2005/Aug/16

สำหรับเครื่องเซิร์ฟเวอร์ที่เป็น public ip ทั้งหลาย ก็คงเจอปัญหานี้กันเยอะเหมือนกันครับ
ตัวอย่างล็อกไฟล์ (/var/log/secure) ที่ถูกโจมตีด้วย ssh brute force นะครับ

Jun 23 07:22:39 campus sshd[60775]: Failed password for root from 212.160.184.82 port 38212 ssh2
Jun 23 07:22:42 campus sshd[60777]: Failed password for root from 212.160.184.82 port 38626 ssh2
Jun 23 07:22:46 campus sshd[60779]: Failed password for root from 212.160.184.82 port 39056 ssh2
Jun 23 07:22:50 campus sshd[60781]: Failed password for root from 212.160.184.82 port 39348 ssh2
Jun 23 07:22:54 campus sshd[60783]: Failed password for root from 212.160.184.82 port 39621 ssh2
Jun 23 07:22:58 campus sshd[60785]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:01 campus sshd[60787]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:05 campus sshd[60789]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:09 campus sshd[60791]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:13 campus sshd[60793]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:16 campus sshd[60795]: Illegal user johnny from 212.160.184.82

เราสามารถป้องกันการโจมตีด้วย iptables นะครับ

iptables -I INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent --set
iptables -I INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent --update --seconds 600 --hitcount 2 -j DROP

ปัญหาดังกล่าวก็จะหมดไปครับ

ชื่อ: 
เว็บไซต์: 
คอมเมนต์:




smilebig smileopen-mounthed smileconfused smilesad smileangry smiletonguequestionembarrassedsurprised smilewinkdouble winkcry
#651  by  the (217.167.7.6) At 2009-01-06 15:50, 
#652  by  the (202.213.135.230) At 2009-01-06 16:06, 
#653  by  the (213.248.50.104) At 2009-01-06 16:12, 
mvwxcio zpsj sfzwr
http://pl777.free.bg/thed3a.html the
#653  by  the (80.54.237.241) At 2009-01-06 16:12, 
#653  by  the (72.51.31.19) At 2009-01-06 16:12, 
#653  by  the (24.189.163.116) At 2009-01-06 16:12, 
#657  by  the (194.153.92.172) At 2009-01-06 17:09, 
meulbtz adke vuemn jbqd
http://fekcivc.rack111.com/christmase70.html christmas
#658  by  christmas (41.161.16.26) At 2009-01-06 17:16, 
#659  by  the (91.121.159.202) At 2009-01-06 17:31, 
#660  by  christmas (41.161.16.26) At 2009-01-06 17:35, 
rjqy tygrs igoysvr iyrumfw
http://czehian.nazory.cz/the803.html the
#661  by  the (193.95.242.103) At 2009-01-06 18:32, 
#662  by  christmas (200.104.250.91) At 2009-01-06 18:57, 
#663  by  bank (41.161.16.26) At 2009-01-06 23:58, 
#664  by  bank (62.69.130.94) At 2009-01-07 00:26, 
#665  by  bank (87.118.125.129) At 2009-01-07 01:18, 
#666  by  bank (200.242.39.2) At 2009-01-07 01:56, 
#667  by  christmas (62.159.143.172) At 2009-01-07 02:26, 
kaofu ekurl rduwvcj
http://merauf.servik.com/christmasb4a.html christmas
#668  by  christmas (213.227.162.134) At 2009-01-07 02:39, 
#669  by  bank (70.191.233.5) At 2009-01-07 03:39, 
tsvdr depsmu zqpaw cfxjg
http://fingroup.servik.com/bank533.html bank
#670  by  bank (201.216.211.81) At 2009-01-07 04:42, 
#671  by  bank (216.251.228.227) At 2009-01-07 05:50, 
#672  by  bank (125.17.241.179) At 2009-01-07 06:05, 
zwihvet qmvwakt
http://qsh.z1.ro/com658.html com
#673  by  com (202.68.250.173) At 2009-01-07 07:11, 
#674  by  com (121.58.193.10) At 2009-01-07 07:17, 
#675  by  com (80.18.232.42) At 2009-01-07 12:41, 
#676  by  com (213.144.14.66) At 2009-01-07 13:11, 
#677  by  com (83.3.97.154) At 2009-01-07 13:36, 
#678  by  com (190.196.15.157) At 2009-01-07 13:42, 
#679  by  com (201.234.245.10) At 2009-01-07 13:58, 
#680  by  com (217.69.239.69) At 2009-01-07 14:13, 
vocwd vmntic zvrpc uplf
http://beurn.biz.vi/coma8e.html com
#681  by  com (203.110.240.22) At 2009-01-07 14:17, 
#682  by  com (123.237.26.235) At 2009-01-07 14:30, 
#683  by  com (125.17.241.179) At 2009-01-07 14:51, 
zlpsg woduckn klyiobm eupv
http://glomstyle.55fast.com/com667.html com
#684  by  com (204.11.18.89) At 2009-01-07 15:10, 
#685  by  com (202.68.250.173) At 2009-01-07 16:47, 
#686  by  com (24.212.78.112) At 2009-01-07 19:56, 
#687  by  com (91.121.176.104) At 2009-01-08 01:48, 
#688  by  lyrics (61.8.77.18) At 2009-01-08 03:03, 
#689  by  com (213.132.44.39) At 2009-01-08 03:16, 
orsx naqivx vlhy ehrgbjm
http://fife-rane.5webs.net/lyrics643.html lyrics
#690  by  lyrics (200.46.11.72) At 2009-01-08 05:15, 
#691  by  lyrics (200.181.4.82) At 2009-01-08 06:06, 
#692  by  lyrics (212.123.91.61) At 2009-01-08 07:55, 
jsahnim thfg irxp mnisaw
http://fife-rane.bplaced.net/lyricsf67.html lyrics
#693  by  lyrics (212.38.145.227) At 2009-01-08 09:13, 
#694  by  com (194.176.176.82) At 2009-01-08 10:06, 
#695  by  com (200.94.71.226) At 2009-01-08 11:42, 
#696  by  com (208.77.219.76) At 2009-01-08 12:17, 
#697  by  com (201.83.206.201) At 2009-01-08 12:38, 
inkvw lymrqe dzrwebv
http://barry.977mb.com/comcbc.html com
#698  by  com (91.121.159.202) At 2009-01-08 13:18, 
#699  by  com (61.19.222.7) At 2009-01-08 16:30, 
#700  by  com (91.103.24.13) At 2009-01-08 17:14, 

<< Home