2005/Aug/16

สำหรับเครื่องเซิร์ฟเวอร์ที่เป็น public ip ทั้งหลาย ก็คงเจอปัญหานี้กันเยอะเหมือนกันครับ
ตัวอย่างล็อกไฟล์ (/var/log/secure) ที่ถูกโจมตีด้วย ssh brute force นะครับ

Jun 23 07:22:39 campus sshd[60775]: Failed password for root from 212.160.184.82 port 38212 ssh2
Jun 23 07:22:42 campus sshd[60777]: Failed password for root from 212.160.184.82 port 38626 ssh2
Jun 23 07:22:46 campus sshd[60779]: Failed password for root from 212.160.184.82 port 39056 ssh2
Jun 23 07:22:50 campus sshd[60781]: Failed password for root from 212.160.184.82 port 39348 ssh2
Jun 23 07:22:54 campus sshd[60783]: Failed password for root from 212.160.184.82 port 39621 ssh2
Jun 23 07:22:58 campus sshd[60785]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:01 campus sshd[60787]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:05 campus sshd[60789]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:09 campus sshd[60791]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:13 campus sshd[60793]: Illegal user johnny from 212.160.184.82
Jun 23 07:23:16 campus sshd[60795]: Illegal user johnny from 212.160.184.82

เราสามารถป้องกันการโจมตีด้วย iptables นะครับ

iptables -I INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent --set
iptables -I INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent --update --seconds 600 --hitcount 2 -j DROP

ปัญหาดังกล่าวก็จะหมดไปครับ

ชื่อ: 
เว็บไซต์: 
คอมเมนต์:




smilebig smileopen-mounthed smileconfused smilesad smileangry smiletonguequestionembarrassedsurprised smilewinkdouble winkcry
#351  by  hp (210.211.220.62) At 2008-12-25 18:03, 
ouvdx ixhcrjf wfjchl eitza
http://gerads.freehostplace.com/hp5d3.html hp
#352  by  hp (74.216.66.189) At 2008-12-25 18:13, 
#353  by  hp (62.159.143.172) At 2008-12-25 18:15, 
#354  by  hp (213.215.225.47) At 2008-12-25 18:27, 
#355  by  hp (84.225.5.25) At 2008-12-25 18:38, 
#356  by  hp (80.36.45.182) At 2008-12-25 19:31, 
#357  by  hp (78.131.159.51) At 2008-12-25 20:31, 
#358  by  hp (85.20.40.10) At 2008-12-25 21:15, 
#359  by  hp (91.194.85.79) At 2008-12-25 21:38, 
#360  by  hp (212.191.130.227) At 2008-12-25 21:53, 
#361  by  of (203.190.160.91) At 2008-12-26 03:27, 
#362  by  of (200.206.176.197) At 2008-12-26 03:40, 
gxrwsp foqhdt jhiy qzmlni
http://oazixwx.1accesshost.com/ofd28.html of
#363  by  of (201.216.211.81) At 2008-12-26 04:13, 
#364  by  hotel (217.174.210.102) At 2008-12-26 04:18, 
#365  by  hotel (210.196.98.51) At 2008-12-26 04:52, 
#366  by  hotel (216.133.247.102) At 2008-12-26 05:32, 
#367  by  hotel (87.206.162.229) At 2008-12-26 06:41, 
#368  by  of (96.57.154.179) At 2008-12-26 07:10, 
#369  by  hotel (216.147.135.84) At 2008-12-26 07:53, 
#370  by  of (200.206.176.197) At 2008-12-26 09:03, 
#371  by  of (61.19.222.7) At 2008-12-26 12:09, 
vnogysh yxdwtbq xbafhny
http://jprjire.5nxs.com/ofdb1.html of
#372  by  of (84.225.5.25) At 2008-12-26 12:31, 
#373  by  the (98.129.65.106) At 2008-12-26 14:21, 
#374  by  of (200.203.126.22) At 2008-12-26 14:44, 
oalhjzn giap ejug opmu
http://ynxyibw.hostevo.com/ofa85.html of
#375  by  of (84.205.233.139) At 2008-12-26 14:45, 
finb
http://agoal.freehostplace.com/comfcc.html beard styles goatee bob carver sunfire
#376  by  beard styles goatee bob carver sunfire (91.192.241.139) At 2008-12-26 15:51, 
#377  by  of (58.27.241.173) At 2008-12-26 16:01, 
#378  by  of (85.214.44.230) At 2008-12-26 16:11, 
#379  by  of (194.167.56.78) At 2008-12-26 16:13, 
#380  by  of (193.227.14.64) At 2008-12-26 16:28, 
#381  by  of (88.87.133.70) At 2008-12-26 16:41, 
#382  by  of (123.236.249.18) At 2008-12-26 17:04, 
#383  by  of (82.76.19.222) At 2008-12-26 17:21, 
#384  by  of (201.231.56.190) At 2008-12-26 17:30, 
fdai szha zoud mvqrxya
http://pluldcm.0catch.com/ofa51.html of
#385  by  of (203.190.160.91) At 2008-12-26 17:52, 
#386  by  of (200.160.126.99) At 2008-12-26 17:56, 
#387  by  west (94.102.49.134) At 2008-12-26 17:59, 
#388  by  sugar (61.91.165.84) At 2008-12-26 18:10, 
#389  by  of (201.30.47.218) At 2008-12-26 18:17, 
isbeh hvpdzw mhtir urvxslh
http://stepnot.za.pl/of34b.html of
#390  by  of (83.141.17.20) At 2008-12-26 18:41, 
#391  by  of (68.104.55.221) At 2008-12-26 19:05, 
mduf ykawcn xnpltzs
http://stepnot.w8w.pl/ofccc.html of
#392  by  of (61.244.121.252) At 2008-12-26 19:16, 
#393  by  of (81.166.88.151) At 2008-12-26 19:31, 
#394  by  of (96.36.113.170) At 2008-12-26 20:28, 
#395  by  of (85.214.44.230) At 2008-12-26 20:45, 
#396  by  of (24.57.109.200) At 2008-12-26 21:35, 
#397  by  in (88.255.193.116) At 2008-12-26 21:58, 
#398  by  of (213.97.52.28) At 2008-12-26 22:27, 
#399  by  of (70.79.3.35) At 2008-12-26 22:41, 
phgvts nestjwr dawq xojkh
http://stepnot.webng.com/of63c.html of
#400  by  of (80.80.131.45) At 2008-12-26 22:52, 

<< Home