Warning: Major Hacker

USHost247

Madly Diligent
Joined
Jul 8, 2009
Messages
8,102
Reaction score
1,036
FP$
5,440
Warning Users of FP,

A user by the IP address of 125.85.141.224

They have gained access to SSH on my server but they done no harm and all data is secure. IP permanently blocked and my providers have been contacted about this. All their accounts have been deleted/terminated. Also we have done some security tweaks on our firewall and all IPs will be perm banned for only 1 failed login to our root/ssh. Security is our #1 goal.

I want everyone to be aware of this.

Email: [email protected]
Time: Wed Mar 24 02:10:08 2010 -0400
IP: 125.85.141.224 (CN/China/-)
Account: meluweho
Method: password authentication
 
It's an IP located in China most likely, and probably a bot. Not very surprising.
 
Yeah, it's possibly a bot but it's one that was successful and should be warned to others who do hosting as well so they can jump the gun on it. 🙂
 
ChrisG2010 said:
Also we have done some security tweaks on our firewall and all IPs will be perm banned for only 1 failed login to our root/ssh.
Is this for client accounts or just your account? If it is client accounts, I think it is slight overkill.
 
The security is in affect for all accounts. If you have an account with us, don't be alarmed, just be sure not to fail your logins as we have lowered the amount of tries to login before being locked out. Also, we have installed more firewalls and a virus scanner. If you get locked out by out hardened firewall, just let me know.
 
I perform major backups for my clients but i'll warn them.
 
=o

1. Hacking saga by China people last time in a game that I played.
2. Hacking SSH...?
 
It is most likely a bot or they are using a fake IP address. Any smart hacker will never use their own IP, they will always make sure they are hidden so they it will be hard for them to get caught.
 
Back
Top Bottom