Account numbers instead of names?
sorry, I cannot change the title. I want to mean: Account numbers instead names.
I'm receiving CPanel security alerts with a chain of numbers instead the account names:
In example:
[QUOTE]....session failed in account "91.2899649070727"....
also it happens with the LFD alerts: [QUOTE]Log entries: [2020-03-06 16:05:20 +0100] info [cpaneld] 185.x.x.x - 38.0545164488456 "GET /rss/order/new HTTP/1.1" FAILED LOGIN cpaneld: user name not provided or invalid user
I'm seeing these chains "91.2899649070727", "38.0545164488456" instead the account names. Why it happens? Is this a bug?
also it happens with the LFD alerts: [QUOTE]Log entries: [2020-03-06 16:05:20 +0100] info [cpaneld] 185.x.x.x - 38.0545164488456 "GET /rss/order/new HTTP/1.1" FAILED LOGIN cpaneld: user name not provided or invalid user
I'm seeing these chains "91.2899649070727", "38.0545164488456" instead the account names. Why it happens? Is this a bug?
-
These seem like failed login attempts - i.e., someone/something is trying to log in as that user (random number string) which doesn't exist. 0 -
yes, although using random numbers for the usernames doesn't have sense. It isn't? I have many attempts from many IPs from different countries from quite days ago. I'm curious about these type of attempts: [QUOTE][2020-03-05 8:21:15 +0100] info [cpaneld] 31.x.x.x - 26.3478912226342 "GET /rss/order/new HTTP/1.1" FAILED LOGIN cpaneld: user name not provided or invalid user [2020-03-05 8:21:15 +0100] info [cpaneld] 31.x.x.x - 26.3478912226342 "GET /rss/catalog/notifystock HTTP/1.1" FAILED LOGIN cpaneld: user name not provided or invalid user [2020-03-05 8:21:16 +0100] info [cpaneld] 31.x.x.x - 26.3478912226342 "GET /rss/catalog/review HTTP/1.1" FAILED LOGIN cpaneld: user name not provided or invalid user [2020-03-05 8:21:16 +0100] info [cpaneld] 31.x.x.x - 61.8377592377412 "GET /old/rss/order/new HTTP/1.1" FAILED LOGIN cpaneld: user name not provided or invalid user [2020-03-05 8:21:17 +0100] info [cpaneld] 31.x.x.x - 61.8377592377412 "GET /old/rss/catalog/notifystock HTTP/1.1" FAILED LOGIN cpaneld: user name not provided or invalid user
seems like if they expect some special behaviour through these url's. I don't know really ok, thanks anyway,0
Please sign in to leave a comment.
Comments
3 comments