Help solve Immediate Brute-Force Attack after addition of new admin name

jaustill

New member
Joined
Dec 30, 2011
Messages
1
I (noob) just added a new admin with a very secure password. I did not send a welcome email, because the admin was only a way to get admin type emails to an extra email address. Also never attempted a login on the new account.

Only 2 hours later I started seeing unsuccessful Brute-Force attacks from a China IP trying to guess the new admins password. How would an outside source have seen the new admin name?

What might I need to look for?

One of the Brute Force Monitor entries (admin name is changed to "adminname"):

18262653060700 120.42.95.44 adminname 1 exim1 2011-12-30 09:09:34 login authenticator failed for (ylmf-pc) [120.42.95.44]: 535 Incorrect authentication data (set_id=adminname)
 
Do you log into DirectAdmin through a secure https connection? If not, then your connection is in plaintext, including your new username, but if so, they probably would have had the password as well.

You don't say the admin name, so we don't know if it's a common one or not. It could just be a guess that happens to be right.

Jeff
 
Back
Top