FTP Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationFTP Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old March 7th, 2003, 08:31 PM
(jp)'s Avatar
(jp) (jp) is offline
/dev/null Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 2002
Posts: 34 (jp) User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 48 sec
Reputation Power: 7
anonFTP hack?

What is this guy trying to do?

Quote:
host (172.130.30.145[172.130.30.145]) - FTP session opened.
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - FTP session closed.
host (172.130.30.145[172.130.30.145]) - FTP session opened.
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - FTP session closed.
host (172.130.30.145[172.130.30.145]) - FTP session opened.
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - FTP session closed.
host (172.130.30.145[172.130.30.145]) - FTP session opened.
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - no such user 'anonymous'
host (172.130.30.145[172.130.30.145]) - FTP session closed.


Anyway to monitor this or block this IP?

Reply With Quote
  #2  
Old March 10th, 2003, 03:58 AM
Battery Powered Battery Powered is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2003
Posts: 161 Battery Powered User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 6 h 3 m 57 sec
Reputation Power: 6
Hes just trying to log onto the ftp server without a valid username or password, as your log shows, anonymous access isnt allowed on the server so he hasnt been getting in
So nothing here really to worry about,

If you really want to block him you can do but he could be on a dynamic IP so if he comes back a day or two later trying to login then his IP could be different and your block will be useless

Hes not getting in with an anymous account so nothing to worry about, just look through and make sure hes not trying to get in (with same IP) using other account names, example - look for

host (172.130.30.145[172.130.30.145]) - no such user 'fred'

If you start seeing thigs such as that, and if there are a large number of them then you might want to think about taking action cause he could be trying a brute force attack to try and get a valid un/pwd combo
One way to make this hard for him is to make sure none of the accounts on the ftp server have weak username and passwd combinations - set a minimum character lenght on aco**** creation and try and get people to use upper/lowercase mix aswell as numbers and other misc characters

All the best

Reply With Quote
  #3  
Old March 10th, 2003, 07:23 AM
(jp)'s Avatar
(jp) (jp) is offline
/dev/null Member
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 2002
Posts: 34 (jp) User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 48 sec
Reputation Power: 7
Thanks for the info.. Is there a way to issue a "timeout" period for someone with too many failures?

For example, I found this guy today:
Quote:
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session opened.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.
host (62.118.53.22[62.118.53.22]) - FTP session closed.


Sorry for all the text, just wanted to make the point. Seems like brute force to me. If I could set a temporary time-out period for say, an hour, after "x" number of failed attempts, I think that could help.

-jp

Reply With Quote
  #4  
Old March 10th, 2003, 01:58 PM
Battery Powered Battery Powered is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2003
Posts: 161 Battery Powered User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 6 h 3 m 57 sec
Reputation Power: 6
You can normally tell a brute force from the time stamps, if there all rediculasly close together and theres a big list like the one above (well normally bigger) then you can tell its a brute attack

As to the timeout question, not sure what ftp server software your using, but this is something that is possible

What ftp software are you using ?

Also, turning on timestamps in your config might help figure out if it is actually a brute force or just someone who has a real problem remembering there password : )

(if you run a large server (with alot of users) these timestamps will increase log file sizes so take this into account, if it is a big server you might just want to enable timestamps just for a day or so for monitoring purposes)

All the best

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationFTP Help > anonFTP hack?


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 2 hosted by Hostway
Stay green...Green IT