|
|

楼主 |
发表于 2006-3-17 14:31:51
|
显示全部楼层
在我的安全日志文件secure里有人试图远程SSH登陆的记录,我找了那段DOWN机时间的日志,9点多钟DOWN掉的
Mar 16 09:16:53 wst sshd[643]: Server listening on 0.0.0.0 port 22.
Mar 16 09:17:22 wst xinetd[657]: START: sgi_fam pid=947 from=<no address>
Mar 16 12:58:02 wst sshd[4020]: Did not receive identification string from 208.35.104.59
Mar 16 13:04:37 wst sshd[4099]: Could not reverse map address 208.35.104.59.
Mar 16 13:04:38 wst sshd[4101]: Could not reverse map address 208.35.104.59.
Mar 16 13:04:43 wst sshd[4104]: Could not reverse map address 208.35.104.59.
Mar 16 13:04:52 wst sshd[4112]: Could not reverse map address 208.35.104.59.
Mar 16 13:05:01 wst sshd[4114]: Could not reverse map address 208.35.104.59.
Mar 16 13:05:08 wst sshd[4116]: Could not reverse map address 208.35.104.59.
Mar 16 13:05:15 wst sshd[4118]: Could not reverse map address 208.35.104.59.
Mar 16 13:05:21 wst sshd[4120]: Could not reverse map address 208.35.104.59.
Mar 17 06:42:04 wst sshd[10535]: Did not receive identification string from 80.86.81.233
Mar 17 06:48:38 wst sshd[10541]: Failed password for root from 80.86.81.233 port 55324 ssh2
Mar 17 06:48:45 wst sshd[10543]: Failed password for root from 80.86.81.233 port 55464 ssh2
Mar 17 06:49:17 wst sshd[10551]: Failed password for root from 80.86.81.233 port 55914 ssh2
Mar 17 11:48:20 wst sshd[16019]: Did not receive identification string from 219.235.52.5
Mar 17 13:30:45 wst sshd[17044]: Could not reverse map address 221.232.128.38.
Mar 17 13:30:45 wst sshd[17044]: Accepted password for root from 221.232.128.38 port 56920 ssh2
Mar 17 13:30:45 wst sshd[17044]: subsystem request for sftp |
|