Jump to content

FTP "Brute forcer"


Dan M

Recommended Posts

Just checking a few places and noticed FTP login logs, when I checked them they were full of the following.

 

06/04/2009 22:09:36 : Invalid User ID or Password: Administrator/abys IP: 06/04/2009 22:09:36 : Invalid User ID or Password: Administrator/alin IP: 06/04/2009 22:09:37 : Invalid User ID or Password: Administrator/acacia IP: 06/04/2009 22:09:38 : Invalid User ID or Password: Administrator/alin123 IP: 06/04/2009 22:09:38 : Invalid User ID or Password: Administrator/acacius IP: 06/04/2009 22:09:39 : Invalid User ID or Password: Administrator/alina IP: 06/04/2009 22:09:40 : Invalid User ID or Password: Administrator/aline IP: 06/04/2009 22:09:41 : Invalid User ID or Password: Administrator/alisa IP: 06/04/2009 22:09:43 : Invalid User ID or Password: Administrator/academia IP: 06/04/2009 22:09:43 : Invalid User ID or Password: Administrator/alisha.bishop IP: 06/04/2009 22:09:44 : Invalid User ID or Password: Administrator/academic IP: 06/04/2009 22:09:44 : Invalid User ID or Password: Administrator/alison IP: 06/04/2009 22:09:45 : Invalid User ID or Password: Administrator/academie IP: 06/04/2009 22:09:45 : Invalid User ID or Password: Administrator/alissa IP: 06/04/2009 22:09:46 : Invalid User ID or Password: Administrator/aliya IP: 06/04/2009 22:09:46 : Invalid User ID or Password: Administrator/accept IP: 06/04/2009 22:09:47 : Invalid User ID or Password: Administrator/access IP: 06/04/2009 22:09:47 : Invalid User ID or Password: Administrator/aliyah IP: 06/04/2009 22:09:49 : Invalid User ID or Password: Administrator/accord IP: 06/04/2009 22:09:49 : Invalid User ID or Password: Administrator/alka IP:

 

I know none of the passwords are even similar to the massive ones that we use but it still looks like a bit of a flaw.

 

We have all of our security features enabled due to previous brutes through the TCA web interface but it looks like our FTP has been attacked now.

 

We have denied the IP but I thought I'd just let you know about this.

 

I have removed the IP for security purposes.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Terms of Use