H. O'DellAug 18, 2004 2:56 am 
Subject:sequences in the auth.log
From:Peter C. Lai (sir@cowbert.net)
Date:Aug 13, 2004 11:52:18 am
List:org.freebsd.freebsd-security

On Fri, Aug 13, 2004 at 04:14:29PM +0200, Mohacsi Janos wrote:

Hi Sandor, You don't have to worry, unless you have user 'test', 'guest', 'admin', 'root' with poor password: typically same or very similar to your accountname. There seems to be a script around the hackers to scan SSH and gain access to poorly configured servers.... Unfortunately they are plenty of badly configured servers. May be you should disable root access via SSH password (only via keys).

Disabling root login via ssh will still cause 'failed password' entries in syslog. (on openssh 3.7 anyway)