Bonjour a tous,
Je viens de recevoir par mail un truc sympa comme ca:
[i]To whom it may concern.
We have detected a hack attempt originating from your network from ip: ns1.yourdomain.com
This suggests that the above server has been compromised and is a participant in a botnet.
This means that this server has been hacked and now, in turn, is attempting to hack other servers on the Internet.
This IP address has now been blacklisted to protect our service from further brute force attacks. Furthermore, this IP address has been uploaded to the DenyHosts database. This means that this IP address will also shortly be blacklisted by all DenyHosts members who query this central database.
An excerpt from our logfiles. All times shown are in GMT:
Apr 7 07:51:50 [sshd] error: PAM: Authentication failure for root from ns1.distribatinfo.com
Apr 7 07:51:50 [sshd] error: PAM: Authentication failure for root from ns1.distribatinfo.com
Apr 7 07:51:50 [sshd] error: PAM: Authentication failure for root from ns1.yourdomain.com[/i]
Le probleme est que je n’ai rien vu dans mes logs qui pourrait ressembler a du hacking, donc pour faire la verification de ce mail, j’aimerais ssavoir si il est possible de faire une verification des logs sortant de mon serveur.
Ou alors, si vous avez une autre idee, elle est la bienvenue.
merci par avance
JP