Hi
My sites were runing fine but i use mysqlcc via putty to connect and maintain the mysql databases and found suddenly i could not connect. logged into webmin and found there also i could not do any changes to the mysql server. the password for the root mysql user had been reset. The password had to be reset and i am back to normal now.
Can this normally happen or is this a definate hack job.
I run freebsd 5.4, php5, apache2 the latest one, mysql 4something latest again, have hostsentry and portsentry set up , no firewall though, apache and mysql are run by separate users and not by root.
how can i find out if i have been hacked
ran chkroot and passed with flying colours.
My var/logs seems ok nothing that i coudl see but if somebody can tell me what to look for it would make things easier.
Is there a list of things I can do to find out if I have been hacked........... .
Also script kiddies have been having a go
Aug 6 09:19:01 xxxx sshd[56099]: Failed password for root from x.x.x.x port
2116 ssh2
Aug 6 09:22:06 xxxx sshd[56163]: Failed password for root from x.x.x.x port
2133 ssh2
Aug 6 09:37:22 xxxx sshd[56310]: Failed keyboard-interactive/pam for root from
82.33.42.128 port 2221 ssh2
Aug 6 15:46:44 xxxx sshd[60581]: Failed password for root from x.x.x.x port
3502 ssh2
Aug 6 15:46:48 xxxx sshd[60583]: Failed password for illegal user jack from 82.100.0.62
port 3624 ssh2
Aug 6 15:46:53 xxxx sshd[60585]: Failed password for root from 82.100.0.62 port
3825 ssh2
Aug 6 15:46:54 xxxx sshd[60587]: Failed password for illegal user alin from 82.100.0.62
port 4067 ssh2
Aug 6 15:46:56 xxxx sshd[60589]: Failed password for illegal user alin from 82.100.0.62
port 4135 ssh2
Aug 6 15:51:17 xxxx sshd[60621]: Failed password for illegal user andrew from 82.100.0.62
port 4868 ssh2
Aug 6 17:14:21 xxxx sshd[61071]: Failed password for root from 82.100.0.62 port
4903 ssh2
Aug 6 19:50:34 xxxx sshd[61826]: reverse mapping checking getaddrinfo for sv.tvcm.ch
failed - POSSIBLE BREAKIN ATTEMPT!
Aug 6 19:50:34 xxxx sshd[61826]: Failed password for illegal user 111 from 61.206.38.7
port 49677 ssh2
Aug 6 19:50:36 xxxx sshd[61828]: reverse mapping checking getaddrinfo for sv.tvcm.ch
failed - POSSIBLE BREAKIN ATTEMPT!
Aug 6 19:50:36 xxxx sshd[61828]: Failed password for illegal user 222 from 61.206.38.7
port 49787 ssh2
Aug 6 19:50:38 xxxx sshd[61830]: reverse mapping checking getaddrinfo for sv.tvcm.ch
failed - POSSIBLE BREAKIN ATTEMPT!
Aug 6 19:50:38 xxxx sshd[61830]: Failed password for illegal user 333 from 61.206.38.7
port 49862 ssh2
Aug 6 19:50:40 xxxx sshd[61832]: reverse mapping checking getaddrinfo for sv.tvcm.ch
failed - POSSIBLE BREAKIN ATTEMPT!
Aug 6 19:50:40 xxxx sshd[61832]: Failed password for illegal user 444 from 61.206.38.7
port 49934 ssh2
Aug 6 19:50:41 xxxx sshd[61834]: reverse mapping checking getaddrinfo for sv.tvcm.ch
failed - POSSIBLE BREAKIN ATTEMPT!
Aug 6 19:50:42 xxxx sshd[61834]: Failed password for illegal user 555 from 61.206.38.7
port 50007 ssh2
Aug 6 19:50:43 xxxx sshd[61836]: reverse mapping checking getaddrinfo for sv.tvcm.ch
failed - POSSIBLE BREAKIN ATTEMPT!
Aug 6 19:50:43 xxxx sshd[61836]: Failed password for illegal user 666 from 61.206.38.7
port 50084 ssh2
Aug 6 19:50:45 xxxx sshd[61838]: reverse mapping checking getaddrinfo for sv.tvcm.ch
failed - POSSIBLE BREAKIN ATTEMPT!
Aug 6 19:50:45 xxxx sshd[61838]: Failed password for illegal user 777 from 61.206.38.7
port 50156 ssh2
Aug 6 19:50:47 xxxx sshd[61840]: reverse mapping checking getaddrinfo for sv.tvcm.ch
failed - POSSIBLE BREAKIN ATTEMPT!
Aug 6 19:50:47 xxxx sshd[61840]: Failed password for illegal user 888 from 61.206.38.7
port 50226 ssh2
Aug 6 19:50:49 xxxx sshd[61842]: reverse mapping checking getaddrinfo for sv.tvcm.ch
failed - POSSIBLE BREAKIN ATTEMPT!
Aug 6 19:50:49 xxxx sshd[61842]: Failed password for illegal user 999 from 61.206.38.7
port 50295 ssh2
Aug 6 19:50:50 xxxx sshd[61844]: reverse mapping checking getaddrinfo for sv.tvcm.ch
failed - POSSIBLE BREAKIN ATTEMPT!
Aug 6 19:50:50 xxxx sshd[61844]: Failed password for illegal user Aaron from 61.206.38.7
port 50373 ssh2
Aug 6 19:50:52 xxxx sshd[61846]: reverse mapping checking getaddrinfo for sv.tvcm.ch
failed - POSSIBLE BREAKIN ATTEMPT!
Aug 6 19:50:52 xxxx sshd[61846]: Failed password for illegal user Abdullah from
61.206.38.7 port 50452 ssh2
Aug 6 19:50:54 xxxx sshd[61848]: reverse mapping checking getaddrinfo for sv.tvcm.ch
failed - POSSIBLE BREAKIN ATTEMPT!
Aug 6 19:50:54 xxxx sshd[61848]: Failed password for illegal user Account from
61.206.38.7 port 50521 ssh2
Aug 6 19:50:56 xxxx sshd[61850]: reverse mapping checking getaddrinfo for sv.tvcm.ch
failed - POSSIBLE BREAKIN ATTEMPT!
Aug 6 19:50:56 xxxx sshd[61850]: Failed password for illegal user Ackerman from
61.206.38.7 port 50597 ssh2
Aug 6 19:50:58 xxxx sshd[61852]: reverse mapping checking getaddrinfo for sv.tvcm.ch
failed - POSSIBLE BREAKIN ATTEMPT!
Also if you chaps could explain what type of breakin attempts they are and their changes of success.
I login with webmin using a https secure channel, and use putty via port 22 using ssh2 to login and so with cuteftp pro have a private and public key when i log in. I login as root which is not recommend but will change that soon.
thanks for the help
Start Free Trial