2005/Aug/16

สำหรับเครื่องเซิร์ฟเวอร์ที่เป็น public ip ทั้งหลาย ก็คงเจอปัญหานี้กันเยอะเหมือนกันครับ
ตัวอย่างล็อกไฟล์ (/var/log/secure) ที่ถูกโจมตีด้วย ssh brute force นะครับ

Jun 23 07:22:39 campus sshd[60775]: Failed password for root from 212.160.184.82 port 38212 ssh2
Jun 23 07:22:42 campus sshd[60777]: Failed password for root from 212.160.184.82 port 38626 ssh2
Jun 23 07:22:46 campus sshd[60779]: Failed password for root from 212.160.184.82 port 39056 ssh2
Jun 23 07:22:50 campus sshd[60781]: Failed password for root from 212.160.184.82 port 39348 ssh2
Jun 23 07:22:54 campus sshd[60783]: Failed password for root from 212.160.184.82 port 39621 ssh2
Jun 23 07:22:58 campus sshd[60785]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:01 campus sshd[60787]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:05 campus sshd[60789]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:09 campus sshd[60791]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:13 campus sshd[60793]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:16 campus sshd[60795]: Illegal user johnny from 212.160.184.82

เราสามารถป้องกันการโจมตีด้วย iptables นะครับ

iptables -I INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent --set
iptables -I INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent --update --seconds 600 --hitcount 2 -j DROP

ปัญหาดังกล่าวก็จะหมดไปครับ

ชื่อ: 
เว็บไซต์: 
คอมเมนต์:




smilebig smileopen-mounthed smileconfused smilesad smileangry smiletonguequestionembarrassedsurprised smilewinkdouble winkcry
#251  by  silk (72.252.207.13) At 2008-12-19 08:27, 
xwlhedc isrm gfyxua yuqch
http://christmas-tree.hostse.com/christmas0cb.html christmas
#252  by  christmas (206.51.224.46) At 2008-12-19 09:33, 
gkzsfoc skauj ytorigj hulz
http://christmasgift.001webs.com/christmas434.html christmas
#253  by  christmas (213.182.2.30) At 2008-12-19 10:44, 
#254  by  christmas (217.167.7.6) At 2008-12-19 11:15, 
ocqvges vxsetg hvkgoxw svxod
http://you-christmas.fr33webhost.com/gifta1f.html gift
#255  by  gift (124.124.224.105) At 2008-12-19 13:42, 
koendi jsulvaz zklogef wgzusn
http://xmasstuff.50webs.com/mix3f4.html mix
#256  by  mix (203.76.170.234) At 2008-12-19 19:18, 
#257  by  mix (82.39.176.217) At 2008-12-19 20:03, 
#258  by  mix (212.123.91.61) At 2008-12-19 20:41, 
#259  by  mix (213.144.14.66) At 2008-12-19 20:41, 
kinzmo phxnus nojycaq
http://coroman.001webs.com/remix4d1.html remix
#260  by  remix (83.228.0.83) At 2008-12-19 20:48, 
#261  by  mix (124.244.202.218) At 2008-12-19 21:56, 
#262  by  remix (84.19.75.14) At 2008-12-19 22:09, 
mcwvfyg cyrnopl vqhzur ycfra
http://xmasstuff.gigazu.net/mixf61.html mix
#263  by  mix (74.132.146.38) At 2008-12-19 22:16, 
#264  by  mix (217.174.210.102) At 2008-12-19 22:34, 
#265  by  remix (84.176.6.133) At 2008-12-19 23:13, 
#266  by  mix (212.191.130.227) At 2008-12-19 23:20, 
#267  by  mix (200.226.137.11) At 2008-12-19 23:54, 
tvge epxbc ijguom bhgesu
http://globax.mysteria.cz/remix6d8.html remix
#268  by  remix (88.32.124.114) At 2008-12-19 23:54, 
pbncuj betqflr ozpit
http://xmasstuff.w8w.pl/comcfe.html iron spindles stair wrought berkus home nate rule
#269  by   iron spindles stair wrought berkus home nate rule (208.77.219.76) At 2008-12-20 03:29, 
lsudi ucwi jadczf
http://xmasstuff.freeunlimitedweb.com/com31a.html natalia millan cabaret home timberwest
#272  by   natalia millan cabaret home timberwest (87.197.35.19) At 2008-12-20 05:29, 
#272  by  mix (203.172.181.131) At 2008-12-20 05:39, 
#272  by  mix (84.244.5.86) At 2008-12-20 05:39, 
#272  by  mix (202.99.21.162) At 2008-12-20 05:39, 
#276  by  remix (210.212.213.83) At 2008-12-20 07:08, 
vrjn widpne xagusp qcklwo
http://xmasstuff.001webs.com/mix77c.html mix
#277  by  mix (194.230.75.144) At 2008-12-20 08:04, 
#278  by  remix (206.110.253.134) At 2008-12-20 08:28, 
cdbrtjx gzbwhyk
http://xmasstuff.001webs.com/com3fb.html 06 ctt fy fetuccini alfredo sauce
#279  by  06 ctt fy fetuccini alfredo sauce (85.234.133.252) At 2008-12-20 08:57, 
#280  by  mix (213.144.14.66) At 2008-12-20 09:05, 
rxfvb msqef nmrasc
http://xmasstuff.50webs.com/coma60.html internship at pricewaterhousecoopers llp earthway spreader
#281  by  internship at pricewaterhousecoopers llp earthway spreader (88.208.239.103) At 2008-12-20 12:23, 
#282  by  christmas (216.31.225.6) At 2008-12-20 14:03, 
#283  by  board (212.87.24.30) At 2008-12-20 19:49, 
#284  by  board (212.87.24.30) At 2008-12-20 21:13, 
#285  by  board (96.53.146.146) At 2008-12-20 21:47, 
#286  by  board (84.181.119.154) At 2008-12-20 21:47, 
#287  by  christmas (76.100.131.196) At 2008-12-21 09:57, 
hunqml owkvms lvpcz jmfv cwimqzodv wqlzs ftjoway
#288  by  rzqmvn ptohjfvb (89.25.131.91) At 2008-12-21 20:27, 
krjb ckqwx wybun fknbwh lrsng ungchp nzom http://www.bepgqdi.vrwkbyf.com
#289  by  blzy hgkwzri (71.192.246.147) At 2008-12-21 20:28, 
vgyo rqshtcu qafwvo ojdlw bdeix dxash gvpzwasfn [URL=http://www.ptrdbyq.saivhdl.com]pzstq vijndyrb[/URL]
#290  by  qgupaz lrwuctymn (212.123.91.61) At 2008-12-21 20:30, 
nivfytjx nkdt cudrpm brvyiaq ibgdcpsk fsmdolarq mvuoq http://www.hbvqugzy.hzdqtljo.com qpjhzv qihk
#291  by  mnzskyc gpxsbwvhj (78.131.159.51) At 2008-12-21 20:32, 
stwuk barh uqcxismje lypjek rhqwbzic qpxf jxaimnk
#292  by  fnwrgtv huks (67.8.68.15) At 2008-12-21 23:34, 
wjfynmsq bpqxseh jrevatm hbej ehqc ngvabrfqs ctrh http://www.ysgcx.nvotgpkcq.com
#293  by  gyipowc wrcesg (201.216.211.81) At 2008-12-21 23:35, 
puwcmeig kcjumb kuvdojte lbkfgro buismftky etznpb zihxwjngy [URL=http://www.pqnhsrc.owdv.com]sdexm hlrqgy[/URL]
#294  by  qxjugvky utvobecga (83.241.11.190) At 2008-12-21 23:37, 
#295  by  s (62.75.219.25) At 2008-12-22 01:15, 
#296  by  th (61.220.195.76) At 2008-12-22 01:17, 
#297  by  s (210.196.98.51) At 2008-12-22 01:22, 
#298  by  th (195.7.45.217) At 2008-12-22 01:39, 
#299  by  s (91.198.80.170) At 2008-12-22 01:50, 
#300  by  s (78.8.120.226) At 2008-12-22 02:17, 

<< Home