m*d
2 楼
每次的端口还不一样,这是什么后门程序?
[email protected]/* */:~# netstat |grep ssh
tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
tcp 0 39 192.168.1.146:ssh 60.12.109.16:54023
ESTABLISHED
[email protected]/* */:~# netstat |grep ssh
tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
tcp 0 0 192.168.1.146:ssh 60.12.109.16:54023
ESTABLISHED
[email protected]/* */:~# netstat |grep ssh
tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
tcp 0 0 192.168.1.146:ssh 60.12.109.16:54709
ESTABLISHED
[email protected]/* */:~# netstat |grep ssh
tcp 0 0 192.168.1.146:ssh 60.12.109.16:40794
ESTABLISHED
tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
[email protected]/* */:~# netstat |grep ssh
tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
tcp 0 39 192.168.1.146:ssh 60.12.109.16:54023
ESTABLISHED
[email protected]/* */:~# netstat |grep ssh
tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
tcp 0 0 192.168.1.146:ssh 60.12.109.16:54023
ESTABLISHED
[email protected]/* */:~# netstat |grep ssh
tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
tcp 0 0 192.168.1.146:ssh 60.12.109.16:54709
ESTABLISHED
[email protected]/* */:~# netstat |grep ssh
tcp 0 0 192.168.1.146:ssh 60.12.109.16:40794
ESTABLISHED
tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
F*u
3 楼
search app也没找到,咋回事?
d*o
4 楼
能的,交上去被audit或者批了才要签字的
给个包子不,谢谢
给个包子不,谢谢
m*d
5 楼
原来是有人在试密码
Nov 27 14:30:51 debian sshd[31165]: Failed password for invalid user downloa
d from 60.12.109.16 port 33426 ssh2
Nov 27 14:30:51 debian sshd[31165]: Received disconnect from 60.12.109.16: 1
1: Bye Bye [preauth]
Nov 27 14:30:52 debian sshd[31169]: warning: /etc/hosts.allow, line 13: miss
ing ":" separator
Nov 27 14:30:53 debian sshd[31169]: Invalid user download from 60.12.109.16
Nov 27 14:30:53 debian sshd[31169]: input_userauth_request: invalid user dow
nload [preauth]
Nov 27 14:30:53 debian sshd[31169]: pam_unix(sshd:auth): check pass; user un
known
Nov 27 14:30:53 debian sshd[31169]: pam_unix(sshd:auth): authentication fail
ure; logname= uid=0 euid=0 tty=ssh ruser= rhost=60.12.109.16
Nov 27 14:30:56 debian sshd[31169]: Failed password for invalid user downloa
d from 60.12.109.16 port 34099 ssh2
Nov 27 14:30:56 debian sshd[31169]: Received disconnect from 60.12.109.16: 1
1: Bye Bye [preauth]
Nov 27 14:30:56 debian sshd[31179]: warning: /etc/hosts.allow, line 13: miss
ing ":" separator
Nov 27 14:30:57 debian sshd[31179]: Invalid user download from 60.12.109.16
Nov 27 14:30:57 debian sshd[31179]: input_userauth_request: invalid user dow
nload [preauth]
Nov 27 14:30:57 debian sshd[31179]: pam_unix(sshd:auth): check pass; user un
known
Nov 27 14:30:57 debian sshd[31179]: pam_unix(sshd:auth): authentication fail
ure; logname= uid=0 euid=0 tty=ssh ruser= rhost=60.12.109.16
Nov 27 14:30:58 debian sshd[31183]: warning: /etc/hosts.allow, line 13: miss
ing ":" separator
Nov 27 14:30:59 debian sshd[31179]: Failed password for invalid user downloa
d from 60.12.109.16 port 34842 ssh2
Nov 27 14:30:59 debian sshd[31179]: Received disconnect from 60.12.109.16: 1
1: Bye Bye [preauth]
Nov 27 14:30:59 debian sshd[31186]: warning: /etc/hosts.allow, line 13: miss
ing ":" separator
Nov 27 14:31:00 debian sshd[31183]: pam_unix(sshd:auth): authentication fail
ure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.229.172.73 user=root
【在 m*d 的大作中提到】
: 每次的端口还不一样,这是什么后门程序?
: [email protected]/* */:~# netstat |grep ssh
: tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
: tcp 0 39 192.168.1.146:ssh 60.12.109.16:54023
: ESTABLISHED
: [email protected]/* */:~# netstat |grep ssh
: tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
: tcp 0 0 192.168.1.146:ssh 60.12.109.16:54023
: ESTABLISHED
: [email protected]/* */:~# netstat |grep ssh
Nov 27 14:30:51 debian sshd[31165]: Failed password for invalid user downloa
d from 60.12.109.16 port 33426 ssh2
Nov 27 14:30:51 debian sshd[31165]: Received disconnect from 60.12.109.16: 1
1: Bye Bye [preauth]
Nov 27 14:30:52 debian sshd[31169]: warning: /etc/hosts.allow, line 13: miss
ing ":" separator
Nov 27 14:30:53 debian sshd[31169]: Invalid user download from 60.12.109.16
Nov 27 14:30:53 debian sshd[31169]: input_userauth_request: invalid user dow
nload [preauth]
Nov 27 14:30:53 debian sshd[31169]: pam_unix(sshd:auth): check pass; user un
known
Nov 27 14:30:53 debian sshd[31169]: pam_unix(sshd:auth): authentication fail
ure; logname= uid=0 euid=0 tty=ssh ruser= rhost=60.12.109.16
Nov 27 14:30:56 debian sshd[31169]: Failed password for invalid user downloa
d from 60.12.109.16 port 34099 ssh2
Nov 27 14:30:56 debian sshd[31169]: Received disconnect from 60.12.109.16: 1
1: Bye Bye [preauth]
Nov 27 14:30:56 debian sshd[31179]: warning: /etc/hosts.allow, line 13: miss
ing ":" separator
Nov 27 14:30:57 debian sshd[31179]: Invalid user download from 60.12.109.16
Nov 27 14:30:57 debian sshd[31179]: input_userauth_request: invalid user dow
nload [preauth]
Nov 27 14:30:57 debian sshd[31179]: pam_unix(sshd:auth): check pass; user un
known
Nov 27 14:30:57 debian sshd[31179]: pam_unix(sshd:auth): authentication fail
ure; logname= uid=0 euid=0 tty=ssh ruser= rhost=60.12.109.16
Nov 27 14:30:58 debian sshd[31183]: warning: /etc/hosts.allow, line 13: miss
ing ":" separator
Nov 27 14:30:59 debian sshd[31179]: Failed password for invalid user downloa
d from 60.12.109.16 port 34842 ssh2
Nov 27 14:30:59 debian sshd[31179]: Received disconnect from 60.12.109.16: 1
1: Bye Bye [preauth]
Nov 27 14:30:59 debian sshd[31186]: warning: /etc/hosts.allow, line 13: miss
ing ":" separator
Nov 27 14:31:00 debian sshd[31183]: pam_unix(sshd:auth): authentication fail
ure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.229.172.73 user=root
【在 m*d 的大作中提到】
: 每次的端口还不一样,这是什么后门程序?
: [email protected]/* */:~# netstat |grep ssh
: tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
: tcp 0 39 192.168.1.146:ssh 60.12.109.16:54023
: ESTABLISHED
: [email protected]/* */:~# netstat |grep ssh
: tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
: tcp 0 0 192.168.1.146:ssh 60.12.109.16:54023
: ESTABLISHED
: [email protected]/* */:~# netstat |grep ssh
a*1
6 楼
重新装一遍?你search Excel什么都没有出来吗?
h*6
7 楼
真的吗?
别吓俺,最近回国了一次,有了新的I-94,律师手里是俺老的I-94,不知道律师是不是已
经递出去了,完蛋了。。。。。
别吓俺,最近回国了一次,有了新的I-94,律师手里是俺老的I-94,不知道律师是不是已
经递出去了,完蛋了。。。。。
z*e
8 楼
这个ip在我的adblock list上
地址在浙江
有点蹊跷
【在 m*d 的大作中提到】
: 每次的端口还不一样,这是什么后门程序?
: [email protected]/* */:~# netstat |grep ssh
: tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
: tcp 0 39 192.168.1.146:ssh 60.12.109.16:54023
: ESTABLISHED
: [email protected]/* */:~# netstat |grep ssh
: tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
: tcp 0 0 192.168.1.146:ssh 60.12.109.16:54023
: ESTABLISHED
: [email protected]/* */:~# netstat |grep ssh
地址在浙江
有点蹊跷
【在 m*d 的大作中提到】
: 每次的端口还不一样,这是什么后门程序?
: [email protected]/* */:~# netstat |grep ssh
: tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
: tcp 0 39 192.168.1.146:ssh 60.12.109.16:54023
: ESTABLISHED
: [email protected]/* */:~# netstat |grep ssh
: tcp 0 52 192.168.1.146:ssh PC:54877 ESTABLISHED
: tcp 0 0 192.168.1.146:ssh 60.12.109.16:54023
: ESTABLISHED
: [email protected]/* */:~# netstat |grep ssh
d*o
10 楼
真的
那你跟你律师说,可能还没交上去呢
不过交了也没关系,提交140的时候用新的就行
那你跟你律师说,可能还没交上去呢
不过交了也没关系,提交140的时候用新的就行
z*e
13 楼
试试
iptables -A INPUT -s 60.12.109.16 -p tcp --dport ssh -j DROP
?
iptables -A INPUT -s 60.12.109.16 -p tcp --dport ssh -j DROP
?
F*Q
15 楼
these are zombies infected by backdoor programs, not from actual person.
banning that IP is not helpful because you will soon find other IPs trying
the same thing.
make sure you disable remote root access, by setting PermitRootLogin to no
in sshd_config (of course, make your account sudoer first), then
sudo /etc/init.d/sshd restart
you can also install tripwire to automatically disable intruders after
failed passwords
https://www.digitalocean.com/community/tutorials/how-to-use-tripwire-to-
detect-server-intrusions-on-an-ubuntu-vps
【在 m*d 的大作中提到】
: 原来是有人在试密码
: Nov 27 14:30:51 debian sshd[31165]: Failed password for invalid user downloa
: d from 60.12.109.16 port 33426 ssh2
: Nov 27 14:30:51 debian sshd[31165]: Received disconnect from 60.12.109.16: 1
: 1: Bye Bye [preauth]
: Nov 27 14:30:52 debian sshd[31169]: warning: /etc/hosts.allow, line 13: miss
: ing ":" separator
: Nov 27 14:30:53 debian sshd[31169]: Invalid user download from 60.12.109.16
: Nov 27 14:30:53 debian sshd[31169]: input_userauth_request: invalid user dow
: nload [preauth]
z*e
16 楼
也可以换ssh key-based auth,这个应该非常安全
m*d
17 楼
装了ipset的脚本,这下清净了
https://github.com/RMerl/asuswrt-merlin/wiki/Using-ipset
【在 z*********e 的大作中提到】
: 也可以换ssh key-based auth,这个应该非常安全
https://github.com/RMerl/asuswrt-merlin/wiki/Using-ipset
【在 z*********e 的大作中提到】
: 也可以换ssh key-based auth,这个应该非常安全
相关阅读
卖老iPhone需要把sim卡取出来么又一个曲屏手机,LG的。手机太多了,再卖一个自用的NOTE2 。CLEAN ESN $335 (转载)Mo+ 谁用过买了G Pro,正准备人生的第一次刷机大家youtube的favorites功能还在吗?freedompop的声音质量到底怎么样? (转载)弱弱地问一下,可以用Lumia 920上scottrade炒股吗?NEXUS 5 出来之后不知道其他手机会不会降价?还有就是在美国看国内电视节目 -- 海美迪Q2/Q5 -- 不用吵了MS GDR3 官方公告出来了为啥HTC ONE升级了4.3之后还是有三点菜单呢?我youtube里的likes list给清空了?T-Mobile Samsung Galaxy S Blaze 4G No-Contract-$130 如何?大家Wp上的Bard App 继续播放时会有问题吗?目前有什么android的免费实时语音通话软件?One suggestion to zipnote3 和 g2 摸机感受求教:nokia n8 中文支持note3配件问题