Witam
Problem jest taki
Otoz od jakiegos czasu mam takie logi
Cytuj:
Feb 22 14:12:57 router sshd[22267]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:12:57 router sshd[22267]: error: Could not get shadow information for NOUSER
Feb 22 14:12:57 router sshd[22267]: Failed password for invalid user eleve from 213.214.76.227 port 54731 ssh2
Feb 22 14:12:57 router sshd[22267]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:12:58 router sshd[22269]: Invalid user proxy from 213.214.76.227
Feb 22 14:12:58 router sshd[22269]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:12:58 router sshd[22269]: error: Could not get shadow information for NOUSER
Feb 22 14:12:58 router sshd[22269]: Failed password for invalid user proxy from 213.214.76.227 port 54794 ssh2
Feb 22 14:12:58 router sshd[22269]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:00 router sshd[22272]: Invalid user sys from 213.214.76.227
Feb 22 14:13:00 router sshd[22272]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:00 router sshd[22272]: error: Could not get shadow information for NOUSER
Feb 22 14:13:00 router sshd[22272]: Failed password for invalid user sys from 213.214.76.227 port 54850 ssh2
Feb 22 14:13:00 router sshd[22272]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:01 router sshd[22274]: Invalid user zzz from 213.214.76.227
Feb 22 14:13:01 router sshd[22274]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:01 router sshd[22274]: error: Could not get shadow information for NOUSER
Feb 22 14:13:01 router sshd[22274]: Failed password for invalid user zzz from 213.214.76.227 port 54896 ssh2
Feb 22 14:13:01 router sshd[22274]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:02 router sshd[22277]: Invalid user frank from 213.214.76.227
Feb 22 14:13:02 router sshd[22277]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:02 router sshd[22277]: error: Could not get shadow information for NOUSER
Feb 22 14:13:02 router sshd[22277]: Failed password for invalid user frank from 213.214.76.227 port 54941 ssh2
Feb 22 14:13:02 router sshd[22277]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:05 router sshd[22280]: Invalid user dan from 213.214.76.227
Feb 22 14:13:05 router sshd[22280]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:05 router sshd[22280]: error: Could not get shadow information for NOUSER
Feb 22 14:13:05 router sshd[22280]: Failed password for invalid user dan from 213.214.76.227 port 55007 ssh2
Feb 22 14:13:05 router sshd[22280]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:06 router sshd[22283]: Invalid user james from 213.214.76.227
Feb 22 14:13:07 router sshd[22283]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:07 router sshd[22283]: error: Could not get shadow information for NOUSER
Feb 22 14:13:07 router sshd[22283]: Failed password for invalid user james from 213.214.76.227 port 55134 ssh2
Feb 22 14:13:07 router sshd[22283]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:08 router sshd[22285]: Invalid user snort from 213.214.76.227
Feb 22 14:13:08 router sshd[22285]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:08 router sshd[22285]: error: Could not get shadow information for NOUSER
Feb 22 14:13:08 router sshd[22285]: Failed password for invalid user snort from 213.214.76.227 port 55187 ssh2
Feb 22 14:13:08 router sshd[22285]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:10 router sshd[22288]: Invalid user radiomail from 213.214.76.227
Feb 22 14:13:10 router sshd[22288]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:10 router sshd[22288]: error: Could not get shadow information for NOUSER
Feb 22 14:13:10 router sshd[22288]: Failed password for invalid user radiomail from 213.214.76.227 port 55260 ssh2
Feb 22 14:13:10 router sshd[22288]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:11 router sshd[22291]: Invalid user harrypotter from 213.214.76.227
Feb 22 14:13:11 router sshd[22291]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:11 router sshd[22291]: error: Could not get shadow information for NOUSER
Feb 22 14:13:11 router sshd[22291]: Failed password for invalid user harrypotter from 213.214.76.227 port 55335 ssh2
Feb 22 14:13:11 router sshd[22291]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:12 router sshd[22293]: Invalid user divine from 213.214.76.227
Feb 22 14:13:12 router sshd[22293]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:12 router sshd[22293]: error: Could not get shadow information for NOUSER
Feb 22 14:13:12 router sshd[22293]: Failed password for invalid user divine from 213.214.76.227 port 55412 ssh2
Feb 22 14:13:12 router sshd[22293]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:14 router sshd[22296]: Invalid user popa3d from 213.214.76.227
Feb 22 14:13:14 router sshd[22296]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:14 router sshd[22296]: error: Could not get shadow information for NOUSER
Feb 22 14:13:14 router sshd[22296]: Failed password for invalid user popa3d from 213.214.76.227 port 55480 ssh2
Feb 22 14:13:14 router sshd[22296]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:15 router sshd[22298]: Invalid user aptproxy from 213.214.76.227
Feb 22 14:13:15 router sshd[22298]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:15 router sshd[22298]: error: Could not get shadow information for NOUSER
Feb 22 14:13:15 router sshd[22298]: Failed password for invalid user aptproxy from 213.214.76.227 port 55558 ssh2
Feb 22 14:13:15 router sshd[22298]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:19 router sshd[22300]: Invalid user desktop from 213.214.76.227
Feb 22 14:13:19 router sshd[22300]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:19 router sshd[22300]: error: Could not get shadow information for NOUSER
Feb 22 14:13:19 router sshd[22300]: Failed password for invalid user desktop from 213.214.76.227 port 55614 ssh2
Feb 22 14:13:19 router sshd[22300]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:20 router sshd[22302]: Invalid user workshop from 213.214.76.227
Feb 22 14:13:20 router sshd[22302]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:20 router sshd[22302]: error: Could not get shadow information for NOUSER
Feb 22 14:13:20 router sshd[22302]: Failed password for invalid user workshop from 213.214.76.227 port 55822 ssh2
Feb 22 14:13:20 router sshd[22302]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:21 router sshd[22304]: Invalid user mailnull from 213.214.76.227
Feb 22 14:13:21 router sshd[22304]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:21 router sshd[22304]: error: Could not get shadow information for NOUSER
Feb 22 14:13:21 router sshd[22304]: Failed password for invalid user mailnull from 213.214.76.227 port 55890 ssh2
Feb 22 14:13:21 router sshd[22304]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:22 router sshd[22306]: Invalid user nfsnobody from 213.214.76.227
Feb 22 14:13:22 router sshd[22306]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:22 router sshd[22306]: error: Could not get shadow information for NOUSER
Feb 22 14:13:22 router sshd[22306]: Failed password for invalid user nfsnobody from 213.214.76.227 port 55950 ssh2
Feb 22 14:13:22 router sshd[22306]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:23 router sshd[22308]: Invalid user rpcuser from 213.214.76.227
Feb 22 14:13:23 router sshd[22308]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:23 router sshd[22308]: error: Could not get shadow information for NOUSER
Feb 22 14:13:23 router sshd[22308]: Failed password for invalid user rpcuser from 213.214.76.227 port 56016 ssh2
Feb 22 14:13:23 router sshd[22308]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:25 router sshd[22310]: Invalid user rpc from 213.214.76.227
Feb 22 14:13:25 router sshd[22310]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:25 router sshd[22310]: error: Could not get shadow information for NOUSER
Feb 22 14:13:25 router sshd[22310]: Failed password for invalid user rpc from 213.214.76.227 port 56090 ssh2
Feb 22 14:13:25 router sshd[22310]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:26 router sshd[22312]: Invalid user gopher from 213.214.76.227
Feb 22 14:13:26 router sshd[22312]: Excess permission or bad ownership on file /var/log/btmp
Feb 22 14:13:26 router sshd[22312]: error: Could not get shadow information for NOUSER
Feb 22 14:13:26 router sshd[22312]: Failed password for invalid user gopher from 213.214.76.227 port 56158 ssh2
Feb 22 14:13:26 router sshd[22312]: Excess permission or bad ownership on file /var/log/btmp
Domyslam sie ze ktos chce zalogowac sie na moj komputer przez ssh. Moze to jest atak brute force ?? Tzn to tylko takie przypuszczenia.
Pytanie moje jest nastepujace jak moge sie zabezpieczyc przed takim czyms ? Potrzebuje ssh do logowania sie z domu na serwer wiec zablokowanie go przez firewall odpada.
Ewentualnie moglbym zablokowac to IP jednak czasem zdaza sie tez taka proba z innych IP
Pozdrawiam