What kind of attack is this?
These showed up in my log last night:
Feb 1 22:06:15 *** login[28361]: FAILED LOGIN 1 FROM **.**.** FOR anao^H^H, User not known to the underlying authentication module
Feb 1 22:06:23 *** login[28361]: FAILED LOGIN 2 FROM **.**.** FOR anonymous, User not known to the underlying authentication module
Feb 1 22:06:34 *** login[28361]: FAILED LOGIN 3 FROM **.**.** FOR seth, User not known to the underlying authentication module
Feb 1 22:06:48 *** login[28361]: FAILED LOGIN SESSION FROM **.**.** FOR es^Hxit, User not known to the underlying authentication module
Feb 1 22:06:23 *** login[28361]: FAILED LOGIN 2 FROM **.**.** FOR anonymous, User not known to the underlying authentication module
Feb 1 22:06:34 *** login[28361]: FAILED LOGIN 3 FROM **.**.** FOR seth, User not known to the underlying authentication module
Feb 1 22:06:48 *** login[28361]: FAILED LOGIN SESSION FROM **.**.** FOR es^Hxit, User not known to the underlying authentication module
As far as I can tell, they never actually made it onto my box. My question is how were they trying to connect. I have very few ports open and those deamons log the daemon name into the log.
TIA,
Frank