messages 로그인데 간단한 해석좀 해주시면 안될까나요~
Apr 22 08:52:35 localhost sshd[19957]: connection from "125.210.34.228"
Apr 22 08:52:35 localhost sshd[19957]: Wrong password given for user 'root'.
Apr 22 08:52:35 localhost sshd[19958]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:36 localhost sshd[19958]: connection from "125.210.34.228"
Apr 22 08:52:36 localhost sshd[19958]: Wrong password given for user 'root'.
Apr 22 08:52:36 localhost sshd[19959]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:36 localhost sshd[19959]: password authentication failed. Login to account mythtv not allowed or account non-existent.
Apr 22 08:52:37 localhost sshd[19960]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:37 localhost sshd[19960]: password authentication failed. Login to account mythtv not allowed or account non-existent.
Apr 22 08:52:37 localhost sshd[19961]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:38 localhost sshd[19961]: password authentication failed. Login to account apache not allowed or account non-existent.
Apr 22 08:52:38 localhost sshd[19962]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:39 localhost sshd[19962]: password authentication failed. Login to account apache not allowed or account non-existent.
Apr 22 08:52:39 localhost sshd[19963]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:40 localhost sshd[19963]: password authentication failed. Login to account apache not allowed or account non-existent.
Apr 22 08:52:40 localhost sshd[19964]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:41 localhost sshd[19964]: password authentication failed. Login to account cvsroot not allowed or account non-existent.
Apr 22 08:52:41 localhost sshd[19965]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:42 localhost sshd[19965]: password authentication failed. Login to account cvsroot not allowed or account non-existent.
Apr 22 08:52:42 localhost sshd[19966]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:43 localhost sshd[19966]: password authentication failed. Login to account cvsroot not allowed or account non-existent.
Apr 22 08:52:43 localhost sshd[19967]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:43 localhost sshd[19967]: connection from "125.210.34.228"
Apr 22 08:52:43 localhost sshd[19967]: Wrong password given for user 'mysql'.
Apr 22 08:52:44 localhost sshd[19968]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:44 localhost sshd[19968]: connection from "125.210.34.228"
Apr 22 08:52:44 localhost sshd[19968]: Wrong password given for user 'mysql'.
Apr 22 08:52:45 localhost sshd[19969]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:45 localhost sshd[19969]: connection from "125.210.34.228"
Apr 22 08:52:45 localhost sshd[19969]: Wrong password given for user 'mysql'.
Apr 22 08:52:45 localhost sshd[19970]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:46 localhost sshd[19970]: password authentication failed. Login to account nagios not allowed or account non-existent.
Apr 22 08:52:46 localhost sshd[19971]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:47 localhost sshd[19971]: password authentication failed. Login to account nagios not allowed or account non-existent.
Apr 22 08:52:47 localhost sshd[19972]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:48 localhost sshd[19972]: password authentication failed. Login to account nagios not allowed or account non-existent.
Apr 22 08:52:48 localhost sshd[19973]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:49 localhost sshd[19973]: password authentication failed. Login to account notes not allowed or account non-existent.
Apr 22 08:52:49 localhost sshd[19974]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:50 localhost sshd[19974]: password authentication failed. Login to account notes not allowed or account non-existent.
Apr 22 08:52:50 localhost sshd[19975]: DNS lookup failed for "125.210.34.228".
Apr 22 08:52:51 localhost sshd[19975]: password authentication failed. Login to account notes not allowed or account non-existent.
Apr 22 08:59:31 localhost : error getting update info: Cannot find a valid baseurl for repo: base
Apr 22 09:01:32 localhost sshd[19877]: LoginGraceTime exceeded.
Apr 22 09:01:33 localhost sshd[19878]: LoginGraceTime exceeded.
Apr 22 09:01:34 localhost sshd[19879]: LoginGraceTime exceeded.
Apr 22 09:01:35 localhost sshd[19880]: LoginGraceTime exceeded.
Apr 22 09:01:36 localhost sshd[19881]: LoginGraceTime exceeded.
누군가 접속시도를 하고있는건지(자동?) 아이피는 다르지만 이런게 좀 많아서 ;;;
마지막에 LoginGraceTime exceeded.여기서 마음한구석이 찜찜합니다 ㅜ.ㅜ
그리고 가끔가다 국내 ip도 눈에 띄던데 의도적인건가요?
단순한 사전식
단순한 사전식 공격이군요. ssh 포트만 바꾸면 일부는 잡을 수 있습니다만, 서버를 돌리고 있는 이상 피할 수 있는 방법은 없습니다.
---- 절취선 ----
http://blog.peremen.name
댓글 감사합니다~
ssh 포트를 한번 바꿔봐야 되겠군요~
LoginGraceTime exceeded. 이게 로그인된건 설마 아니겠죠 ;;;
제..취미는...삽질......입니다 -_-;;;
댓글 달기