View Single Post

   
  #3 (permalink)  
Old 02-19-2008, 12:17 PM
Carl Parsons
 
Posts: n/a
Default Re: in.comsat vulnerability

This was the target computer log file

Jun 15 23:27:24 sshd[1238]: Illegal user pingnu from 81.178.1.21
Jun 15 23:27:45 sshd[1238]: Failed unknown for illegal user pingnu from
81.178.1.21 port 32807 ssh2
Jun 15 23:27:59 last message repeated 2 times
Jun 15 23:28:02 sshd[1243]: Illegal user pingnu from 81.178.1.21
Jun 15 23:28:18 sshd[1243]: Failed unknown for illegal user pingnu from
81.178.1.21 port 32808 ssh2
Jun 15 23:28:23 sshd[1243]: fatal: PAM: authentication thread exited
unexpectedly
Jun 15 23:28:49 sshd[1247]: Illegal user pingnu from 81.178.1.21
Jun 15 23:29:04 sshd[1247]: Failed unknown for illegal user pingnu from
81.178.1.21 port 32809 ssh2
Jun 15 23:29:43 sshd[1247]: Failed unknown for illegal user pingnu from
81.178.1.21 port 32809 ssh2
Jun 15 23:29:45 sshd[1247]: fatal: PAM: authentication thread exited
unexpectedly

My log files

Jun 16 01:12:06 router in.identd[6265]: reply to 127.0.0.1: 33182 , 25 :
USERID : OTHER :25
Jun 16 01:13:17 router in.identd[6282]: reply to 127.0.0.1: 33184 , 25 :
USERID : OTHER :25

Jun 16 01:12:07 router in.comsat[6268]: connect from 127.0.0.1

Jun 16 01:12:06 router sendmail[6263]: i5G0C6Zp006263: from=root, size=788,
class=0, nrcpts=1, msgid=<200406160012.i5G0C6Zp006263@router.pingnu.c om>,
relay=root@localhost
Jun 16 01:12:07 router sm-mta[6264]: i5G0C6SL006264:
from=<root@router.pingnu.com>, size=1064, class=0, nrcpts=1,
msgid=<200406160012.i5G0C6Zp006263@router.pingnu.c om>, proto=ESMTP,
daemon=MTA, relay=IDENT:25@localhost [127.0.0.1]

I do not have a user called pingnu but a group called pingnu the time
difference could be he is in France and I am i the UK and my clock is not
set exactly.


Regards Carl Parsons








Reply With Quote