RE: failed ssh breakins on my exposed www box ..

2002-03-26 Thread Howland, Curtis
I'm impressed. Even here in Tokyo, where "a cop on ever street corner" is not just an Orwellian slur, the only people who get that kind of service are the ones who directly pay their salaries. Seriously, the only person you can rely on is you. You're the one on the scene, be it a mugging or a c

RE: failed ssh breakins on my exposed www box ..

2002-03-26 Thread Howland, Curtis
I'm impressed. Even here in Tokyo, where "a cop on ever street corner" is not just an Orwellian slur, the only people who get that kind of service are the ones who directly pay their salaries. Seriously, the only person you can rely on is you. You're the one on the scene, be it a mugging or a

RE: failed ssh breakins on my exposed www box ..

2002-03-25 Thread Gary MacDougall
@lists.debian.org Subject: Re: failed ssh breakins on my exposed www box .. On Mon, Mar 25, 2002 at 04:50:17PM -0500, Gary MacDougall wrote: > Agreed. > I'll never understand why people will let "crackers" reap havoc > on a network without issue, but if someone comes up and

Re: failed ssh breakins on my exposed www box ..

2002-03-25 Thread Petro
On Mon, Mar 25, 2002 at 04:50:17PM -0500, Gary MacDougall wrote: > Agreed. > I'll never understand why people will let "crackers" reap havoc > on a network without issue, but if someone comes up and tries > to break into my house, the police will be there in 2 seconds. Hate to break it to you,

Re: failed ssh breakins on my exposed www box ..

2002-03-25 Thread Joe
Yes, I've had a person that I had a judgement against change jobs once the papers were in to start taking money from his paycheck. The only thing is that I know until he pays up what the court says, he has to change jobs every 6 months. Is going to court for everyone? No, its up to you to decid

RE: failed ssh breakins on my exposed www box ..

2002-03-25 Thread Gary MacDougall
onday, March 25, 2002 4:43 PM To: andreas mayer; Gary MacDougall; debian-security@lists.debian.org Subject: Re: failed ssh breakins on my exposed www box .. >I think the net is freedom, and that is good... That is the silliest thing I have ever heard. So what you are saying is that any

Re: failed ssh breakins on my exposed www box ..

2002-03-25 Thread Langdon Green
- Original Message - From: "andreas mayer" <[EMAIL PROTECTED]> To: "Gary MacDougall" <[EMAIL PROTECTED]>; Sent: Monday, March 25, 2002 4:24 AM Subject: Re: failed ssh breakins on my exposed www box .. > > We seriouslly need a US branch of the law-enfor

RE: failed ssh breakins on my exposed www box ..

2002-03-25 Thread Gary MacDougall
PROTECTED] Subject: Re: failed ssh breakins on my exposed www box .. On Mon, Mar 25, 2002 at 04:50:17PM -0500, Gary MacDougall wrote: > Agreed. > I'll never understand why people will let "crackers" reap havoc > on a network without issue, but if someone comes up and tries >

Re: failed ssh breakins on my exposed www box ..

2002-03-25 Thread Petro
On Mon, Mar 25, 2002 at 04:50:17PM -0500, Gary MacDougall wrote: > Agreed. > I'll never understand why people will let "crackers" reap havoc > on a network without issue, but if someone comes up and tries > to break into my house, the police will be there in 2 seconds. Hate to break it to you

Re: failed ssh breakins on my exposed www box ..

2002-03-25 Thread Joe
Yes, I've had a person that I had a judgement against change jobs once the papers were in to start taking money from his paycheck. The only thing is that I know until he pays up what the court says, he has to change jobs every 6 months. Is going to court for everyone? No, its up to you to deci

RE: failed ssh breakins on my exposed www box ..

2002-03-25 Thread Gary MacDougall
: Monday, March 25, 2002 4:43 PM To: andreas mayer; Gary MacDougall; [EMAIL PROTECTED] Subject: Re: failed ssh breakins on my exposed www box .. >I think the net is freedom, and that is good... That is the silliest thing I have ever heard. So what you are saying is that any kiddy/profes

Re: failed ssh breakins on my exposed www box ..

2002-03-25 Thread Langdon Green
- Original Message - From: "andreas mayer" <[EMAIL PROTECTED]> To: "Gary MacDougall" <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]> Sent: Monday, March 25, 2002 4:24 AM Subject: Re: failed ssh breakins on my exposed www box .. > > We seriouslly need a

Re: failed ssh breakins on my exposed www box ..

2002-03-25 Thread Kenneth Pronovici
> Does this work? Going to civil court against a cracker? YES. It > comes down to: > > Do you have the time to wait for a result or lawsuit? > Do you know or have a lawyer that is net-smart or willing to learn? > Do you have the start-up money for the lawsuit? (at least > $1,000-$5000) Sorry to

Re: failed ssh breakins on my exposed www box ..

2002-03-25 Thread Joe
You do have another option, sue them in Civil court. Just because someone tries to break into your computer does not mean that you have to go to the Feds in order to get anything done, you can take them to civil court and sue them. Granted, this is a long process, you must have a good lawyer tha

Re: failed ssh breakins on my exposed www box ..

2002-03-25 Thread Kenneth Pronovici
> Does this work? Going to civil court against a cracker? YES. It > comes down to: > > Do you have the time to wait for a result or lawsuit? > Do you know or have a lawyer that is net-smart or willing to learn? > Do you have the start-up money for the lawsuit? (at least > $1,000-$5000) Sorry t

Re: failed ssh breakins on my exposed www box ..

2002-03-25 Thread Joe
You do have another option, sue them in Civil court. Just because someone tries to break into your computer does not mean that you have to go to the Feds in order to get anything done, you can take them to civil court and sue them. Granted, this is a long process, you must have a good lawyer th

Re: failed ssh breakins on my exposed www box ..

2002-03-25 Thread Blars Blarson
In article <[EMAIL PROTECTED]> [EMAIL PROTECTED] writes: >What's the best way to figure >out the admin for a subnet from a machine's IP? As others have pointed out, whois is the normal tool to do it, but they forgot to mention the complexities you get with servers pointing to each other and somet

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Blars Blarson
In article <[EMAIL PROTECTED]> [EMAIL PROTECTED] writes: >What's the best way to figure >out the admin for a subnet from a machine's IP? As others have pointed out, whois is the normal tool to do it, but they forgot to mention the complexities you get with servers pointing to each other and some

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Petro
On Sun, Mar 24, 2002 at 07:24:18PM +0100, andreas mayer wrote: > > We seriouslly need a US branch of the law-enforcement to deal > > with this sort of stuff. ?I think if more people got prosecuted for > > trying to crack into a site, the level of BS would drop to zero. > Yeah! And what if the atta

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Petro
On Sun, Mar 24, 2002 at 12:28:17PM -0500, timothy bauscher wrote: > > We seriouslly need a US branch of the law-enforcement to deal > > with this sort of stuff. > I respect your opinion, but i would hate to > have a new branch of government wasting my > tax dollars. If these types of "attacks" can

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Petro
On Sun, Mar 24, 2002 at 07:24:18PM +0100, andreas mayer wrote: > > We seriouslly need a US branch of the law-enforcement to deal > > with this sort of stuff. ?I think if more people got prosecuted for > > trying to crack into a site, the level of BS would drop to zero. > Yeah! And what if the att

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Petro
On Sun, Mar 24, 2002 at 12:28:17PM -0500, timothy bauscher wrote: > > We seriouslly need a US branch of the law-enforcement to deal > > with this sort of stuff. > I respect your opinion, but i would hate to > have a new branch of government wasting my > tax dollars. If these types of "attacks" can

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Martin WHEELER
Feeding the trolls in this pen is inadvisable. -- Martin Wheeler <[EMAIL PROTECTED]> gpg key 01269BEB @ the.earth.li -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Gary MacDougall
> > We seriouslly need a US branch of the law-enforcement to deal > > with this sort of stuff. I think if more people got prosecuted for > > trying to crack into a site, the level of BS would drop to zero. > > Yeah! And what if the attacker is from a other country? > You cannot just bomb 'em for t

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Martin WHEELER
Feeding the trolls in this pen is inadvisable. -- Martin Wheeler <[EMAIL PROTECTED]> gpg key 01269BEB @ the.earth.li -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread andreas mayer
> We seriouslly need a US branch of the law-enforcement to deal > with this sort of stuff.  I think if more people got prosecuted for > trying to crack into a site, the level of BS would drop to zero. Yeah! And what if the attacker is from a other country? You cannot just bomb 'em for terrorist a

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Anne Carasik
t;shiftee" <[EMAIL PROTECTED]> > To: > Sent: Sunday, March 24, 2002 11:35 AM > Subject: Re: failed ssh breakins on my exposed www box .. > > > > Hi, > > > > To find out who owns the IP block you can do 'whois -h whois.arin.net > '. > > >

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Gary MacDougall
> > We seriouslly need a US branch of the law-enforcement to deal > > with this sort of stuff. I think if more people got prosecuted for > > trying to crack into a site, the level of BS would drop to zero. > > Yeah! And what if the attacker is from a other country? > You cannot just bomb 'em for

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread timothy bauscher
> We seriouslly need a US branch of the law-enforcement to deal > with this sort of stuff. I respect your opinion, but i would hate to have a new branch of government wasting my tax dollars. If these types of "attacks" can be stopped on the software side, than that be much more effective than gove

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Noah L. Meyerhans
On Sun, Mar 24, 2002 at 11:44:26AM -0500, Gary MacDougall wrote: > We seriouslly need a US branch of the law-enforcement to deal > with this sort of stuff. I think if more people got prosecuted for > trying to crack into a site, the level of BS would drop to zero. Sure, but this particular attemp

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Gary MacDougall
ng ticket... g. - Original Message - From: "shiftee" <[EMAIL PROTECTED]> To: Sent: Sunday, March 24, 2002 11:35 AM Subject: Re: failed ssh breakins on my exposed www box .. > Hi, > > To find out who owns the IP block you can do 'whois -h whois.arin.net &#

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Lionel Elie Mamane
On Sun, Mar 24, 2002 at 08:01:04AM -0800, Stephen Hassard wrote: > What's the best way to figure out the admin for a subnet from a > machine's IP? whois the_ip_adress -- Lionel Mamane pgpMU0pdcNCQO.pgp Description: PGP signature

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread shiftee
Hi, To find out who owns the IP block you can do 'whois -h whois.arin.net '. I don't think reporting it would achieve anything, just a friendly warning from the ISP to the user in question. On Sun, Mar 24, 2002 at 08:01:04AM -0800, Stephen Hassard wrote: > sorta what I figured, but it was a pret

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Stephen Hassard
sorta what I figured, but it was a pretty half assed attempt. :P on a side note, are these typically worth reporting to the ISP of the attacker? I tried doing a DNS lookup on the box in question, but it doesn't seem to have an FDQN registered. What's the best way to figure out the admin for a

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread andreas mayer
> We seriouslly need a US branch of the law-enforcement to deal > with this sort of stuff.  I think if more people got prosecuted for > trying to crack into a site, the level of BS would drop to zero. Yeah! And what if the attacker is from a other country? You cannot just bomb 'em for terrorist

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Anne Carasik
iftee" <[EMAIL PROTECTED]> > To: <[EMAIL PROTECTED]> > Sent: Sunday, March 24, 2002 11:35 AM > Subject: Re: failed ssh breakins on my exposed www box .. > > > > Hi, > > > > To find out who owns the IP block you can do 'whois -h whois.arin.

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread shiftee
It just looks like someone is trying to brute-force an account, I'm sure there are plenty of places that provide tools for this. Just make sure you enforce secure passwords, and keep an eye on your syslog. On Sun, Mar 24, 2002 at 07:11:25AM -0800, Stephen Hassard wrote: > Hi there, > > I found t

failed ssh breakins on my exposed www box ..

2002-03-24 Thread Stephen Hassard
Hi there, I found these in my event log from yesterday: >>> Mar 23 09:33:16 www sshd[10998]: input_userauth_request: illegal user www Mar 23 09:33:18 www sshd[10998]: Failed none for illegal user www from 213.26.96.103 port 2276 ssh2 Mar 23 09:33:18 www sshd[10998]: Failed keyboard-interactive

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread timothy bauscher
> We seriouslly need a US branch of the law-enforcement to deal > with this sort of stuff. I respect your opinion, but i would hate to have a new branch of government wasting my tax dollars. If these types of "attacks" can be stopped on the software side, than that be much more effective than gov

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Noah L. Meyerhans
On Sun, Mar 24, 2002 at 11:44:26AM -0500, Gary MacDougall wrote: > We seriouslly need a US branch of the law-enforcement to deal > with this sort of stuff. I think if more people got prosecuted for > trying to crack into a site, the level of BS would drop to zero. Sure, but this particular attem

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Gary MacDougall
ng ticket... g. - Original Message - From: "shiftee" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Sunday, March 24, 2002 11:35 AM Subject: Re: failed ssh breakins on my exposed www box .. > Hi, > > To find out who owns the IP block you can do 'whois

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Lionel Elie Mamane
On Sun, Mar 24, 2002 at 08:01:04AM -0800, Stephen Hassard wrote: > What's the best way to figure out the admin for a subnet from a > machine's IP? whois the_ip_adress -- Lionel Mamane msg06057/pgp0.pgp Description: PGP signature

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread shiftee
Hi, To find out who owns the IP block you can do 'whois -h whois.arin.net '. I don't think reporting it would achieve anything, just a friendly warning from the ISP to the user in question. On Sun, Mar 24, 2002 at 08:01:04AM -0800, Stephen Hassard wrote: > sorta what I figured, but it was a pre

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Stephen Hassard
sorta what I figured, but it was a pretty half assed attempt. :P on a side note, are these typically worth reporting to the ISP of the attacker? I tried doing a DNS lookup on the box in question, but it doesn't seem to have an FDQN registered. What's the best way to figure out the admin for a

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread shiftee
It just looks like someone is trying to brute-force an account, I'm sure there are plenty of places that provide tools for this. Just make sure you enforce secure passwords, and keep an eye on your syslog. On Sun, Mar 24, 2002 at 07:11:25AM -0800, Stephen Hassard wrote: > Hi there, > > I found

failed ssh breakins on my exposed www box ..

2002-03-24 Thread Stephen Hassard
Hi there, I found these in my event log from yesterday: >>> Mar 23 09:33:16 www sshd[10998]: input_userauth_request: illegal user www Mar 23 09:33:18 www sshd[10998]: Failed none for illegal user www from 213.26.96.103 port 2276 ssh2 Mar 23 09:33:18 www sshd[10998]: Failed keyboard-interactive