I gotten the following report from Digital Ocean in an abuse report. I got on before and did the following:
I’m not sure where to go from here but it looks like my box is still being abused. Any help?
Hi, We have detected a network attack from an IP ( 192.241.xxx.xxx ) from your network, a computer connected to it is probably infected and being part of a botnet. Please check it and fix it up as soon as possible. Thank you.
The IP 192.241.xxx.xxx has just been banned by Fail2Ban after 4 attempts against apache-attack.
Domain: dondevasconesoshierros.com (195.78.231.40)
Here are more information about 192.241.xxx.xxx: Lines containing IP:192.241.xxx.xxx in /furanet/sites/*/web/htdocs/logs/access
/furanet/sites/dondevasconesoshierros.com/web/htdocs/logs/access:192.241.xxx.xxx - - [24/Feb/2014:03:54:06 +0100] “POST /wp-login.php HTTP/1.0” 200 1946 “-” “-” “-” /furanet/sites/dondevasconesoshierros.com/web/htdocs/logs/access:192.241.xxx.xxx - - [24/Feb/2014:03:54:07 +0100] “POST /wp-login.php HTTP/1.0” 200 1946 “-” “-” “-” /furanet/sites/dondevasconesoshierros.com/web/htdocs/logs/access:192.241.xxx.xxx - - [24/Feb/2014:03:54:07 +0100] “POST /wp-login.php HTTP/1.0” 200 1946 “-” “-” “-” /furanet/sites/dondevasconesoshierros.com/web/htdocs/logs/access:192.241.xxx.xxx - - [24/Feb/2014:03:54:07 +0100] “POST /wp-login.php HTTP/1.0” 200 1946 “-” “-” “-” /furanet/sites/dondevasconesoshierros.com/web/htdocs/logs/access:192.241.xxx.xxx - - [24/Feb/2014:03:54:08 +0100] “POST /wp-login.php HTTP/1.0” 200 1946 “-” “-” “-”
This textbox defaults to using Markdown to format your answer.
You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!
Interesting I got similar email. <br> <br>I am running maldet scan on my server right now. <br> <br>Funny thing is that it seems to come from same network: 195.78.231.227 <br> <br>
Very often, servers are compromised by simple brute force attacks that attempt to connect to the root account over ssh guessing passwords. If you haven’t done so yet, there are some basic precautions you can take. I’d argue that disabling password authentication in favor of just using the key is the first thing you should do when you create a new server. This tutorial will run you through some basic security measures: <br> <br>https://www.digitalocean.com/community/articles/initial-server-setup-with-ubuntu-12-04
Get paid to write technical tutorials and select a tech-focused charity to receive a matching donation.
Full documentation for every DigitalOcean product.
The Wave has everything you need to know about building a business, from raising funding to marketing your product.
Stay up to date by signing up for DigitalOcean’s Infrastructure as a Newsletter.
New accounts only. By submitting your email you agree to our Privacy Policy
Scale up as you grow — whether you're running one virtual machine or ten thousand.
Sign up and get $200 in credit for your first 60 days with DigitalOcean.*
*This promotional offer applies to new accounts only.