Look what I found out on my server today:
netstat -p
Active Internet connections (w/o servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 192.168.*.*:60416 quakenet.euroserv.com:ircd ESTABLISHED 2630/crond
tcp 0 0 192.168.*.*:41016 clanserver4u.de.quaken:ircd ESTABLISHED 2630/crond
This is something you *DO NOT* wanna see on your server.
Yesterday I set up an account for a friend just to upload me some files on the ftp. The password was weak as I thought I would delete the acount inmediatly afterwards but...I forgot to!
And in one day time someone already broke into my machine and set a cron job to start this "conncection" or whatever. First of all I'm gonna clean up this mess and then I'll try to dig into the logs and find out where this attack come from.
Oct 19 22:40:43 laurelin sshd[5688]: Accepted password for esteban from port 54790 ssh2
Oct 19 20:10:14 laurelin sshd[13002]: Accepted password for esteban from port 10060 ssh2
Oct 19 20:11:37 laurelin sshd[13226]: Failed password for root from port 19205 ssh2
There he is! And he is up and running:
Starting Nmap 5.21 ( http://nmap.org ) at 2010-10-21 03:23 CEST
Nmap scan report for (
Host is up (0.069s latency).
Not shown: 989 closed ports
21/tcp open ftp
22/tcp open ssh
23/tcp open telnet
80/tcp open http
1720/tcp filtered H.323/Q.931
1863/tcp open msnp
1864/tcp open paradym-31
4443/tcp open pharos
4662/tcp filtered edonkey
5190/tcp open aol
5566/tcp open unknown
Nmap done: 1 IP address (1 host up) scanned in 8.99 seconds
Starting Nmap 5.21 ( http://nmap.org ) at 2010-10-21 03:24 CEST
Nmap scan report for
Host is up (0.36s latency).
Not shown: 983 closed ports
22/tcp open ssh
25/tcp open smtp
80/tcp open http
110/tcp open pop3
111/tcp open rpcbind
443/tcp open https
445/tcp filtered microsoft-ds
995/tcp open pop3s
1720/tcp filtered H.323/Q.931
1863/tcp open msnp
3306/tcp open mysql
4444/tcp filtered krb524
5190/tcp open aol
5989/tcp open unknown
8000/tcp open http-alt
8443/tcp open https-alt
11111/tcp open unknown