SSH keeps restarting - possible hacking attempts?
I'm getting emails everyday non-stop.... am I being hacked? I don't have SSH on port 22, but I still get this.System integrity monitor on linux.mydomain.com has taken action in responce to an event. Recent event logs are enclosed below for your inspection. There has been 10 events today, if an average of 8 events is reached, e-mail alerts will be terminated for the duration of the day.
- Events Summary:
Total event count: 10
Average event count: 1
- Service Summary:
HTTP [online - 0 events]
DNS [online - 0 events]
SSH [restarted - 10 events]
MYSQL [online - 0 events]
SMTP [online - 0 events]
XINET [online - 0 events]
- System Summary:
LOAD [0.60 - status good - 0 events]
- SIM Log:
[03/06/05 00:40:00]: HTTP service is online.
[03/06/05 00:40:00]: DNS service is online.
[03/06/05 00:40:00]: SSH service is offline.
[03/06/05 00:40:00]: Restarted SSH service (9 SSH events today).
[03/06/05 00:40:00]: MYSQL service is online.
[03/06/05 00:40:00]: XINET service is online.
[03/06/05 00:40:00]: SMTP service is online.
[03/06/05 00:45:00]: LOAD 0.60 (status good)
[03/06/05 00:45:00]: HTTP service is online.
[03/06/05 00:45:00]: DNS service is online.
[03/06/05 00:45:00]: SSH service is offline.
[03/06/05 00:45:00]: Restarted SSH service (10 SSH events today).
[03/06/05 00:45:00]: MYSQL service is online.
[03/06/05 00:45:00]: XINET service is online.
[03/06/05 00:45:00]: SMTP service is online.