免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 2587 | 回复: 1
打印 上一主题 下一主题

机器在被人家扫描root密码 咋个解决-- [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2010-02-22 15:35 |只看该作者 |倒序浏览
本帖最后由 gianterdaddy 于 2010-02-22 15:39 编辑

sshd_conf 怎么配置呢? 次数是限制了 但是禁不住 他用其他新连接来测试
ClientAliveInterval 10
ClientAliveCountMax 3
iptables 怎么都感觉不靠谱啊 因为iptables 貌似只能对特定的IP范围来限制SSH的次数

vi /var/log/secure 看到的

Feb 21 12:23:52 localhost sshd[9077]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:23:55 localhost sshd[9078]: Failed password for root from ::ffff:113.105.131.130 port 47274 ssh2
Feb 21 12:23:55 localhost sshd[9079]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:23:57 localhost sshd[9080]: Failed password for root from ::ffff:113.105.131.130 port 47759 ssh2
Feb 21 12:23:57 localhost sshd[9081]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:00 localhost sshd[9082]: Failed password for root from ::ffff:113.105.131.130 port 48238 ssh2
Feb 21 12:24:00 localhost sshd[9083]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:03 localhost sshd[9084]: Failed password for root from ::ffff:113.105.131.130 port 48709 ssh2
Feb 21 12:24:03 localhost sshd[9085]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:06 localhost sshd[9086]: Failed password for root from ::ffff:113.105.131.130 port 49172 ssh2
Feb 21 12:24:06 localhost sshd[9087]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:09 localhost sshd[9088]: Failed password for root from ::ffff:113.105.131.130 port 49672 ssh2
Feb 21 12:24:09 localhost sshd[9089]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:11 localhost sshd[9090]: Failed password for root from ::ffff:113.105.131.130 port 50145 ssh2
Feb 21 12:24:11 localhost sshd[9091]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:14 localhost sshd[9092]: Failed password for root from ::ffff:113.105.131.130 port 50617 ssh2
Feb 21 12:24:14 localhost sshd[9093]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:17 localhost sshd[9094]: Failed password for root from ::ffff:113.105.131.130 port 51083 ssh2
Feb 21 12:24:17 localhost sshd[9095]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:20 localhost sshd[9096]: Failed password for root from ::ffff:113.105.131.130 port 51564 ssh2
Feb 21 12:24:20 localhost sshd[9097]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:23 localhost sshd[9098]: Failed password for root from ::ffff:113.105.131.130 port 52042 ssh2
Feb 21 12:24:23 localhost sshd[9099]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:26 localhost sshd[9100]: Failed password for root from ::ffff:113.105.131.130 port 52501 ssh2
Feb 21 12:24:26 localhost sshd[9101]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:28 localhost sshd[9102]: Failed password for root from ::ffff:113.105.131.130 port 52983 ssh2
Feb 21 12:24:28 localhost sshd[9103]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:31 localhost sshd[9104]: Failed password for root from ::ffff:113.105.131.130 port 53454 ssh2
Feb 21 12:24:31 localhost sshd[9105]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:34 localhost sshd[9106]: Failed password for root from ::ffff:113.105.131.130 port 53930 ssh2
Feb 21 12:24:34 localhost sshd[9107]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:37 localhost sshd[9108]: Failed password for root from ::ffff:113.105.131.130 port 54411 ssh2
Feb 21 12:24:37 localhost sshd[9109]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:40 localhost sshd[9110]: Failed password for root from ::ffff:113.105.131.130 port 54876 ssh2
Feb 21 12:24:40 localhost sshd[9111]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:42 localhost sshd[9112]: Failed password for root from ::ffff:113.105.131.130 port 55352 ssh2
Feb 21 12:24:42 localhost sshd[9113]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:45 localhost sshd[9114]: Failed password for root from ::ffff:113.105.131.130 port 55840 ssh2
Feb 21 12:24:45 localhost sshd[9115]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:48 localhost sshd[9116]: Failed password for root from ::ffff:113.105.131.130 port 56318 ssh2
Feb 21 12:24:48 localhost sshd[9117]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:51 localhost sshd[9118]: Failed password for root from ::ffff:113.105.131.130 port 56798 ssh2
Feb 21 12:24:51 localhost sshd[9119]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:54 localhost sshd[9120]: Failed password for root from ::ffff:113.105.131.130 port 57259 ssh2
Feb 21 12:24:54 localhost sshd[9121]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:57 localhost sshd[9122]: Failed password for root from ::ffff:113.105.131.130 port 57733 ssh2
Feb 21 12:24:57 localhost sshd[9123]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:24:59 localhost sshd[9124]: Failed password for root from ::ffff:113.105.131.130 port 58215 ssh2
Feb 21 12:24:59 localhost sshd[9125]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:25:02 localhost sshd[9126]: Failed password for root from ::ffff:113.105.131.130 port 58694 ssh2
Feb 21 12:25:02 localhost sshd[9127]: Received disconnect from ::ffff:113.105.131.130: 11: Bye Bye
Feb 21 12:25:05 localhost sshd[9128]: Failed password for root from ::ffff:113.105.131.130 port 59166 ssh2

论坛徽章:
0
2 [报告]
发表于 2010-02-22 15:37 |只看该作者
敢问各位的好的解决办法。。。
注:暂时不想改变22端口 。。。。
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP