My own VPS blocking SSH access to me?

Discussion in 'Site & Server Administration' started by hvalle98, Dec 29, 2009.

  1. #1
    I don't know why, but my vps is denying ssh access to me. I checked the etc/hosts.deny file and there were lots of IP's in there, which I don't know how they got there. Anyway, I don't care too much about that.

    What puzzles me is that my ip was on that list, with SSH blocked. I deleted the string and I got SSH access. Anyway, when I closed the connection, my IP got again on this list. What is going on? Also, why all of those IP's were on this list? This happens after switching from Apache to lighttpd.

    Here's my hosts.deny file:

    ###Start Program Hostdeny config Area
    ###Please Don't edit these comments or the content in between. lxadmin uses this to recognize the lines it writes to the the file. If the above line is corrupted, it may fail to recognize them, leading to multiple lines.
    ALL : 60.36.182.61
    ALL : 60.217.229.222
    ALL : 75.99.178.139
    ALL : 196.15.143.106
    ALL : 168.96.15.71
    ALL : 222.127.0.68
    ALL : 61.49.18.189
    ALL : 218.223.24.76
    ALL : 60.217.229.220
    ALL : 121.169.208.222
    ALL : 211.139.201.158
    ALL : 69.162.85.168
    ALL : 121.15.167.243
    ALL : 67.55.0.109
    ALL : 212.156.5.254
    ALL : 72.249.144.227
    ALL : 211.144.87.181
    ALL : 202.96.188.86
    ALL : 195.149.118.43
    ALL : 60.217.229.229
    ALL : 97.107.133.228
    ALL : 67.43.56.14
    ALL : 203.33.255.66
    ALL : 220.227.198.226
    ALL : 218.205.244.158
    ALL : 61.4.191.29
    ALL : 114.255.164.83
    ALL : 64.118.84.9
    ALL : 221.234.41.105
    ALL : 217.31.51.234
    ALL : 209.52.170.114
    ALL : 59.50.33.102
    ALL : 85.12.195.188
    ALL : 220.168.55.171
    ALL : 113.23.144.62
    ALL : 200.91.200.115
    ALL : 61.83.228.112
    ALL : 83.235.222.243
    ALL : 77.233.171.144
    ALL : 124.232.135.15
    ALL : 207.112.13.178
    ALL : 117.22.252.2
    ALL : 60.191.205.212
    ALL : 122.160.238.214
    ALL : 190.26.212.4
    ALL : 96.57.49.213
    ALL : 72.165.161.222
    ALL : 202.131.227.27
    ALL : 62.117.122.118
    ALL : 82.114.81.76
    ALL : 78.111.167.117
    ALL : 58.151.138.123
    
    ###End Program HostDeny config Area
    
    sshd: 200.110.171.76
    sshd: 153.90.198.105
    sshd: 202.107.228.137
    sshd: 201.33.229.246
    sshd: 208.82.21.7
    sshd: 222.178.134.125
    sshd: 122.160.219.81
    sshd: 218.202.129.89
    sshd: 60.217.229.222
    sshd: 70.38.11.7
    sshd: 219.134.242.67
    sshd: 83.233.149.162
    sshd: 59.64.112.137
    sshd: 196.216.66.166
    sshd: 220.233.10.138
    sshd: 81.169.135.117
    sshd: 216.219.239.160
    sshd: 118.217.181.52
    sshd: 62.84.11.64
    sshd: 211.153.34.106
    sshd: 203.130.240.60
    sshd: 61.152.255.56
    sshd: 201.86.117.162
    sshd: 216.229.160.194
    sshd: 121.131.210.109
    sshd: 194.65.138.84
    sshd: 70.89.61.34
    sshd: 200.175.156.186
    sshd: 62.112.195.219
    sshd: 60.199.226.101
    sshd: 123.242.184.10
    sshd: 61.219.227.171
    sshd: 187.11.193.213
    sshd: 59.163.108.39
    sshd: 59.76.80.179
    sshd: 122.160.219.69
    sshd: 218.15.163.222
    sshd: 120.107.149.119
    sshd: 116.28.64.132
    sshd: 64.40.101.89
    sshd: 91.189.123.230
    sshd: 67.219.62.24
    sshd: 76.12.142.184
    sshd: 82.54.198.85
    sshd: 202.9.108.35
    sshd: 222.236.44.99
    sshd: 88.191.78.113
    sshd: 124.124.212.172
    sshd: 82.200.130.235
    sshd: 82.235.127.63
    sshd: 81.17.167.187
    sshd: 193.147.116.213
    sshd: 92.48.122.209
    sshd: 202.67.211.78
    sshd: 209.172.33.134
    sshd: 61.95.144.78
    sshd: 200.105.199.83
    sshd: 60.220.218.88
    sshd: 200.105.239.194
    sshd: 218.200.227.140
    sshd: 203.129.200.233
    sshd: 201.116.35.190
    sshd: 122.168.193.251
    sshd: 121.11.153.242
    sshd: 193.85.149.46
    sshd: 190.146.247.15
    sshd: 210.51.190.111
    sshd: 202.205.179.163
    sshd: 201.228.3.10
    sshd: 207.61.33.78
    sshd: 218.205.11.212
    sshd: 61.195.161.74
    sshd: 76.205.188.137
    sshd: 61.129.60.23
    sshd: 122.136.32.57
    sshd: 210.51.171.74
    sshd: 62.43.224.224
    sshd: 58.121.85.153
    sshd: 84.109.46.27
    sshd: 12.54.112.27
    sshd: 58.247.222.202
    sshd: 122.136.32.62
    sshd: 90.188.20.254
    sshd: 124.160.192.119
    sshd: 125.32.113.212
    sshd: 76.21.57.117
    sshd: 58.181.18.140
    sshd: 192.121.234.229
    sshd: 58.68.49.197
    sshd: 119.167.216.25
    sshd: 24.131.254.242
    sshd: 213.154.72.72
    sshd: 190.68.110.213
    sshd: 85.121.160.235
    sshd: 117.21.246.164
    sshd: 115.238.51.150
    sshd: 60.191.39.253
    sshd: 209.128.105.77
    sshd: 58.22.131.116
    sshd: 218.101.6.171
    sshd: 67.82.14.60
    sshd: 211.154.254.120
    sshd: 210.44.80.7
    sshd: 82.94.236.139
    sshd: 211.144.102.8
    sshd: 210.3.38.140
    sshd: 61.222.188.150
    sshd: 64.62.148.198
    sshd: 220.225.66.58
    sshd: 66.64.128.234
    sshd: 95.154.240.232
    sshd: 210.192.123.204
    sshd: 200.47.34.56
    sshd: 212.18.195.102
    sshd: 122.224.104.195
    sshd: 88.204.159.93
    sshd: 88.204.159.93
    [B]sshd: 190.121.193.239 <- my IP[/B]
    
    Code (markup):
    P.S. I am using lxadmin.
     
    hvalle98, Dec 29, 2009 IP
  2. chandan123

    chandan123 Prominent Member

    Messages:
    11,586
    Likes Received:
    578
    Best Answers:
    0
    Trophy Points:
    360
    #2
    they are blocked by lxadmin for too many ssh login attempts

    i guess when u login to lxadmin panel u can go to lxguard tab and see those blocked ips

    try with that link and see if it fixes
     
    chandan123, Dec 29, 2009 IP
  3. iRock-Matt

    iRock-Matt Peon

    Messages:
    39
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    You can simply remove your IP from that list.
     
    iRock-Matt, Jan 6, 2010 IP
  4. chandan123

    chandan123 Prominent Member

    Messages:
    11,586
    Likes Received:
    578
    Best Answers:
    0
    Trophy Points:
    360
    #4
    but OP facing problem after the relogin even with ip removal
     
    chandan123, Jan 6, 2010 IP
  5. hans

    hans Well-Known Member

    Messages:
    2,923
    Likes Received:
    126
    Best Answers:
    1
    Trophy Points:
    173
    #5
    instead of simply removing your banned IP from a blacklist
    you may whitelist your IP
    i dont know your overall software for your server admin
    on normal linux LAMP dedicated servers there are multiple solutions - for example iptables-whitelisting your various ( incl alternate ) login IPs
    similar whitelisting options usually are available for mod_security, fail2ban etc

    in addition to avoid such errors use serverkey authentication and you never ever have a wrong password login again
     
    hans, Jan 7, 2010 IP
  6. cocodude

    cocodude Active Member

    Messages:
    37
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    55
    #6
    Indeed if you add your IP address to hosts.allow, this should override any in hosts.deny
     
    cocodude, Jan 7, 2010 IP
  7. tamer1009

    tamer1009 Peon

    Messages:
    74
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #7
    remove the ip's in lxadmin --> lxguard, don't edit that file.
    and @chandan123 is agree.

    btw: i use lighttpd instead of apache, and it works great. lighttpd doesn't use much resources :D
     
    tamer1009, Jan 7, 2010 IP
  8. ramnet

    ramnet Peon

    Messages:
    32
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Agreed.

    Your IP got put back in by lxadmin / lxgaurd since it keeps it's own copy of the banned IP's - if you remove it directly from /etc/hosts.deny it will get put back in the next time lxadmin / lxgaurd runs.
     
    ramnet, Jan 9, 2010 IP