로그좀 봐주세요.
글쓴이: darkduck / 작성시간: 수, 2005/05/18 - 1:52오후
May 17 14:41:58 ns sshd(pam_unix)[8479]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:42:01 ns sshd(pam_unix)[8481]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:42:06 ns sshd(pam_unix)[8483]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:42:09 ns sshd(pam_unix)[8485]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:42:12 ns sshd(pam_unix)[8487]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:42:16 ns sshd(pam_unix)[8489]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:42:22 ns sshd(pam_unix)[8491]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:42:27 ns sshd(pam_unix)[8493]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:42:33 ns sshd(pam_unix)[8495]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:42:37 ns sshd(pam_unix)[8497]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:42:41 ns sshd(pam_unix)[8499]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:42:48 ns sshd(pam_unix)[8501]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:42:51 ns sshd(pam_unix)[8503]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:42:58 ns sshd(pam_unix)[8505]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:43:01 ns sshd(pam_unix)[8507]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:43:04 ns sshd(pam_unix)[8509]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net user=root May 17 14:43:08 ns sshd(pam_unix)[8511]: check pass; user unknown May 17 14:43:08 ns sshd(pam_unix)[8511]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net May 17 14:43:11 ns sshd(pam_unix)[8513]: check pass; user unknown May 17 14:43:11 ns sshd(pam_unix)[8513]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net May 17 14:43:14 ns sshd(pam_unix)[8515]: check pass; user unknown May 17 14:43:14 ns sshd(pam_unix)[8515]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net May 17 14:43:18 ns sshd(pam_unix)[8517]: check pass; user unknown May 17 14:43:18 ns sshd(pam_unix)[8517]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net May 17 14:43:21 ns sshd(pam_unix)[8519]: check pass; user unknown May 17 14:43:21 ns sshd(pam_unix)[8519]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net May 17 14:43:24 ns sshd(pam_unix)[8522]: check pass; user unknown May 17 14:43:24 ns sshd(pam_unix)[8522]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net May 17 14:43:32 ns sshd(pam_unix)[8527]: check pass; user unknown May 17 14:43:32 ns sshd(pam_unix)[8527]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net May 17 14:43:38 ns sshd(pam_unix)[8529]: check pass; user unknown May 17 14:43:38 ns sshd(pam_unix)[8529]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net May 17 14:43:42 ns sshd(pam_unix)[8531]: check pass; user unknown May 17 14:43:42 ns sshd(pam_unix)[8531]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net May 17 14:43:49 ns sshd(pam_unix)[8533]: check pass; user unknown May 17 14:43:49 ns sshd(pam_unix)[8533]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net May 17 14:43:52 ns sshd(pam_unix)[8536]: check pass; user unknown May 17 14:43:52 ns sshd(pam_unix)[8536]: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=c207.134.68-214.clta.globetrotter.net May 17 14:43:57 ns sshd(pam_unix)[8540]: check pass; user unknown
이런식의 로그가 계속 생기는데...
로봇에 의한건지?..
ssh 접근을 하는것 같은데... 보통 어떻게 조치를 취하시는지요?
Forums:
iptable을 사용하신다면 block을 거세요.그리고 ssh나 te
iptable을 사용하신다면 block을 거세요.
그리고 ssh나 telnet모두 root로는 접근이 불가능하도록 설정을 바꾸시면 됩니다.
(최근 배포판이라면 기본적으로 막혀있을겁니다.)
자세한건 man을 이용하세요.
------------------------------
좋은 하루 되세요.
댓글 달기