免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 2224 | 回复: 6
打印 上一主题 下一主题

我的妈呀!因为求助乱码问题泄露ip遭无数次实验登录啊!(已限制ip) [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2010-03-27 09:08 |只看该作者 |倒序浏览
本帖最后由 chenmeng10 于 2010-03-27 11:08 编辑

奉劝各位别试了!已限制ip



**Unmatched Entries**
STARTUP (V5.0)
STARTUP (V5.0)
STARTUP (V5.0)

---------------------- Cron End -------------------------


--------------------- Init Begin ------------------------



Re-execs of init: 1 times

---------------------- Init End -------------------------


--------------------- pam_unix Begin ------------------------

sshd:
   Authentication Failures:
      root (112.216.57.254): 89 Time(s)
      unknown (89.33.116.82): 51 Time(s)
      unknown (95.77.196.171): 50 Time(s)
      root (arato.lanten.hu): 26 Time(s)
      root (211.102.90.131): 16 Time(s)
      root (89.33.116.82): 11 Time(s)
      root (s094127068004.m.truevds.ru): 6 Time(s)
      unknown (211.102.90.131): 3 Time(s)
      unknown (arato.lanten.hu): 2 Time(s)
      adm (95.77.196.171): 1 Time(s)
      apache (89.33.116.82): 1 Time(s)
      ftp (89.33.116.82): 1 Time(s)
      named (89.33.116.82): 1 Time(s)
      unknown (112.216.57.254): 1 Time(s)
   Invalid Users:
      Unknown Account: 107 Time(s)


---------------------- pam_unix End -------------------------


--------------------- Connections (secure-log) Begin ------------------------


**Unmatched Entries**
userhelper[2970]: pam_timestamp: updated timestamp file `/var/run/sudo/root/unknown'
userhelper[2973]: running '/usr/sbin/system-install-packages /home/scim-fcitx-debuginfo-3.1.1-9.fc9.i386.rpm' with root privileges on behalf of 'root'
userhelper[2981]: pam_timestamp: updated timestamp file `/var/run/sudo/root/unknown'
userhelper[2984]: running '/usr/sbin/system-install-packages /home/scim-fcitx-debuginfo-3.1.1-9.fc9.i386.rpm' with root privileges on behalf of 'root'
userhelper[3314]: pam_timestamp: updated timestamp file `/var/run/sudo/root/unknown'
userhelper[3317]: running '/usr/sbin/system-switch-im' with root privileges on behalf of 'root'
userhelper[5201]: pam_timestamp: updated timestamp file `/var/run/sudo/root/unknown'
userhelper[5204]: running '/usr/sbin/system-switch-im' with root privileges on behalf of 'root'
userhelper[5207]: pam_timestamp: updated timestamp file `/var/run/sudo/root/unknown'
userhelper[5210]: running '/usr/sbin/system-switch-im' with root privileges on behalf of 'root'
userhelper[5216]: pam_timestamp: updated timestamp file `/var/run/sudo/root/unknown'
userhelper[5219]: running '/usr/share/system-config-display/system-config-display' with root privileges on behalf of 'root'
userhelper[5295]: pam_timestamp: updated timestamp file `/var/run/sudo/root/unknown'
userhelper[5298]: running '/usr/sbin/system-config-services' with root privileges on behalf of 'root'

---------------------- Connections (secure-log) End -------------------------


--------------------- SSHD Begin ------------------------


SSHD Killed: 3 Time(s)

SSHD Started: 3 Time(s)

Failed to bind:
   0.0.0.0 port 22 (Address already in use) : 3 Time(s)

Failed logins from these:
   adm/password from ::ffff:95.77.196.171: 1 Time(s)
   apache/password from ::ffff:89.33.116.82: 1 Time(s)
   ftp/password from ::ffff:89.33.116.82: 1 Time(s)
   invalid/password from aaron: 1 Time(s)
   invalid/password from aarti: 1 Time(s)
   invalid/password from abc: 1 Time(s)
   invalid/password from abdenace: 1 Time(s)
   invalid/password from abdol: 1 Time(s)
   invalid/password from abdul: 1 Time(s)
   invalid/password from abdulkaf: 1 Time(s)
   invalid/password from abdullah: 1 Time(s)
   invalid/password from abdur: 1 Time(s)
   invalid/password from abhijit: 1 Time(s)
   invalid/password from abhiram: 1 Time(s)
   invalid/password from abraham: 1 Time(s)
   invalid/password from abrar: 1 Time(s)
   invalid/password from acacia: 1 Time(s)
   invalid/password from academia: 1 Time(s)
   invalid/password from academic: 1 Time(s)
   invalid/password from accept: 1 Time(s)
   invalid/password from access: 1 Time(s)
   invalid/password from ada: 1 Time(s)
   invalid/password from adam: 1 Time(s)
   invalid/password from adel: 1 Time(s)
   invalid/password from adi: 1 Time(s)
   invalid/password from adib: 1 Time(s)
   invalid/password from adine: 1 Time(s)
   invalid/password from admin: 8 Time(s)
   invalid/password from administrator: 1 Time(s)
   invalid/password from adrian: 1 Time(s)
   invalid/password from adrianna: 1 Time(s)
   invalid/password from adrianne: 1 Time(s)
   invalid/password from adrien: 1 Time(s)
   invalid/password from adrienne: 1 Time(s)
   invalid/password from adult: 1 Time(s)
   invalid/password from aeneas: 1 Time(s)
   invalid/password from aerobics: 1 Time(s)
   invalid/password from afrid: 1 Time(s)
   invalid/password from aggie: 1 Time(s)
   invalid/password from agnes: 1 Time(s)
   invalid/password from ahidee: 1 Time(s)
   invalid/password from ahmed: 1 Time(s)
   invalid/password from ahmet: 1 Time(s)
   invalid/password from aileen: 1 Time(s)
   invalid/password from aimee: 1 Time(s)
   invalid/password from airplane: 1 Time(s)
   invalid/password from ajai: 1 Time(s)
   invalid/password from ajay: 1 Time(s)
   invalid/password from akhil: 1 Time(s)
   invalid/password from akiko: 1 Time(s)
   invalid/password from alain: 1 Time(s)
   invalid/password from alamgir: 1 Time(s)
   invalid/password from alan: 1 Time(s)
   invalid/password from alastair: 1 Time(s)
   invalid/password from alias: 1 Time(s)
   invalid/password from core: 1 Time(s)
   invalid/password from cyrus: 1 Time(s)
   invalid/password from david: 1 Time(s)
   invalid/password from ftpuser: 1 Time(s)
   invalid/password from guest: 2 Time(s)
   invalid/password from info: 1 Time(s)
   invalid/password from library: 1 Time(s)
   invalid/password from linux: 1 Time(s)
   invalid/password from master: 1 Time(s)
   invalid/password from michael: 1 Time(s)
   invalid/password from mysql: 1 Time(s)
   invalid/password from nagios: 1 Time(s)
   invalid/password from newsletter: 1 Time(s)
   invalid/password from office: 1 Time(s)
   invalid/password from oracle: 3 Time(s)
   invalid/password from paul: 1 Time(s)
   invalid/password from pgsql: 1 Time(s)
   invalid/password from postfix: 1 Time(s)
   invalid/password from postgres: 1 Time(s)
   invalid/password from postmaster: 1 Time(s)
   invalid/password from recruit: 1 Time(s)
   invalid/password from sales: 1 Time(s)
   invalid/password from samba: 1 Time(s)
   invalid/password from si: 1 Time(s)
   invalid/password from spam: 1 Time(s)
   invalid/password from staff: 1 Time(s)
   invalid/password from test: 7 Time(s)
   invalid/password from tomcat: 1 Time(s)
   invalid/password from tony: 1 Time(s)
   invalid/password from user: 2 Time(s)
   invalid/password from username: 2 Time(s)
   invalid/password from virus: 1 Time(s)
   invalid/password from visitor: 1 Time(s)
   invalid/password from web: 1 Time(s)
   invalid/password from webadmin: 1 Time(s)
   invalid/password from webmaster: 2 Time(s)
   named/password from ::ffff:89.33.116.82: 1 Time(s)
   root/password from ::ffff:112.216.57.254: 89 Time(s)
   root/password from ::ffff:211.102.90.131: 16 Time(s)
   root/password from ::ffff:212.52.166.104: 26 Time(s)
   root/password from ::ffff:89.33.116.82: 11 Time(s)
   root/password from ::ffff:94.127.68.4: 6 Time(s)

Illegal users from these:
   Invalid/none from aaron: 1 Time(s)
   Invalid/none from aarti: 1 Time(s)
   Invalid/none from abc: 1 Time(s)
   Invalid/none from abdenace: 1 Time(s)
   Invalid/none from abdol: 1 Time(s)
   Invalid/none from abdul: 1 Time(s)
   Invalid/none from abdulkaf: 1 Time(s)
   Invalid/none from abdullah: 1 Time(s)
   Invalid/none from abdur: 1 Time(s)
   Invalid/none from abhijit: 1 Time(s)
   Invalid/none from abhiram: 1 Time(s)
   Invalid/none from abraham: 1 Time(s)
   Invalid/none from abrar: 1 Time(s)
   Invalid/none from acacia: 1 Time(s)
   Invalid/none from academia: 1 Time(s)
   Invalid/none from academic: 1 Time(s)
   Invalid/none from accept: 1 Time(s)
   Invalid/none from access: 1 Time(s)
   Invalid/none from ada: 1 Time(s)
   Invalid/none from adam: 1 Time(s)
   Invalid/none from adel: 1 Time(s)
   Invalid/none from adi: 1 Time(s)
   Invalid/none from adib: 1 Time(s)
   Invalid/none from adine: 1 Time(s)
   Invalid/none from admin: 8 Time(s)
   Invalid/none from administrator: 1 Time(s)
   Invalid/none from adrian: 1 Time(s)
   Invalid/none from adrianna: 1 Time(s)
   Invalid/none from adrianne: 1 Time(s)
   Invalid/none from adrien: 1 Time(s)
   Invalid/none from adrienne: 1 Time(s)
   Invalid/none from adult: 1 Time(s)
   Invalid/none from aeneas: 1 Time(s)
   Invalid/none from aerobics: 1 Time(s)
   Invalid/none from afrid: 1 Time(s)
   Invalid/none from aggie: 1 Time(s)
   Invalid/none from agnes: 1 Time(s)
   Invalid/none from ahidee: 1 Time(s)
   Invalid/none from ahmed: 1 Time(s)
   Invalid/none from ahmet: 1 Time(s)
   Invalid/none from aileen: 1 Time(s)
   Invalid/none from aimee: 1 Time(s)
   Invalid/none from airplane: 1 Time(s)
   Invalid/none from ajai: 1 Time(s)
   Invalid/none from ajay: 1 Time(s)
   Invalid/none from akhil: 1 Time(s)
   Invalid/none from akiko: 1 Time(s)
   Invalid/none from alain: 1 Time(s)
   Invalid/none from alamgir: 1 Time(s)
   Invalid/none from alan: 1 Time(s)
   Invalid/none from alastair: 1 Time(s)
   Invalid/none from alias: 1 Time(s)
   Invalid/none from core: 1 Time(s)
   Invalid/none from cyrus: 1 Time(s)
   Invalid/none from david: 1 Time(s)
   Invalid/none from ftpuser: 1 Time(s)
   Invalid/none from guest: 2 Time(s)
   Invalid/none from info: 1 Time(s)
   Invalid/none from library: 1 Time(s)
   Invalid/none from linux: 1 Time(s)
   Invalid/none from master: 1 Time(s)
   Invalid/none from michael: 1 Time(s)
   Invalid/none from mysql: 1 Time(s)
   Invalid/none from nagios: 1 Time(s)
   Invalid/none from newsletter: 1 Time(s)
   Invalid/none from office: 1 Time(s)
   Invalid/none from oracle: 3 Time(s)
   Invalid/none from paul: 1 Time(s)
   Invalid/none from pgsql: 1 Time(s)
   Invalid/none from postfix: 1 Time(s)
   Invalid/none from postgres: 1 Time(s)
   Invalid/none from postmaster: 1 Time(s)
   Invalid/none from recruit: 1 Time(s)
   Invalid/none from sales: 1 Time(s)
   Invalid/none from samba: 1 Time(s)
   Invalid/none from si: 1 Time(s)
   Invalid/none from spam: 1 Time(s)
   Invalid/none from staff: 1 Time(s)
   Invalid/none from test: 7 Time(s)
   Invalid/none from tomcat: 1 Time(s)
   Invalid/none from tony: 1 Time(s)
   Invalid/none from user: 2 Time(s)
   Invalid/none from username: 2 Time(s)
   Invalid/none from virus: 1 Time(s)
   Invalid/none from visitor: 1 Time(s)
   Invalid/none from web: 1 Time(s)
   Invalid/none from webadmin: 1 Time(s)
   Invalid/none from webmaster: 2 Time(s)
   invalid/none from unknown: 107 Time(s)
   invalid/password from aaron: 1 Time(s)
   invalid/password from aarti: 1 Time(s)
   invalid/password from abc: 1 Time(s)
   invalid/password from abdenace: 1 Time(s)
   invalid/password from abdol: 1 Time(s)
   invalid/password from abdul: 1 Time(s)
   invalid/password from abdulkaf: 1 Time(s)
   invalid/password from abdullah: 1 Time(s)
   invalid/password from abdur: 1 Time(s)
   invalid/password from abhijit: 1 Time(s)
   invalid/password from abhiram: 1 Time(s)
   invalid/password from abraham: 1 Time(s)
   invalid/password from abrar: 1 Time(s)
   invalid/password from acacia: 1 Time(s)
   invalid/password from academia: 1 Time(s)
   invalid/password from academic: 1 Time(s)
   invalid/password from accept: 1 Time(s)
   invalid/password from access: 1 Time(s)
   invalid/password from ada: 1 Time(s)
   invalid/password from adam: 1 Time(s)
   invalid/password from adel: 1 Time(s)
   invalid/password from adi: 1 Time(s)
   invalid/password from adib: 1 Time(s)
   invalid/password from adine: 1 Time(s)
   invalid/password from admin: 8 Time(s)
   invalid/password from administrator: 1 Time(s)
   invalid/password from adrian: 1 Time(s)
   invalid/password from adrianna: 1 Time(s)
   invalid/password from adrianne: 1 Time(s)
   invalid/password from adrien: 1 Time(s)
   invalid/password from adrienne: 1 Time(s)
   invalid/password from adult: 1 Time(s)
   invalid/password from aeneas: 1 Time(s)
   invalid/password from aerobics: 1 Time(s)
   invalid/password from afrid: 1 Time(s)
   invalid/password from aggie: 1 Time(s)
   invalid/password from agnes: 1 Time(s)
   invalid/password from ahidee: 1 Time(s)
   invalid/password from ahmed: 1 Time(s)
   invalid/password from ahmet: 1 Time(s)
   invalid/password from aileen: 1 Time(s)
   invalid/password from aimee: 1 Time(s)
   invalid/password from airplane: 1 Time(s)
   invalid/password from ajai: 1 Time(s)
   invalid/password from ajay: 1 Time(s)
   invalid/password from akhil: 1 Time(s)
   invalid/password from akiko: 1 Time(s)
   invalid/password from alain: 1 Time(s)
   invalid/password from alamgir: 1 Time(s)
   invalid/password from alan: 1 Time(s)
   invalid/password from alastair: 1 Time(s)
   invalid/password from alias: 1 Time(s)
   invalid/password from core: 1 Time(s)
   invalid/password from cyrus: 1 Time(s)
   invalid/password from david: 1 Time(s)
   invalid/password from ftpuser: 1 Time(s)
   invalid/password from guest: 2 Time(s)
   invalid/password from info: 1 Time(s)
   invalid/password from library: 1 Time(s)
   invalid/password from linux: 1 Time(s)
   invalid/password from master: 1 Time(s)
   invalid/password from michael: 1 Time(s)
   invalid/password from mysql: 1 Time(s)
   invalid/password from nagios: 1 Time(s)
   invalid/password from newsletter: 1 Time(s)
   invalid/password from office: 1 Time(s)
   invalid/password from oracle: 3 Time(s)
   invalid/password from paul: 1 Time(s)
   invalid/password from pgsql: 1 Time(s)
   invalid/password from postfix: 1 Time(s)
   invalid/password from postgres: 1 Time(s)
   invalid/password from postmaster: 1 Time(s)
   invalid/password from recruit: 1 Time(s)
   invalid/password from sales: 1 Time(s)
   invalid/password from samba: 1 Time(s)
   invalid/password from si: 1 Time(s)
   invalid/password from spam: 1 Time(s)
   invalid/password from staff: 1 Time(s)
   invalid/password from test: 7 Time(s)
   invalid/password from tomcat: 1 Time(s)
   invalid/password from tony: 1 Time(s)
   invalid/password from user: 2 Time(s)
   invalid/password from username: 2 Time(s)
   invalid/password from virus: 1 Time(s)
   invalid/password from visitor: 1 Time(s)
   invalid/password from web: 1 Time(s)
   invalid/password from webadmin: 1 Time(s)
   invalid/password from webmaster: 2 Time(s)

Users logging in through sshd:
   root:
      222.48.205.181: 3 times
      122.92.186.0: 2 times
      122.92.188.67: 1 time


Received disconnect:
   11: Bye Bye
      ::ffff:112.216.57.254 : 89 Time(s)
      ::ffff:211.102.90.131 : 19 Time(s)
      ::ffff:212.52.166.104 : 27 Time(s)
      ::ffff:89.33.116.82 : 65 Time(s)
      ::ffff:94.127.68.4 : 6 Time(s)
      ::ffff:95.77.196.171 : 50 Time(s)
   11: Disconnect requested by Windows SSH Client.
      ::ffff:122.92.186.0 : 1 Time(s)

SFTP subsystem requests: 4 Time(s)

---------------------- SSHD End -------------------------


--------------------- Sudo (secure-log) Begin ------------------------

==============================================================================
root => root
------------------------------------------------------------------------------
/usr/bin/apt-get install alien
/usr/bin/apt-get install dpkg
/usr/bin/apt-get install chinput
/usr/bin/apt-get update
/usr/bin/apt-get install scim scim-chinese scim-gtk2-immodule

---------------------- Sudo (secure-log) End -------------------------



------------------ Disk Space --------------------

/dev/mapper/VolGroup00-LogVol00
                      536G   88G  421G  18% /
/dev/sda1              99M   21M   74M  22% /boot


###################### LogWatch End #########################

From root@localhost.localdomain  Tue Mar 16 04:02:07 2010
Return-Path: <root@localhost.localdomain>
Received: from localhost.localdomain (localhost.localdomain [127.0.0.1])
        by localhost.localdomain (8.13.1/8.13.1) with ESMTP id o2FK27Po013446
        for <root@localhost.localdomain>; Tue, 16 Mar 2010 04:02:07 +0800
Received: (from root@localhost)
        by localhost.localdomain (8.13.1/8.13.1/Submit) id o2FK2610013444
        for root; Tue, 16 Mar 2010 04:02:06 +0800
Date: Tue, 16 Mar 2010 04:02:06 +0800
From: root <root@localhost.localdomain>
Message-Id: <201003152002.o2FK2610013444@localhost.localdomain>
To: root@localhost.localdomain
Subject: LogWatch for localhost.localdomain


################### LogWatch 5.2.2 (06/23/04) ####################
       Processing Initiated: Tue Mar 16 04:02:03 2010
       Date Range Processed: yesterday
     Detail Level of Output: 0
          Logfiles for Host: localhost.localdomain
################################################################

--------------------- Init Begin ------------------------

Re-execs of init: 1 times

---------------------- Init End -------------------------


--------------------- Kernel Begin ------------------------


WARNING:  Kernel Errors Present
   end_request: I/O error, dev fd0, sector...:  2 Time(s)

---------------------- Kernel End -------------------------


--------------------- pam_unix Begin ------------------------

sshd:
   Authentication Failures:
      unknown (218.69.106.45): 1857 Time(s)
      unknown (61.167.49.106): 170 Time(s)
      root (218.69.106.45): 50 Tim

论坛徽章:
381
CU十二周年纪念徽章
日期:2014-01-04 22:46:58CU大牛徽章
日期:2013-03-13 15:32:35CU大牛徽章
日期:2013-03-13 15:38:15CU大牛徽章
日期:2013-03-13 15:38:52CU大牛徽章
日期:2013-03-14 14:08:55CU大牛徽章
日期:2013-04-17 11:17:19CU大牛徽章
日期:2013-04-17 11:17:32CU大牛徽章
日期:2013-04-17 11:17:37CU大牛徽章
日期:2013-04-17 11:17:42CU大牛徽章
日期:2013-04-17 11:17:47CU大牛徽章
日期:2013-04-17 11:17:52CU大牛徽章
日期:2013-04-17 11:17:56
2 [报告]
发表于 2010-03-27 10:19 |只看该作者
好事的人真不少啊.

论坛徽章:
1
天秤座
日期:2013-10-23 13:20:42
3 [报告]
发表于 2010-03-27 14:47 |只看该作者
LZ是没见过试探性攻击,还是怎么地
我们放在公网上的服务器,经常一堆
要担心,开墙,禁ping啥的

有个一劳永逸的方法,不要在论坛上询问了

论坛徽章:
5
寅虎
日期:2015-01-20 09:16:52亥猪
日期:2015-01-21 14:43:44IT运维版块每日发帖之星
日期:2015-12-17 06:20:00每日论坛发贴之星
日期:2015-12-17 06:20:00每周论坛发贴之星
日期:2015-12-20 22:22:00
4 [报告]
发表于 2010-03-27 16:16 |只看该作者
ssh用key登錄,port改一下
禁止ping

论坛徽章:
0
5 [报告]
发表于 2010-03-28 16:14 |只看该作者
在上面问题记得把真实信息屏蔽。。

论坛徽章:
0
6 [报告]
发表于 2010-03-29 13:39 |只看该作者
好事之人真多啊。。。。lz写个脚本和防火墙联动不就得了。。。

论坛徽章:
0
7 [报告]
发表于 2010-03-29 14:30 |只看该作者
{:3_182:}
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP