- 论坛徽章:
- 0
|
系统:Asianux
内核:2.6.9-11.19AX
主机名:frank
查了一下年初的记录,/var/log/messages的其中的几部分吓了我一跳, 有人在试图用ssh 登陆我的系统! 吓的我直冒冷汗,第一个家伙(1月3号,6号,8号)来自小日本,后面两个一个是北京,一个是上海的IP,我的主机名是frank,把它们记录在此让大家 看看,千万不可大意,注意防范,别让肮脏的狗钻了空子:
Jan 3 02:09:43 frank sshd(pam_unix)[4567]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=58x156x7x92.ap58.ftth.ucom.ne.jp
Jan 3 02:09:49 frank sshd(pam_unix)[4569]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=58x156x7x92.ap58.ftth.ucom.ne.jp
Jan 3 02:09:54 frank sshd(pam_unix)[4571]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=58x156x7x92.ap58.ftth.ucom.ne.jp
Jan 3 02:10:00 frank sshd(pam_unix)[4573]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=58x156x7x92.ap58.ftth.ucom.ne.jp
Jan 3 02:10:07 frank sshd(pam_unix)[4575]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=58x156x7x92.ap58.ftth.ucom.ne.jp
Jan 3 02:10:12 frank sshd(pam_unix)[4577]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=58x156x7x92.ap58.ftth.ucom.ne.jp
Jan 3 02:10:18 frank sshd(pam_unix)[4579]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=58x156x7x92.ap58.ftth.ucom.ne.jp
Jan 3 02:10:33 frank sshd(pam_unix)[4581]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=58x156x7x92.ap58.ftth.ucom.ne.jp
Jan 6 16:49:29 frank sshd(pam_unix)[5114]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=222.106.22.248
Jan 8 04:36:07 frank sshd(pam_unix)[4404]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=j076189.ppp.asahi-net.or.jp
Jan 8 04:36:15 frank sshd(pam_unix)[4406]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=j076189.ppp.asahi-net.or.jp
Jan 12 02:58:15 frank sshd(pam_unix)[4983]: authentication failure; logname= uid=0 euid=0 tty=ss
h ruser= rhost=222.73.4.119
Jan 12 02:58:22 frank sshd(pam_unix)[4985]: check pass; user unknown
Jan 12 02:58:22 frank sshd(pam_unix)[4985]: authentication failure; logname= uid=0 euid=0 tty=ss
h ruser= rhost=222.73.4.119
Jan 12 02:58:27 frank sshd(pam_unix)[4987]: check pass; user unknown
Jan 12 02:58:27 frank sshd(pam_unix)[4987]: authentication failure; logname= uid=0 euid=0 tty=ss
h ruser= rhost=222.73.4.119
Jan 12 02:58:32 frank sshd(pam_unix)[4989]: check pass; user unknown
Jan 12 02:58:32 frank sshd(pam_unix)[4989]: authentication failure; logname= uid=0 euid=0 tty=ss
h ruser= rhost=222.73.4.119
Jan 12 02:58:37 frank sshd(pam_unix)[4991]: check pass; user unknown
Jan 12 02:58:37 frank sshd(pam_unix)[4991]: authentication failure; logname= uid=0 euid=0 tty=ss
h ruser= rhost=222.73.4.119
Jan 12 02:58:44 frank sshd(pam_unix)[4993]: check pass; user unknown
Jan 12 02:58:44 frank sshd(pam_unix)[4993]: authentication failure; logname= uid=0 euid=0 tty=ss
h ruser= rhost=222.73.4.119
Jan 12 02:58:55 frank sshd(pam_unix)[4998]: check pass; user unknown
Jan 12 02:58:55 frank sshd(pam_unix)[4998]: authentication failure; logname= uid=0 euid=0 tty=ss
h ruser= rhost=222.73.4.119
Jan 20 07:11:07 frank sshd(pam_unix)[4755]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=211.94.73.182
Jan 20 07:11:10 frank sshd(pam_unix)[4757]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=211.94.73.182
Jan 20 07:11:13 frank sshd(pam_unix)[4759]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=211.94.73.182
Jan 20 07:11:17 frank sshd(pam_unix)[4761]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=211.94.73.182
Jan 20 07:11:20 frank sshd(pam_unix)[4763]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=211.94.73.182
Jan 20 07:11:23 frank sshd(pam_unix)[4765]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=211.94.73.182
Jan 20 07:11:27 frank sshd(pam_unix)[4767]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=211.94.73.182
Jan 20 07:11:30 frank sshd(pam_unix)[4769]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=211.94.73.182
Jan 20 07:11:33 frank sshd(pam_unix)[4771]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=211.94.73.182
[ 本帖最后由 scudetto 于 2006-7-5 02:49 编辑 ] |
|