Receiving ssh root login alerts with no ssh root login
Posted: 08 Oct 2012, 20:39
Hi there -
My servers are setup to only allow ssh by root. These alerts work fine with actual root logins but I've also gotten a couple of alerts with no evidence of an actual ssh/root login -
lfd on server.servername.com: SSH login alert for user root from 62.212.154.143 (NL/Netherlands/www.digiinfo.nl)
When I parse /var/log/secure for this IP, there are no log entries. When I parse /var/log/secure for "Accepted" to view successful logins, I see nothing other than my own successful root ssh logins and nothing that doesn't belong.
What would be causing the false positives? Which log does CSF parse for ssh login alerts and what specific string is it alerting on?
Thanks.
Mike
My servers are setup to only allow ssh by root. These alerts work fine with actual root logins but I've also gotten a couple of alerts with no evidence of an actual ssh/root login -
lfd on server.servername.com: SSH login alert for user root from 62.212.154.143 (NL/Netherlands/www.digiinfo.nl)
When I parse /var/log/secure for this IP, there are no log entries. When I parse /var/log/secure for "Accepted" to view successful logins, I see nothing other than my own successful root ssh logins and nothing that doesn't belong.
What would be causing the false positives? Which log does CSF parse for ssh login alerts and what specific string is it alerting on?
Thanks.
Mike