Freesco, NND, CDN, EOS
http://forum.freesco.pl/

Atak ?!
http://forum.freesco.pl/viewtopic.php?f=22&t=10658
Strona 1 z 1

Autor:  djbass [ środa, 11 stycznia 2006, 10:53 ]
Tytuł:  Atak ?!

Od niedawna mam w logach "autch" coś takigo:
: [/] [] ()
Jan 11 09:40:39 adlan sshd[26438]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:40 adlan sshd[26448]: Invalid user christine from 216.118.117.62
Jan 11 09:40:40 adlan sshd[26448]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:40 adlan sshd[26448]: error: Could not get shadow information for NOUSER
Jan 11 09:40:40 adlan sshd[26448]: Failed password for invalid user christine from 216.118.117.62 port 33383 ssh2
Jan 11 09:40:40 adlan sshd[26448]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:41 adlan sshd[26451]: Invalid user christine from 216.118.117.62
Jan 11 09:40:41 adlan sshd[26451]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:41 adlan sshd[26451]: error: Could not get shadow information for NOUSER
Jan 11 09:40:41 adlan sshd[26451]: Failed password for invalid user christine from 216.118.117.62 port 33645 ssh2
Jan 11 09:40:41 adlan sshd[26451]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:43 adlan sshd[26460]: Invalid user christine from 216.118.117.62
Jan 11 09:40:43 adlan sshd[26460]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:43 adlan sshd[26460]: error: Could not get shadow information for NOUSER
Jan 11 09:40:43 adlan sshd[26460]: Failed password for invalid user christine from 216.118.117.62 port 33889 ssh2
Jan 11 09:40:43 adlan sshd[26460]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:44 adlan sshd[26463]: Invalid user christine from 216.118.117.62
Jan 11 09:40:44 adlan sshd[26463]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:44 adlan sshd[26463]: error: Could not get shadow information for NOUSER
Jan 11 09:40:44 adlan sshd[26463]: Failed password for invalid user christine from 216.118.117.62 port 34139 ssh2
Jan 11 09:40:44 adlan sshd[26463]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:45 adlan sshd[26470]: Invalid user claire from 216.118.117.62
Jan 11 09:40:46 adlan sshd[26470]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:46 adlan sshd[26470]: error: Could not get shadow information for NOUSER
Jan 11 09:40:46 adlan sshd[26470]: Failed password for invalid user claire from 216.118.117.62 port 34405 ssh2
Jan 11 09:40:46 adlan sshd[26470]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:47 adlan sshd[26473]: Invalid user claire from 216.118.117.62
Jan 11 09:40:47 adlan sshd[26473]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:47 adlan sshd[26473]: error: Could not get shadow information for NOUSER
Jan 11 09:40:47 adlan sshd[26473]: Failed password for invalid user claire from 216.118.117.62 port 34666 ssh2
Jan 11 09:40:47 adlan sshd[26473]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:48 adlan sshd[26481]: Invalid user claire from 216.118.117.62
Jan 11 09:40:48 adlan sshd[26481]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:48 adlan sshd[26481]: error: Could not get shadow information for NOUSER
Jan 11 09:40:48 adlan sshd[26481]: Failed password for invalid user claire from 216.118.117.62 port 34925 ssh2
Jan 11 09:40:48 adlan sshd[26481]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:50 adlan sshd[26483]: Invalid user claire from 216.118.117.62
Jan 11 09:40:50 adlan sshd[26483]: Excess permission or bad ownership on file /var/log/btmp
Jan 11 09:40:50 adlan sshd[26483]: error: Could not get shadow information for NOUSER
Jan 11 09:40:50 adlan sshd[26483]: Failed password for invalid user claire from 216.118.117.62 port 35182 ssh2
Jan 11 09:40:50 adlan sshd[26483]: Excess permission or bad ownership on file /var/log/btmp

Wiem ze ktoś prawdopodobnie skanuje wszyskie porty i probuje znależć hasło
Jak się pozbyć takiego delikwenta?
Proszę o pomoc !!!

Autor:  KrzySie [ środa, 11 stycznia 2006, 11:25 ]
Tytuł: 

Wielokrotnie już to wałkowane.
Przekieruj port ssh na inny jak chcesz mieć dostęp z internetu do swego routarka.
Nie chcesz to w /etc/rc.conf SSH=0
Ew. zmiany zapisów w hosts.alow i hosts.deny

Autor:  djbass [ środa, 11 stycznia 2006, 11:55 ]
Tytuł: 

KrzySie pisze:
Wielokrotnie już to wałkowane.
Przekieruj port ssh na inny jak chcesz mieć dostęp z internetu do swego routarka.
Nie chcesz to w /etc/rc.conf SSH=0
Ew. zmiany zapisów w hosts.alow i hosts.deny

Ok dzieki zrobilem jak kazałeś teraz czekam na efekty
Pozdr

Autor:  Jacq [ środa, 11 stycznia 2006, 11:57 ]
Tytuł: 

jest jeszcze możliwość zastosowania pewnej pułapki, ale to musze sprawdzić dopiero. Jak już przywrócą mi net to może.... ;)

Strona 1 z 1 Strefa czasowa UTC+2godz.
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/