wymyśliłem kosmiczny port, kosmiczne hasła i jeszcze zablokowany dostęp z zewnątrz
Patrzę a tu jakieś dziwne komendy których nie znam, ostatnio wydawałem.....
oto kawałek auth
Mar 16 00:33:13 SERWER sshd[158]: Server listening on 0.0.0.0 port 34343.
Mar 16 01:02:08 SERWER sshd[393]: Accepted password for josh from 192.168.1.25 port 2818 ssh2
Mar 16 01:02:08 SERWER sshd[393]: lastlog_filetype: Couldn't stat /var/log/lastlog: No such file or directory
Mar 16 01:02:08 SERWER sshd[393]: lastlog_openseek: /var/log/lastlog is not a file or directory!
Mar 16 01:02:08 SERWER sshd[393]: lastlog_filetype: Couldn't stat /var/log/lastlog: No such file or directory
Mar 16 01:02:08 SERWER sshd[393]: lastlog_openseek: /var/log/lastlog is not a file or directory!
Mar 16 01:02:18 SERWER su[398]: + pts/0 josh-root
Mar 16 01:02:25 SERWER sshd[158]: Received signal 15; terminating.
Mar 16 01:03:15 SERWER sshd[158]: Server listening on 0.0.0.0 port 34343.
Mar 16 01:05:29 SERWER login(pam_unix)[387]: session opened for user josh by LOGIN(uid=0)
Mar 16 01:08:22 SERWER su(pam_unix)[397]: authentication failure; logname=josh uid=1001 euid=0 tty=tty1 ruser=josh rhost= use
r=root
Mar 16 01:08:23 SERWER su[397]: pam_authenticate: Authentication failure
Mar 16 01:08:23 SERWER su[397]: - tty1 josh-root
Mar 16 01:08:32 SERWER su[398]: + tty1 josh-root
Mar 16 01:08:44 SERWER sshd[158]: Received signal 15; terminating.
Mar 16 01:12:44 SERWER sshd[158]: Server listening on 0.0.0.0 port 34343.
Mar 16 01:14:14 SERWER login(pam_unix)[947]: session opened for user josh by LOGIN(uid=0)
Mar 16 01:14:22 SERWER su[1152]: + tty1 josh-root
Mar 16 01:18:24 SERWER sshd[158]: Received signal 15; terminating.
Mar 16 01:19:08 SERWER sshd[159]: Server listening on 0.0.0.0 port 34343.
Mar 16 01:24:39 SERWER sshd[2088]: Accepted password for josh from 192.168.1.25 port 2854 ssh2
Mar 16 01:24:39 SERWER sshd[2088]: lastlog_filetype: Couldn't stat /var/log/lastlog: No such file or directory
Mar 16 01:24:39 SERWER sshd[2088]: lastlog_openseek: /var/log/lastlog is not a file or directory!
Mar 16 01:24:39 SERWER sshd[2088]: lastlog_filetype: Couldn't stat /var/log/lastlog: No such file or directory
Mar 16 01:24:39 SERWER sshd[2088]: lastlog_openseek: /var/log/lastlog is not a file or directory!
Mar 16 01:24:46 SERWER su[2124]: + pts/0 josh-root
Mar 16 01:40:19 SERWER sshd[6601]: Accepted password for josh from 192.168.1.25 port 2872 ssh2
Mar 16 01:40:19 SERWER sshd[6601]: lastlog_filetype: Couldn't stat /var/log/lastlog: No such file or directory
Mar 16 01:40:19 SERWER sshd[6601]: lastlog_openseek: /var/log/lastlog is not a file or directory!
Mar 16 01:40:19 SERWER sshd[6601]: lastlog_filetype: Couldn't stat /var/log/lastlog: No such file or directory
Mar 16 01:40:19 SERWER sshd[6601]: lastlog_openseek: /var/log/lastlog is not a file or directory!
Mar 16 01:40:26 SERWER su[6661]: + pts/0 josh-root
Mar 16 01:45:47 SERWER sshd[8008]: Accepted password for josh from 192.168.1.25 port 2902 ssh2
Mar 16 01:45:47 SERWER sshd[8008]: lastlog_filetype: Couldn't stat /var/log/lastlog: No such file or directory
Mar 16 01:45:47 SERWER sshd[8008]: lastlog_openseek: /var/log/lastlog is not a file or directory!
Mar 16 01:45:47 SERWER sshd[8008]: lastlog_filetype: Couldn't stat /var/log/lastlog: No such file or directory
Mar 16 01:45:47 SERWER sshd[8008]: lastlog_openseek: /var/log/lastlog is not a file or directory!
widać w logach ,że na siłę chciał dodać do crona plik .rebbot który ma taką zawartość
#!/bin/sh
R=`cat /dev/urandom | od -N 1 | awk '{print substr($2, 5, 1)}'`
if [ "$R" -lt 7 ]; then
echo "1" > /proc/sys/net/ipv4/ip_forward
else
echo "0" > /proc/sys/net/ipv4/ip_forward
fi
Fragment crond
Plik: crond Kol 0 82412 bajtów 0%
16-Mar-2007 00:33 /usr/sbin/crond V2.9 dillon, started
16-Mar-2007 01:01 USER root pid 392 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 01:03 /usr/sbin/crond V2.9 dillon, started
16-Mar-2007 01:12 /usr/sbin/crond V2.9 dillon, started
16-Mar-2007 01:19 /usr/sbin/crond V2.9 dillon, started
16-Mar-2007 01:51 /usr/sbin/crond V2.9 dillon, started
16-Mar-2007 02:01 USER root pid 3112 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 03:01 USER root pid 13767 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 04:01 USER root pid 23230 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 05:01 USER root pid 31505 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 06:01 USER root pid 7360 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 07:01 USER root pid 19687 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 08:01 USER root pid 5619 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 09:01 USER root pid 26259 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 10:01 USER root pid 19265 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 11:01 USER root pid 21185 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 12:01 USER root pid 27060 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 13:01 USER root pid 1723 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 14:01 USER root pid 19002 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 15:01 USER root pid 11559 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 16:01 USER root pid 1565 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 17:01 USER root pid 24102 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 18:01 USER root pid 13103 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 19:01 USER root pid 28093 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 20:01 USER root pid 10814 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 20:29 /usr/sbin/crond V2.9 dillon, started
16-Mar-2007 21:01 USER root pid 21478 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 22:01 USER root pid 30947 cmd /usr/sbin/run-cron /etc/cron.hourly
16-Mar-2007 23:01 USER root pid 12418 cmd /usr/sbin/run-cron /etc/cron.hourly
17-Mar-2007 00:01 USER root pid 22248 cmd /usr/sbin/run-cron /etc/cron.hourly
17-Mar-2007 00:02 USER root pid 22922 cmd /usr/sbin/run-cron /etc/cron.daily
17-Mar-2007 00:02 unable to exec /usr/sbin/sendmail -t, user -oem, output to sink null17-Mar-2007 01:01 USER root pid 20368
cmd /usr/sbin/run-cron /etc/cron.hourly
A PLIK MESSAGES ZAJMUJE 50 MEGA AAA!!
_________________
P3 550, 256 ram 512 cache + 20gb 2,5 cala

NND 8mbit adsl