I've always had usernames when it comes to sshd's log entries in auth.log, like the following:
<time> <hostname> sshd[5926]: error: PAM: Authentication failure for <username> from <ip-adress> On 3/19/09, Paul Hartman <paul.hartman+gen...@gmail.com> wrote: > In my ssh logs this morning I noticed a couple login attempts with > usenames on them... I've never seen that before. It is usually just an > IP address. > > Mar 18 20:19:48 [sshd] refused connect from > postmas...@dns.cablecentro.net.co > Mar 18 23:42:44 [sshd] refused connect from 211.116.136.107 > Mar 18 23:44:44 [sshd] refused connect from > [u2fsdgvkx19g32yzvkmsqkl+mouwitiloicy4iq9oq...@211.116.136.107 > Mar 19 02:41:09 [sshd] refused connect from 221.194.128.66 > > weird... maybe the bad guys are up to something new. > > -- ------------------------------------------------ For security reasons, all text in this mail is double-rot13 encrypted.