Page 1 of 1
Someone is trying to Hack my Subsonic server

Posted:
Sat Jan 24, 2015 2:09 pm
by elinter
For the last several days, I'm getting this log message every 10 seconds:
"[1/24/15 8:47:56 AM EST] INFO RESTRequestParameterProcessingFilter Authentication failed for user admin"
I've got a pretty strong, totally random 128 bit password, so I'm a little less concerned. However, seems to me that the login algorithm needs to have added an anti-hacking feature to defeat automated scripts like this. I turned off my server for a couple days hoping they'd move on, but they were right back within minutes of it coming online again.
Is anyone else seeing this behavior?
Mike
Re: Someone is trying to Hack my Subsonic server

Posted:
Sat Jan 24, 2015 6:16 pm
by alphawave7
I have seen this too but it wasn't nefarious..it was one of many devices I have (multiple phones, tablets, etc.) trying to log in when the app runs. See if you have any devices with the app running, even in the background.
Sent from my Nexus 6
Re: Someone is trying to Hack my Subsonic server

Posted:
Sat Jan 24, 2015 9:44 pm
by elinter
I do, but they are not set up to log in as admin. I set up a limit user accounts for that purpose. Anyway, I turned them off and still am getting failed login attempts to the admin account.
Re: Someone is trying to Hack my Subsonic server

Posted:
Sat Jan 24, 2015 10:11 pm
by mikes
If it's happening every 10 seconds, use Wireshark to do a capture and see what the IP is. Then block it in your firewall.
Re: Someone is trying to Hack my Subsonic server

Posted:
Sun Jan 25, 2015 3:14 am
by elinter
I guess I've got some learning to do. My subsonic server is running under FREENAS, which doesn't have Wireshark installed. If anyone has experience with installing and using Wireshark on FREENAS, I would appreciate the help.
Re: Someone is trying to Hack my Subsonic server

Posted:
Mon Jan 26, 2015 6:11 pm
by mikes
It looks like freenas has tcpdump installed. You may be able to
get a pcap as described here, then transfer and open it with Wireshark on a PC.
Re: Someone is trying to Hack my Subsonic server

Posted:
Tue Feb 17, 2015 2:18 pm
by isotopp
It would be really useful if the log message actually included the source IP and user-agent string of the failed login attempt, and optionally the failed password.
Re: Someone is trying to Hack my Subsonic server

Posted:
Tue Mar 10, 2015 10:06 am
by MonsterMuffin
Same thing was happening to me, was pretty easy to stop.
I run PfSense as my firewall and all I had to do was filter active connections coming into port 4040, find the offender IP and create a WAN rule to block that IP.
Problem sorted.