13
« on: February 13, 2017, 12:21:16 PM »
While troubleshooting a sys alarm we are getting, I noticed some entries in our syslog as follows.
In looking up these IP's , they seem to be in China, is this some kind of login attack?
Thanks for any insight!
Feb 10 05:36:12 xx-xxxxxxm sshd[11547]: Failed password for root from 122.194.229.3 port 31359 ssh2
Feb 10 05:49:32 xx-xxxxxxm sshd[11597]: Did not receive identification string from 60.169.49.179
Feb 10 05:52:41 xx-xxxxxxm sshd[11611]: Did not receive identification string from 123.31.35.108
Feb 10 05:52:46 xx-xxxxxxm sshd[11615]: error: Could not get shadow information for support
Feb 10 05:52:46 xx-xxxxxxm sshd[11615]: Failed password for support from 123.31.35.108 port 51186 ssh2