What kind of attack is this?

These showed up in my log last night:

Feb 1 22:06:15 *** login[28361]: FAILED LOGIN 1 FROM **.**.** FOR anao^H^H, User not known to the underlying authentication module
Feb 1 22:06:23 *** login[28361]: FAILED LOGIN 2 FROM **.**.** FOR anonymous, User not known to the underlying authentication module
Feb 1 22:06:34 *** login[28361]: FAILED LOGIN 3 FROM **.**.** FOR seth, User not known to the underlying authentication module
Feb 1 22:06:48 *** login[28361]: FAILED LOGIN SESSION FROM **.**.** FOR es^Hxit, User not known to the underlying authentication module
(I've **'ed out certain details).

As far as I can tell, they never actually made it onto my box. My question is how were they trying to connect. I have very few ports open and those deamons log the daemon name into the log.

TIA,

Frank

 

 

 

 

Top