So I have fail2ban working I noticed something odd. I have SSH locked down to just a few IPs but I noticed someone trying to hack in via SSH. Here is a snip from my secure log.
Mar 18 00:18:14 ns1 sshd[15416]: Failed password for root from 116.10.191.164 port 3003 ssh2
Mar 18 00:18:14 ns1 unix_chkpwd[15426]: password check failed for user (root)
Mar 18 00:18:14 ns1 sshd[15416]: Unable to connect to Plesk Database: Can't connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (13)
Mar 18 00:18:15 ns1 sshd[15418]: Failed password for root from 116.10.191.164 port 1362 ssh2
Mar 18 00:18:15 ns1 unix_chkpwd[15427]: password check failed for user (root)
Mar 18 00:18:15 ns1 sshd[15418]: Unable to connect to Plesk Database: Can't connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (13)
Mar 18 00:18:16 ns1 sshd[15416]: Failed password for root from 116.10.191.164 port 3003 ssh2
Mar 18 00:18:16 ns1 unix_chkpwd[15428]: password check failed for user (root)
Mar 18 00:18:16 ns1 sshd[15416]: Unable to connect to Plesk Database: Can't connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (13)
Mar 18 00:18:17 ns1 sshd[15418]: Failed password for root from 116.10.191.164 port 1362 ssh2
Mar 18 00:18:18 ns1 unix_chkpwd[15429]: password check failed for user (root)
Mar 18 00:18:18 ns1 sshd[15418]: Unable to connect to Plesk Database: Can't connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (13)
Mar 18 00:18:18 ns1 sshd[15416]: Failed password for root from 116.10.191.164 port 3003 ssh2
Mar 18 00:18:18 ns1 unix_chkpwd[15430]: password check failed for user (root)
Mar 18 00:18:18 ns1 sshd[15416]: Unable to connect to Plesk Database: Can't connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (13)
Mar 18 00:18:19 ns1 sshd[15418]: Failed password for root from 116.10.191.164 port 1362 ssh2
Mar 18 00:18:20 ns1 sshd[15416]: Failed password for root from 116.10.191.164 port 3003 ssh2
Odd that I am seeing different ports and I am unsure how they are trying to hack in. Does anyone have any ideas?
BTW fail2ban is a must... I hope it makes it into Plesk 12.
Mar 18 00:18:14 ns1 sshd[15416]: Failed password for root from 116.10.191.164 port 3003 ssh2
Mar 18 00:18:14 ns1 unix_chkpwd[15426]: password check failed for user (root)
Mar 18 00:18:14 ns1 sshd[15416]: Unable to connect to Plesk Database: Can't connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (13)
Mar 18 00:18:15 ns1 sshd[15418]: Failed password for root from 116.10.191.164 port 1362 ssh2
Mar 18 00:18:15 ns1 unix_chkpwd[15427]: password check failed for user (root)
Mar 18 00:18:15 ns1 sshd[15418]: Unable to connect to Plesk Database: Can't connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (13)
Mar 18 00:18:16 ns1 sshd[15416]: Failed password for root from 116.10.191.164 port 3003 ssh2
Mar 18 00:18:16 ns1 unix_chkpwd[15428]: password check failed for user (root)
Mar 18 00:18:16 ns1 sshd[15416]: Unable to connect to Plesk Database: Can't connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (13)
Mar 18 00:18:17 ns1 sshd[15418]: Failed password for root from 116.10.191.164 port 1362 ssh2
Mar 18 00:18:18 ns1 unix_chkpwd[15429]: password check failed for user (root)
Mar 18 00:18:18 ns1 sshd[15418]: Unable to connect to Plesk Database: Can't connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (13)
Mar 18 00:18:18 ns1 sshd[15416]: Failed password for root from 116.10.191.164 port 3003 ssh2
Mar 18 00:18:18 ns1 unix_chkpwd[15430]: password check failed for user (root)
Mar 18 00:18:18 ns1 sshd[15416]: Unable to connect to Plesk Database: Can't connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (13)
Mar 18 00:18:19 ns1 sshd[15418]: Failed password for root from 116.10.191.164 port 1362 ssh2
Mar 18 00:18:20 ns1 sshd[15416]: Failed password for root from 116.10.191.164 port 3003 ssh2
Odd that I am seeing different ports and I am unsure how they are trying to hack in. Does anyone have any ideas?
BTW fail2ban is a must... I hope it makes it into Plesk 12.