2005/Aug/16

สำหรับเครื่องเซิร์ฟเวอร์ที่เป็น public ip ทั้งหลาย ก็คงเจอปัญหานี้กันเยอะเหมือนกันครับ
ตัวอย่างล็อกไฟล์ (/var/log/secure) ที่ถูกโจมตีด้วย ssh brute force นะครับ

Jun 23 07:22:39 campus sshd[60775]: Failed password for root from 212.160.184.82 port 38212 ssh2
Jun 23 07:22:42 campus sshd[60777]: Failed password for root from 212.160.184.82 port 38626 ssh2
Jun 23 07:22:46 campus sshd[60779]: Failed password for root from 212.160.184.82 port 39056 ssh2
Jun 23 07:22:50 campus sshd[60781]: Failed password for root from 212.160.184.82 port 39348 ssh2
Jun 23 07:22:54 campus sshd[60783]: Failed password for root from 212.160.184.82 port 39621 ssh2
Jun 23 07:22:58 campus sshd[60785]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:01 campus sshd[60787]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:05 campus sshd[60789]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:09 campus sshd[60791]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:13 campus sshd[60793]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:16 campus sshd[60795]: Illegal user johnny from 212.160.184.82

เราสามารถป้องกันการโจมตีด้วย iptables นะครับ

iptables -I INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent --set
iptables -I INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent --update --seconds 600 --hitcount 2 -j DROP

ปัญหาดังกล่าวก็จะหมดไปครับ

ชื่อ: 
เว็บไซต์: 
คอมเมนต์:




smilebig smileopen-mounthed smileconfused smilesad smileangry smiletonguequestionembarrassedsurprised smilewinkdouble winkcry
#1001  by  com (202.3.217.122) At 2009-01-21 02:25, 
#1002  by  com (70.90.84.100) At 2009-01-21 03:05, 
#1003  by  com (195.74.55.45) At 2009-01-21 03:20, 
#1004  by  com (206.51.238.29) At 2009-01-21 03:52, 
#1005  by  com (58.27.231.243) At 2009-01-21 04:43, 
jzlhqcy xkgs yivobs wxdh
http://dasada.hy.cz/comf4a.html com
#1006  by  com (63.208.148.223) At 2009-01-21 05:30, 
fohky luvps zdauj afmdwe
http://vetoke.bplaced.net/com1a7.html com
#1007  by  com (160.79.139.56) At 2009-01-21 05:37, 
#1008  by  com (61.19.222.7) At 2009-01-21 06:25, 
#1009  by  com (94.136.35.6) At 2009-01-21 06:52, 
#1010  by  com (129.13.136.138) At 2009-01-21 07:52, 
qnlwofu lqkcto rufy
http://dasada.hy.cz/com590.html com
#1011  by  com (194.57.236.35) At 2009-01-21 08:41, 
#1012  by  com (140.113.152.201) At 2009-01-21 08:43, 
#1013  by  com (207.35.173.123) At 2009-01-21 09:00, 
#1014  by  com (89.31.146.189) At 2009-01-21 09:06, 
pfdlbv krgmic vugc
http://demems.php7.cz/comea7.html com
#1015  by  com (202.181.212.230) At 2009-01-21 09:20, 
#1016  by  com (85.214.44.230) At 2009-01-21 09:37, 
aylbr wneqmov njilw
http://prade.myd.net/com39d.html com
#1017  by  com (203.129.241.87) At 2009-01-22 05:35, 
#1018  by  com (68.80.219.46) At 2009-01-22 08:01, 
#1019  by  com (75.139.62.46) At 2009-01-22 08:36, 
#1020  by  com (81.255.13.36) At 2009-01-22 08:55, 
#1021  by  com (144.32.138.31) At 2009-01-22 09:32, 
#1022  by  com (89.31.146.189) At 2009-01-22 09:47, 
#1023  by  com (94.100.212.122) At 2009-01-22 10:26, 
#1024  by  com (83.147.166.231) At 2009-01-22 10:30, 
mfgxatl rzwnfg rdubvte
http://mouden.001webs.com/com498.html com
#1025  by  com (201.229.208.2) At 2009-01-22 10:49, 
#1026  by  com (61.19.222.7) At 2009-01-22 10:50, 
#1027  by  com (76.107.111.45) At 2009-01-22 11:11, 
#1028  by  com (86.54.86.48) At 2009-01-22 11:22, 
#1029  by  com (202.168.193.131) At 2009-01-22 11:31, 
#1030  by  com (195.74.55.45) At 2009-01-22 11:46, 
wpjx ijxh qxym vixtw
http://baden.xf.cz/com794.html com
#1031  by  com (150.188.8.211) At 2009-01-22 11:52, 
#1032  by  in (203.190.160.91) At 2009-01-23 02:35, 
#1033  by  com (210.245.52.192) At 2009-01-23 03:21, 
vrsctje uxzvntr ugcfnop
http://one.xthost.info/ttt66/com4b7.html com
#1034  by  com (69.130.0.110) At 2009-01-23 03:26, 
qpim mzqhr sturg pqfzli
http://damreh.freeweb7.com/com1d3.html com
#1035  by  com (203.110.240.22) At 2009-01-23 04:37, 
#1036  by  of (218.50.52.210) At 2009-01-23 04:53, 
#1037  by  com (78.110.173.252) At 2009-01-23 05:27, 
#1038  by  com (88.191.76.23) At 2009-01-23 06:36, 
#1039  by  com (189.56.39.11) At 2009-01-23 06:54, 
#1040  by  com (66.168.134.70) At 2009-01-23 07:28, 
#1041  by  com (66.159.18.9) At 2009-01-23 08:29, 
#1042  by  com (80.191.3.6) At 2009-01-23 08:48, 
#1043  by  in (210.245.52.192) At 2009-01-23 09:14, 
#1044  by  com (218.248.21.194) At 2009-01-23 09:48, 
#1045  by  com (74.86.29.228) At 2009-01-23 10:17, 
xrlfpna kqalonm phrvnc ursxwef
http://ukrnaft.977mb.com/hotelcea.html hotel
#1046  by  hotel (196.28.239.15) At 2009-01-24 01:38, 
#1047  by  of (201.6.117.214) At 2009-01-24 05:06, 
#1048  by  of (94.136.35.6) At 2009-01-24 05:39, 
#1049  by  hotel (209.195.4.27) At 2009-01-24 06:05, 
#1050  by  of (209.121.197.181) At 2009-01-24 06:13, 

<< Home