Morph: Ломают сервак?

3 сообщения / 0 new
Последнее сообщение
Гость
Morph: Ломают сервак?

Господа! В логах сервера все чаще вижу что-то типа:

[code]
Nov 15 06:10:21 ice sshd[8784]: Illegal user tom from ::ffff:193.170.220.17
Nov 15 06:10:25 ice sshd[8786]: Illegal user tony from ::ffff:193.170.220.17
Nov 15 06:10:29 ice sshd[8788]: Illegal user vanessa from ::ffff:193.170.220.17
Nov 15 06:10:33 ice sshd[8790]: Illegal user will from ::ffff:193.170.220.17
Nov 15 06:10:37 ice sshd[8792]: Illegal user willie from ::ffff:193.170.220.17
Nov 15 12:31:45 ice sshd[9976]: Illegal user a from ::ffff:211.94.188.54
Nov 15 12:31:49 ice sshd[9978]: Illegal user b from ::ffff:211.94.188.54
Nov 15 12:31:53 ice sshd[9980]: Illegal user c from ::ffff:211.94.188.54
Nov 15 12:31:57 ice sshd[9982]: Illegal user d from ::ffff:211.94.188.54
Nov 15 12:32:01 ice sshd[9984]: Illegal user e from ::ffff:211.94.188.54
Nov 15 12:32:05 ice sshd[9986]: Illegal user f from ::ffff:211.94.188.54
Nov 15 12:32:09 ice sshd[9989]: Illegal user g from ::ffff:211.94.188.54
Nov 15 12:32:13 ice sshd[9991]: Illegal user h from ::ffff:211.94.188.54
Nov 15 12:32:17 ice sshd[9993]: Illegal user i from ::ffff:211.94.188.54
Nov 15 12:32:22 ice sshd[9995]: Illegal user j from ::ffff:211.94.188.54
Nov 15 12:32:26 ice sshd[9997]: Illegal user k from ::ffff:211.94.188.54
Nov 15 12:32:30 ice sshd[10000]: Illegal user l from ::ffff:211.94.188.54
Nov 15 12:32:34 ice sshd[10002]: Illegal user m from ::ffff:211.94.188.54
Nov 15 12:32:38 ice sshd[10004]: Illegal user n from ::ffff:211.94.188.54
Nov 15 12:32:42 ice sshd[10006]: Illegal user o from ::ffff:211.94.188.54
Nov 15 12:32:47 ice sshd[10008]: Illegal user p from ::ffff:211.94.188.54
Nov 15 12:32:51 ice sshd[10010]: Illegal user q from ::ffff:211.94.188.54
Nov 15 12:32:55 ice sshd[10012]: Illegal user r from ::ffff:211.94.188.54
Nov 15 12:32:59 ice sshd[10014]: Illegal user s from ::ffff:211.94.188.54
Nov 16 19:43:39 ice sshd[3938]: Illegal user 1 from ::ffff:80.14.0.37
Nov 16 19:43:41 ice sshd[3940]: Illegal user 2 from ::ffff:80.14.0.37
Nov 16 19:43:43 ice sshd[3942]: Illegal user 3 from ::ffff:80.14.0.37
Nov 16 19:43:45 ice sshd[3944]: Illegal user a from ::ffff:80.14.0.37
Nov 16 19:43:49 ice sshd[3946]: Illegal user aa from ::ffff:80.14.0.37
Nov 16 19:43:52 ice sshd[3948]: Illegal user aaa from ::ffff:80.14.0.37
Nov 16 19:43:55 ice sshd[3950]: Illegal user aaaa from ::ffff:80.14.0.37
Nov 16 19:43:58 ice sshd[3952]: Illegal user aaaaa from ::ffff:80.14.0.37
Nov 16 19:44:00 ice sshd[3954]: Illegal user aada from ::ffff:80.14.0.37
Nov 16 19:44:03 ice sshd[3956]: Illegal user aage from ::ffff:80.14.0.37
Nov 16 19:44:05 ice sshd[3958]: Illegal user aaliah from ::ffff:80.14.0.37
Nov 16 19:44:07 ice sshd[3960]: Illegal user aaliyah from ::ffff:80.14.0.37
Nov 16 19:44:09 ice sshd[3962]: Illegal user aaltje from ::ffff:80.14.0.37
Nov 16 19:44:11 ice sshd[3964]: Illegal user aapo from ::ffff:80.14.0.37
Nov 16 19:44:13 ice sshd[3966]: Illegal user aarabi from ::ffff:80.14.0.37
Nov 16 19:44:16 ice sshd[3968]: Illegal user aaro from ::ffff:80.14.0.37
Nov 16 19:44:18 ice sshd[3970]: Illegal user aaron from ::ffff:80.14.0.37
Nov 16 19:44:20 ice sshd[3972]: Illegal user aarovonda from ::ffff:80.14.0.37
Nov 16 19:44:22 ice sshd[3974]: Illegal user aarti from ::ffff:80.14.0.37
Nov 16 19:44:24 ice sshd[3976]: Illegal user aase from ::ffff:80.14.0.37
Nov 16 19:44:27 ice sshd[3978]: Illegal user aatu from ::ffff:80.14.0.37
Nov 16 19:44:29 ice sshd[3980]: Illegal user abadie from ::ffff:80.14.0.37
Nov 16 19:44:31 ice sshd[3982]: Illegal user abagail from ::ffff:80.14.0.37
Nov 16 19:44:35 ice sshd[3984]: Illegal user abbas from ::ffff:80.14.0.37
ice:/var/log #
[/code]

приведена только часть - естессно - перебирают от А до Я!

че за х...ня???
кто виноват?

наружу сервер смотрит только ssh2. root'у логинится нельзя. и еще мой юзер....которого как ни странно нет в их списке ;) Да и паролик у меня не 123. а сгенеренный makepasswd 8-ми символьный

Но интерес гложет что за кульхацкеры или бот тупой...

[ Редактирование ]

igorsia (не проверено)

это боты инет тралят... не обращай внимания.

Nick
Не в сети
Зарегистрирован: 20/09/2010

Это ssh-червь. Если найдет пользователя со слабым паролем -- залогинится и пойдет дальше. По всем хостам, которые есть в ~/.ssh/known_hosts. А если еще и id_rsa или id_dsa без пароля, вот тогда ему радость...
<span class='smallblacktext'>[ Редактирование 16.11.2005 - 21:50:24 ]</span>

RSS-материал