Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

telnetd

Status
Not open for further replies.

abovebrd

IS-IT--Management
May 9, 2000
690
US
May 30 06:18:51 serverone telnetd[19996]: can't find user in protected password database

This shows up in /var/adm/syslog several times a day. Does anyone know what is causing this error message. Or ideas

Is this simply some one entering a bad password ?

-Danny






 
I see that in our syslog as well.
How many users?

We have around 120 users and it appears 0-10 times a day.

The people I´ve asked says its only users with clumsy fingers.
Perhaps there´s an internal competition among the users. The fastest password-typing user wins a busquit or something, therefor all the errors. /Sören
 
We have about 80 user on this SCO box. I suspected it was the old "fat fingers" problem.

The entries show up ramdomly, 0-20 on any given day.



-Danny






 
We have seen a recent spike in this activity -- 4 times PER SECOND on a system with about 50 users. That's 4 times per second -- on a weekend evening and we don't work weekends. Obviously changed our firewall plans. Any ideas?
 
Is this system connected to the internet? With that many failed login attempts it sounds like a hack.

I would either load ipfilter on this or put it behind a firewall that can filter IP packets. Another soloution might be to replace inetd with xinetd. It was greater security and logging facilities. However I an not sure if xinetd ports to SCO unix. I am still looking into to that.



-Danny






 
Sorry, all, yes this system was exposed to the 'Net but has since been whisked back behind a firewall. Would be curious about xinetd for SCO as well enjoying it on our Linux boxes. Thanks, M.
 
I ported all of my linux boxes to xinetd. Its actual very easy. You can configure the xinetd.conf file to allow telnet connection based on multiple type of rules. Such as only allow connection to be made for these user accounts : user1 user2 user3

or allow connection from specific IP addresses.

xinetd is a replacment for inetd. All of your current services that use inetd will work under xinetd. The configuration file is in a different format.

Another solotuion I just thought of would be to use tcpwrappers. I believe it can be complied to run on SCO Unix
and it will work with inetd or xinetd.

If you want more information you can contact outside of this forum

dcd@pop.mainstreet.net


-Danny






 
I´m curious about this xinetd thing. Never heard of it.

How do you replace the existing inetd? Is it a troublesome operation?

Where do I find more information?

Danny... Let me know if you find a SCO-version out there.

/Sören
 
I have not been able to find any related info on running xinetd on SCO

Sometime in the sort future I am going to put a test system togeather. Once I get the test system up on the wire I will attempt to compile xinetd. I will post back in a week or so
with the results.

I have complied xinetd to run on Solaris 8, RH Linx 6-7,
and a freebsd machine.

-Danny






 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top