|
|
发表于 2006-11-21 17:43:17
|
显示全部楼层
我也经常有 这种 日志 ,那些 人 是用什么工具来攻击的呢??
Nov 19 06:35:13 mail vsftpd(pam_unix)[17525]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=202.96.59.201
Nov 19 06:35:15 mail vsftpd(pam_unix)[17527]: check pass; user unknown
Nov 19 06:35:15 mail vsftpd(pam_unix)[17527]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=202.96.59.201
Nov 19 06:35:16 mail vsftpd(pam_unix)[17525]: check pass; user unknown
Nov 19 06:35:16 mail vsftpd(pam_unix)[17525]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=202.96.59.201
Nov 19 06:35:18 mail vsftpd(pam_unix)[17527]: check pass; user unknown
Nov 19 06:35:18 mail vsftpd(pam_unix)[17527]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=202.96.59.201
Nov 19 06:35:18 mail vsftpd(pam_unix)[17525]: check pass; user unknown
Nov 19 06:35:18 mail vsftpd(pam_unix)[17525]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=202.96.59.201
Nov 19 06:35:20 mail vsftpd(pam_unix)[17527]: check pass; user unknown
Nov 19 06:35:20 mail vsftpd(pam_unix)[17527]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=202.96.59.201
Nov 19 06:35:20 mail vsftpd(pam_unix)[17525]: check pass; user unknown
Nov 19 06:35:20 mail vsftpd(pam_unix)[17525]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=202.96.59.201
Nov 19 06:35:22 mail vsftpd(pam_unix)[17527]: check pass; user unknown
Nov 19 06:35:22 mail vsftpd(pam_unix)[17527]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=202.96.59.201
Nov 19 06:35:23 mail vsftpd(pam_unix)[17525]: check pass; user unknown
Nov 19 06:35:23 mail vsftpd(pam_unix)[17525]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=202.96.59.201
Nov 19 06:35:25 mail vsftpd(pam_unix)[17527]: check pass; user unknown
Nov 19 06:35:25 mail vsftpd(pam_unix)[17527]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=202.96.59.201
Nov 19 06:35:25 mail vsftpd(pam_unix)[17525]: check pass; user unknown
Nov 19 06:35:25 mail vsftpd(pam_unix)[17525]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=202.96.59.201
Nov 19 06:35:28 mail vsftpd(pam_unix)[17527]: check pass; user unknown
Nov 19 06:35:28 mail vsftpd(pam_unix)[17527]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=202.96.59.201
Nov 19 06:35:28 mail vsftpd(pam_unix)[17525]: check pass; user unknown
Nov 19 06:35:28 mail vsftpd(pam_unix)[17525]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=202.96.59.201
Nov 19 06:35:30 mail vsftpd(pam_unix)[17527]: check pass; user unknown
Nov 19 06:35:30 mail vsftpd(pam_unix)[17527]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=202.96.59.201
Nov 19 06:35:30 mail vsftpd(pam_unix)[17525]: check pass; user unknown
Nov 19 06:35:30 mail vsftpd(pam_unix)[17525]: authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=202.96.59.201
Nov 19 06:35:32 mail vsftpd(pam_unix)[17527]: check pass; user unknown
再看 logwatch 的记录 :
vsftpd:
Unknown Entries:
check pass; user unknown: 12252 Time(s)
authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=64.107.76.15 : 11841 Time(s)
authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=218.94.26.146 : 409 Time(s)
恐怖吧,1W多次啊。。。 |
|