Skip to main content
Contributor
October 28, 2008
Question

Unauthorized SSH Login Failed

  • October 28, 2008
  • 4 replies
  • 5418 views
The night following an upgraded to MR7 Patch1, I have several login attempts that are not me. I am the only one who should have access to this equipment. I am just curious what one should do in this situation? I could block the IPs but I have a feeling they would be different each time a login is attempted again. Fortigate-60 3.00-b0730 Valid and current AV & IPS Defs Below is the log: 8 2008-10-28 01:09:58 alert ssh(117.28.224.71) login Administrator NOUSER login failed from ssh(117.28.224.71) because of invalid user name 9 2008-10-28 01:09:58 alert ssh(117.28.224.71) login Administrator root login failed from ssh(117.28.224.71) because of invalid user name 10 2008-10-28 01:09:56 alert ssh(117.28.224.71) login Administrator NOUSER login failed from ssh(117.28.224.71) because of invalid user name 11 2008-10-28 01:09:56 alert ssh(117.28.224.71) login Administrator root login failed from ssh(117.28.224.71) because of invalid user name 12 2008-10-28 00:31:09 notice Fortigate scheduled update virdb(9.00680) idsdb(2.00560) aven(3.00003) idsen(1.00096) from 208.91.114.72:443 13 2008-10-27 23:47:38 alert ssh(202.67.15.18) login Administrator NOUSER login failed from ssh(202.67.15.18) because of invalid user name 14 2008-10-27 23:47:38 alert ssh(202.67.15.18) login Administrator root login failed from ssh(202.67.15.18) because of invalid user name 15 2008-10-27 23:47:35 alert ssh(202.67.15.18) login Administrator NOUSER login failed from ssh(202.67.15.18) because of invalid user name 16 2008-10-27 23:47:35 alert ssh(202.67.15.18) login Administrator root login failed from ssh(202.67.15.18) because of invalid user name Any suggestions?

    4 replies

    rwpatterson
    New Member
    October 28, 2008
    I get them on my FGT as well as my FTP server. Probably bots probing to gain access. I wouldn' t worry about them unless they are consuming most of your bandwidth. Just make sure you don' t have ' standard' or easily guessable account names and passwords. I avoid ' administrator' , ' admin' and the like whenever possible...
    Contributor
    October 30, 2008
    I did get a few other attempts the next day but not any more after that. My usernames are not easily guessable and have strong passwords so I will feel safe in that at least. What does the " NOUSER" and " root" mean anyway, where they trying to login with " administrator" as the username or is there some special root login that does not show in the UI?
    Contributor
    October 31, 2008
    My fgt-60 has this error these days. Does someone attempt to access ? How to strengthen my unit security?
    p768
    New Member
    October 31, 2008
    configure your admin users with Trusted Hosts
    romanr
    New Member
    October 31, 2008
    I would also suggest to use the trusted host feature! SSH brute-force attacks can consume a real noticeable amount of cpu time of the Fortinet unit!!! cheers.roman