|
我是今天早上开机发现我的apache起不来才检查日志文件的!!在安全日志里发现了下面的内容,是不是我的机子已经被入侵了??大家看看!~~我感觉是是通过swat服务来入侵的!~
Aug 27 15:31:50 ruochen xinetd[5267]: START: swat pid=5391 from=219.139.0.80
Aug 27 15:31:59 ruochen xinetd[5267]: START: swat pid=5392 from=219.139.0.80
Aug 27 15:47:15 ruochen sshd[5540]: fatal: Timeout before authentication for 219.139.0.80
Aug 29 21:58:36 ruochen xinetd[3250]: START: swat pid=4383 from=219.154.14.244
Aug 29 21:03:55 ruochen xinetd[3250]: START: swat pid=4086 from=218.197.208.196
Aug 29 21:05:57 ruochen xinetd[3250]: START: swat pid=4095 from=218.197.208.196
Aug 29 21:08:01 ruochen xinetd[3250]: START: swat pid=4109 from=218.197.208.196
Aug 29 21:10:03 ruochen xinetd[3250]: START: swat pid=4127 from=218.197.208.196
Aug 29 21:12:07 ruochen xinetd[3250]: START: swat pid=4144 from=218.197.208.196
Aug 29 21:14:09 ruochen xinetd[3250]: START: swat pid=4154 from=218.197.208.196
Aug 29 21:58:36 ruochen xinetd[3250]: START: swat pid=4383 from=219.154.14.244
Aug 26 12:34:52 ruochen xinetd[3249]: pmap_set failed. service=sgi_fam program=391002 version=2-----这个是什么???
Aug 26 13:51:24 ruochen xinetd[3242]: pmap_set failed. service=sgi_fam program=391002 version=2
Aug 26 19:52:52 ruochen login[3440]: FAILED LOGIN 1 FROM (null) FOR wangyang, Authentication failure
Aug 26 19:52:52 ruochen login[3440]: FAILED LOGIN 1 FROM (null) FOR wangyang, Authentication failure
大家帮我拿点注意!~ |
|