Is this log showing someone hacked into my server?

Discussion in 'General' started by skysky, Dec 2, 2020.

  1. skysky

    skysky Member

    Hi

    I used ISPconfig auto script to install the ubuntu 18.04 perfect server. it has pure-FTP installed by default. after a few days I installed the server, I found something suspicious from syslog below showing that someone successfully connected to my server, then logout.

    syslog:
    Nov 25 06:30:17 sev1 pure-ftpd: ([email protected]) [INFO] New connection from 192.241.234.66
    Nov 25 06:30:18 sev1 pure-ftpd: ([email protected]) [INFO] Logout.

    I did not create any FTP account (ISPconfig FTP account page empty), and I enabled SSH with key for root. I also tried to root can not login FTP with port 21. I really don't understand how it is possible someone can hack my new server to login as FTP as the log shows.
     
  2. skysky

    skysky Member

  3. Th0m

    Th0m ISPConfig Developer Staff Member ISPConfig Developer

    Connections are normal, this is just someone trying to reach the server which happens all the time.
     

Share This Page