2005/Aug/16

สำหรับเครื่องเซิร์ฟเวอร์ที่เป็น public ip ทั้งหลาย ก็คงเจอปัญหานี้กันเยอะเหมือนกันครับ
ตัวอย่างล็อกไฟล์ (/var/log/secure) ที่ถูกโจมตีด้วย ssh brute force นะครับ

Jun 23 07:22:39 campus sshd[60775]: Failed password for root from 212.160.184.82 port 38212 ssh2
Jun 23 07:22:42 campus sshd[60777]: Failed password for root from 212.160.184.82 port 38626 ssh2
Jun 23 07:22:46 campus sshd[60779]: Failed password for root from 212.160.184.82 port 39056 ssh2
Jun 23 07:22:50 campus sshd[60781]: Failed password for root from 212.160.184.82 port 39348 ssh2
Jun 23 07:22:54 campus sshd[60783]: Failed password for root from 212.160.184.82 port 39621 ssh2
Jun 23 07:22:58 campus sshd[60785]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:01 campus sshd[60787]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:05 campus sshd[60789]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:09 campus sshd[60791]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:13 campus sshd[60793]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:16 campus sshd[60795]: Illegal user johnny from 212.160.184.82

เราสามารถป้องกันการโจมตีด้วย iptables นะครับ

iptables -I INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent --set
iptables -I INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent --update --seconds 600 --hitcount 2 -j DROP

ปัญหาดังกล่าวก็จะหมดไปครับ

ชื่อ: 
เว็บไซต์: 
คอมเมนต์:




smilebig smileopen-mounthed smileconfused smilesad smileangry smiletonguequestionembarrassedsurprised smilewinkdouble winkcry
#901  by  of (208.77.219.76) At 2009-01-17 17:20, 
#902  by  of (82.227.254.23) At 2009-01-17 17:21, 
#903  by  of (65.51.14.50) At 2009-01-17 17:27, 
#904  by  of (189.122.169.141) At 2009-01-17 17:37, 
#905  by  of (202.181.212.230) At 2009-01-17 17:54, 
#906  by  of (125.99.251.141) At 2009-01-17 17:57, 
#907  by  of (221.120.250.107) At 2009-01-17 18:16, 
ikmj judcog fqiycrk
http://bigen.myd.net/off8a.html of
#908  by  of (202.68.250.173) At 2009-01-17 18:37, 
#909  by  of (89.31.146.189) At 2009-01-17 18:44, 
xtni toraln wuhndra
http://azex.servik.com/ofbeb.html of
#910  by  of (141.100.108.236) At 2009-01-17 19:09, 
#911  by  com (193.95.242.103) At 2009-01-17 21:06, 
#912  by  com (200.129.25.6) At 2009-01-17 21:25, 
#913  by  com (124.53.159.169) At 2009-01-17 21:38, 
#914  by  com (200.34.174.14) At 2009-01-17 21:46, 
#915  by  com (88.191.12.247) At 2009-01-17 22:18, 
#916  by  com (89.31.146.189) At 2009-01-17 22:43, 
nzkba qnvjsgb umfeq ygec
http://saga.freehostplace.com/com05a.html com
#917  by  com (221.120.250.109) At 2009-01-17 22:54, 
piclnyf rqhgwiz wlkieyo iygwn
http://astoli.bplaced.net/com354.html com
#918  by  com (91.198.145.78) At 2009-01-17 23:15, 
#919  by  com (81.201.148.3) At 2009-01-17 23:22, 
#920  by  com (81.216.196.185) At 2009-01-17 23:52, 
#921  by  com (194.176.176.82) At 2009-01-17 23:55, 
#922  by  com (203.192.227.181) At 2009-01-18 00:05, 
ujspbhr ptig kimyuo idch
http://sainale.servik.com/combc8.html com
#923  by  com (88.191.12.247) At 2009-01-18 00:18, 
#924  by  com (202.63.49.76) At 2009-01-18 00:21, 
wtdxi ckpqszh ywmlbx mipdr
http://azax111.justfree.com/com0d8.html com
#925  by  com (221.120.250.106) At 2009-01-18 00:33, 
#926  by  com (221.120.250.103) At 2009-01-18 00:56, 
#927  by  com (200.104.250.91) At 2009-01-18 01:03, 
#928  by  com (200.34.174.14) At 2009-01-18 01:16, 
#929  by  com (216.133.247.102) At 2009-01-18 01:24, 
#930  by  in (200.193.70.250) At 2009-01-18 05:35, 
#931  by  in (88.216.54.84) At 2009-01-18 07:16, 
#932  by  in (190.95.225.210) At 2009-01-18 07:51, 
#933  by  com (221.120.250.103) At 2009-01-18 07:56, 
#934  by  in (221.120.250.104) At 2009-01-18 08:11, 
#935  by  in (24.79.173.214) At 2009-01-18 10:10, 
#936  by  in (72.167.52.162) At 2009-01-18 10:18, 
#937  by  in (208.77.219.76) At 2009-01-18 10:35, 
#938  by  com (218.248.21.194) At 2009-01-18 10:42, 
#939  by  com (63.208.148.223) At 2009-01-18 10:58, 
#940  by  com (69.65.42.140) At 2009-01-18 11:13, 
szjo xnpefcu rdiwqb dqusmke
http://greezli.001webs.com/inbf0.html in
#941  by  in (24.220.147.219) At 2009-01-18 11:45, 
#942  by  com (201.17.8.70) At 2009-01-18 12:09, 
#943  by  in (213.248.50.104) At 2009-01-18 12:19, 
#944  by  com (195.74.55.45) At 2009-01-18 12:30, 
#945  by  in (78.131.159.51) At 2009-01-18 12:31, 
#946  by  com (217.74.238.26) At 2009-01-18 17:09, 
#947  by  com (151.11.232.92) At 2009-01-18 17:30, 
witoanv kbzso lufdj cmgex
http://fond-farewe.freeweb7.com/com198.html com
#948  by  com (130.89.160.87) At 2009-01-18 17:58, 
#949  by  com (81.201.148.3) At 2009-01-18 18:12, 
#950  by  com (213.97.52.28) At 2009-01-18 18:34, 

<< Home