Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 545832 - net-misc/openssh-6.8_p1-r3 bad syslog message priorities
Summary: net-misc/openssh-6.8_p1-r3 bad syslog message priorities
Status: RESOLVED UPSTREAM
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Server (show other bugs)
Hardware: All All
: Normal normal (vote)
Assignee: Gentoo's Team for Core System packages
URL: https://bugzilla.mindrot.org/show_bug...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-04-07 15:27 UTC by Jaak Ristioja
Modified: 2015-04-08 07:05 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jaak Ristioja 2015-04-07 15:27:24 UTC
A SSH service on a server running Gentoo is being scanned and brute-forced, subject to all the "privileges" of running on a public IP address. For some random connections, only the following messages are logged to syslog:

Apr  7 18:09:10 localhost sshd:20499:info Received disconnect from 77.233.89.158: 11: disconnected by user
Apr  7 18:09:10 localhost sshd:20499:info Disconnected from 77.233.89.158
Apr  7 18:09:10 localhost sshd:20496:err error: mm_request_receive: socket closed

If the system administrator has configured syslog to drop messages with informational priority, only the cryptic and rather useless "error: mm_request_receive: socket closed" remain.

These messages contain no IP address of the client and seem useless from a systems administration point of view. I mean what kind of reasonable action is the sysadmin supposed to take on such an error message?

The error messages do not contain information about whether the disconnect happened before or after authentication, or what was the IP address of the client etc.

[ebuild   R   ~] net-misc/openssh-6.8_p1-r3  USE="libedit pam pie ssl -X -X509 -bindist -debug -hpn -kerberos -ldap -ldns -sctp (-selinux) -skey -ssh1 -static"
Comment 1 SpanKY gentoo-dev 2015-04-08 03:50:52 UTC
please file such requests here:
  https://bugzilla.mindrot.org/

we have no plans on writing custom code here
Comment 2 Jaak Ristioja 2015-04-08 06:56:11 UTC
Reported to https://bugzilla.mindrot.org/show_bug.cgi?id=2375
Comment 3 SpanKY gentoo-dev 2015-04-08 07:05:25 UTC
thanks!