CentOS6 – Break In Attempt? What Is The Exploit?

Home » General » CentOS6 – Break In Attempt? What Is The Exploit?
General No Comments

Yes, we run fail2ban. No, fail2ban did not catch this because the number of attempts was below the threshold for a single IP.

The logwatch message reported is incomplete. Our address was the destination address. The source address was not reported by logwatch but it was logged in the syslog and it was not an internal address. It did belong to an organisation that bills itself as “a leader in enterprise security. . .”.

We have contacted them requesting an explanation of the probe. It could have been an error on someone’s part. I suppose.

We see a lot of cracker traffic from Chile, Romania, Russia and the Ukraine. China was such a PITA that eventually we simply cut off that range of addresses from reaching us by any ports other than 25/80/443
so we do not even see it any more, except via proxy. Taiwan is nearly in the same boat and Vietnam is next in the queue.