免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 4180 | 回复: 4
打印 上一主题 下一主题

大家帮忙给分析下日志 [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2011-09-14 23:28 |只看该作者 |倒序浏览
下面是我截取的/var/log/secure部分内容:
第一部分:
Sep 11 11:52:12 ssenp sshd[29960]: Failed password for invalid user pooyan from 124.127.125.2 port 47257 ssh2
Sep 11 11:52:12 ssenp sshd[29961]: Received disconnect from 124.127.125.2: 11: Bye Bye
Sep 11 11:52:12 ssenp sshd[29962]: Failed password for invalid user wwan from 124.127.125.2 port 41331 ssh2
Sep 11 11:52:12 ssenp sshd[29963]: Received disconnect from 124.127.125.2: 11: Bye Bye
Sep 11 11:52:12 ssenp sshd[29964]: Invalid user wegu from 124.127.125.2
Sep 11 11:52:12 ssenp sshd[29964]: Address 124.127.125.2 maps to mail.navinfo.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Sep 11 11:52:12 ssenp sshd[29965]: input_userauth_request: invalid user wegu
Sep 11 11:52:12 ssenp sshd[29964]: pam_unix(sshd:auth): check pass; user unknown
Sep 11 11:52:12 ssenp sshd[29964]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=124.127.125.2
Sep 11 11:52:12 ssenp sshd[29964]: pam_succeed_if(sshd:auth): error retrieving information about user wegu
Sep 11 11:52:12 ssenp sshd[29966]: Invalid user guozhe from 124.127.125.2
Sep 11 11:52:12 ssenp sshd[29966]: Address 124.127.125.2 maps to mail.navinfo.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Sep 11 11:52:12 ssenp sshd[29967]: input_userauth_request: invalid user guozhe
Sep 11 11:52:12 ssenp sshd[29966]: pam_unix(sshd:auth): check pass; user unknown
Sep 11 11:52:12 ssenp sshd[29966]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=124.127.125.2
Sep 11 11:52:12 ssenp sshd[29966]: pam_succeed_if(sshd:auth): error retrieving information about user guozhe


第二部分:
Sep 14 22:20:30 ssenp sshd[6613]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=sd-27673.dedibox.fr  user=root
Sep 14 22:20:32 ssenp sshd[6613]: Failed password for root from 88.191.145.142 port 44339 ssh2
Sep 14 22:20:32 ssenp sshd[6614]: Received disconnect from 88.191.145.142: 11: Bye Bye
Sep 14 22:20:35 ssenp sshd[6615]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=sd-27673.dedibox.fr  user=root
Sep 14 22:20:36 ssenp sshd[6615]: Failed password for root from 88.191.145.142 port 44644 ssh2
Sep 14 22:20:37 ssenp sshd[6616]: Received disconnect from 88.191.145.142: 11: Bye Bye
Sep 14 22:20:39 ssenp sshd[6617]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=sd-27673.dedibox.fr  user=root
Sep 14 22:20:41 ssenp sshd[6617]: Failed password for root from 88.191.145.142 port 53963 ssh2
Sep 14 22:20:42 ssenp sshd[6618]: Received disconnect from 88.191.145.142: 11: Bye Bye
Sep 14 22:20:44 ssenp sshd[6619]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=sd-27673.dedibox.fr  user=root
Sep 14 22:20:46 ssenp sshd[6619]: Failed password for root from 88.191.145.142 port 54251 ssh2
Sep 14 22:20:46 ssenp sshd[6620]: Received disconnect from 88.191.145.142: 11: Bye Bye
Sep 14 22:20:51 ssenp sshd[6621]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=sd-27673.dedibox.fr  user=root
Sep 14 22:20:53 ssenp sshd[6621]: Failed password for root from 88.191.145.142 port 54537 ssh2
Sep 14 22:20:53 ssenp sshd[6622]: Received disconnect from 88.191.145.142: 11: Bye Bye
Sep 14 22:20:57 ssenp sshd[6623]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=sd-27673.dedibox.fr  user=root
Sep 14 22:20:59 ssenp sshd[6623]: Failed password for root from 88.191.145.142 port 54933 ssh2


我的判断是有人使用ssh连接我的主机。
主机名是ssenp
其中第一段中的那些用户pooyan、wwan、wegu、guozhe....都不是我的系统用户,其中出现的ip也不是我连接的用的,也不是服务器ip
还有那个Address 124.127.125.2 maps to mail.navinfo.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!怎么解释
有知道的帮忙分析下,谢谢大家了。

论坛徽章:
0
2 [报告]
发表于 2011-09-14 23:37 |只看该作者
黑客使用软件扫描的把,建议LZ把ssh的端口改了,这样就比较安全了。

论坛徽章:
0
3 [报告]
发表于 2011-09-14 23:46 |只看该作者
回复 1# enmingma


  配置文件  GSSAPIAuthentication no

论坛徽章:
0
4 [报告]
发表于 2011-09-15 09:00 |只看该作者
本帖最后由 enmingma 于 2011-09-15 09:13 编辑

回复 3# taojie2000
请问这起什么作用

论坛徽章:
0
5 [报告]
发表于 2011-09-15 10:07 |只看该作者
回复 4# enmingma


    取消 GSSAPI 验证
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP