Link to home
Start Free TrialLog in
Avatar of chaseivey
chaseivey

asked on

Logwatch beginning to worry me ?

Hello,
I have linux server running CentOS, Apache, mySQL.
I have an external Cisco firewall, and I currently connect to my server via SSH or Plesk 9.

I have recently reviewed several 'logwatch' emails sent to me from my server.  The content of these emails is beginning to worry me.  There are over a hundred unauthorized attempts at accessing my server with usernames anywhere from 'Bob' to 'madman86'.  I am the ONLY person who even knows about my server, so I'm wondering if these are hacking attempts?  If so, is this normal? Is this something I should worry about? What is the best safeguard against these 'attempts'?
ASKER CERTIFIED SOLUTION
Avatar of upanwar
upanwar
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Avatar of Ernie Beek
Ernie Beek
Flag of Netherlands image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of chaseivey
chaseivey

ASKER

Thanks guys.  I think I'm gonna just limit the ssh access to the 2 places I ever connect.  Sounds like that's my best bet. :)
Think so. There should be a lot less attempts then.