>"...IMO schaut das nach einem gezielten angriff aufs SSH service aus..."
von einem gezielten angriff würd ich jetzt nicht reden. es hat schon immer hinreichend vielen affen gegeben, die das ganze netz auf offene standardports abscannen. dann stoßen sie irgendwo auf einen offenen port und gehen halt die standardpw.'s durch. unlängst wollte einer unbedingt mit ssh auf das st eines bekannten (war auf tcp/22 wanseitig offen):
- Code: Alles auswählen
=>syslog msgbuf show
<37> Feb 13 08:47:53 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:47:57 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:48:01 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:48:05 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:48:09 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:48:13 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:48:17 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:48:21 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:48:25 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:48:29 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:48:33 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:48:37 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:48:41 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:48:45 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:48:49 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:48:53 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:48:57 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:49:01 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:49:05 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:49:09 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:49:13 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:49:17 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:49:21 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:49:25 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:49:29 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:49:33 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:49:37 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:49:41 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:49:45 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:49:49 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:49:53 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:49:57 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:50:01 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:50:05 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:50:09 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:50:13 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:50:17 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:50:21 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:50:25 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:50:29 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:50:33 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:50:37 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:50:41 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:50:45 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:50:49 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:50:53 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:50:57 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:51:01 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:51:05 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:51:09 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:51:13 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:51:17 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:51:21 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:51:25 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:51:29 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:51:33 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:51:37 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:51:41 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:51:45 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:51:49 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:51:53 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:51:57 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:52:01 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:52:05 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:52:09 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:52:13 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:52:17 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:52:21 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:52:25 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:52:29 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:52:33 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:52:37 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:52:41 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:52:45 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:52:49 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:52:53 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:52:57 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:53:01 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:53:05 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:53:09 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:53:13 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:53:17 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:53:21 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:53:25 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:53:29 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:53:33 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:53:37 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:53:41 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:53:45 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:53:49 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:53:53 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:53:57 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:54:01 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:54:05 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:54:09 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:54:13 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:54:17 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:54:21 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:54:25 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:54:29 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:54:33 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:54:37 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:54:41 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:54:45 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:54:49 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:54:53 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:54:57 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:55:01 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:55:05 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:55:09 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:55:13 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:55:17 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:55:21 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:55:25 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:55:29 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:55:33 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:55:37 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:55:41 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:55:45 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:55:49 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:55:53 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:55:57 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:56:01 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:56:05 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:56:09 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:56:13 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:56:17 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:56:21 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:56:25 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:56:29 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:56:33 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:56:37 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:56:41 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:56:45 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:56:49 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:56:53 LOGOUT session of user killed (118.97.246.31)
<37> Feb 13 08:58:27 LOGOUT session of user gmail killed (72.55.148.230)
<37> Feb 13 09:17:54 LOGOUT session of user fastweb killed (72.55.148.230)
<37> Feb 13 09:39:34 LOGOUT session of user newsletter killed (72.55.148.230)
<37> Feb 13 10:11:36 LOGOUT session of user visitor killed (72.55.148.230)
<37> Feb 13 10:42:23 LOGOUT session of user ftpuser killed (72.55.148.230)
<37> Feb 13 10:58:10 LOGOUT session of user username killed (72.55.148.230)
...
...
da ichs nicht gern hab, daß mir die logs zugemüllt werden, hab ich halt eine acl gesetzt. jetzt ist ruhe.
alternativ (nicht so gut) könnte man die wartungsdienste auch auf non-standardports laufen lassen. früher war ich nicht so begeistert von dieser idee, aber es bringts wirklich. der größte müll ist einmal weg.
lg
zid
//edit:
>"...nicht "könnte", IST..."
yep, der typ wollte sich als user "teste" anmelden.