Hi!
I have a question, I hope this is the right place to post.
I have this test PC for about 5 days I do test/installing/configuring and when I login as root just today here I have 5 new mail. Now, I read it and I came along this messages hundreds of them.-->>
The [lookslikeportnumber] is a 4 digit number, and the lookslikeIPnumber is like this one 211.60.184.138, 217.171.2.36, 82.208.124.129.
Is my box under attack?
Thanks and regards,
OrTigaS
I have a question, I hope this is the right place to post.
I have this test PC for about 5 days I do test/installing/configuring and when I login as root just today here I have 5 new mail. Now, I read it and I came along this messages hundreds of them.-->>
Code:
"Feb 5 (time) www sshd[lookslikesportnumber]: Invalid user (user) from (lookslikeIPnumber)"
"Feb 5 (time) www sshd[3321]: input_userauth_request: invalid user (user) [preauth]"
"Feb 5 (time) www sshd[3333]: Bad Protocol version identification " from (lookslikeIPnumber)"
'GET http://www.taobao.com / HTTP/1.1' from (lookslikeIPnumber)"
"Disconnecting Too many Authentication failures for root [preauth]
The [lookslikeportnumber] is a 4 digit number, and the lookslikeIPnumber is like this one 211.60.184.138, 217.171.2.36, 82.208.124.129.
Is my box under attack?
Thanks and regards,
OrTigaS