Gentoo Archives: gentoo-user-es

From: Angel Cervera Claudio <angel@××××××××.com>
To: gentoo-user-es@l.g.o
Subject: Re: [gentoo-user-es] Intentos de acceso ssh
Date: Mon, 25 Jul 2005 20:30:08
Message-Id: 42E54BAB.10200@acervera.com
In Reply to: Re: [gentoo-user-es] Intentos de acceso ssh by "Fede Diaz (aka Nordri)"
1 Curioso, pero estos ataques los llevo sufriendo desde hace mucho tiempo.
2
3 De todas formas, ahí he podido encontrar direcciones que, aunque no
4 hacen lo que comentaba, parecen muy interesantes:
5 http://a.mongers.org/muppets/20040808-sshscan-1
6
7 Gracias.
8
9
10
11 Fede Diaz (aka Nordri) wrote:
12
13 > Tal vez te interese leer esto:
14 >
15 > http://barrapunto.com/article.pl?sid=05/07/24/106216&mode=thread
16 >
17 > Saludos
18 >
19 > Angel Cervera Claudio escribió:
20 >
21 >> Hola a todos.
22 >> Tengo un problemilla.
23 >> Todos los días recibo "ataques".
24 >> Es una tontería. Simplemente intentan logarse en mi máquina mediante
25 >> ssh con diferentes usuario.
26 >> Lógicamente no consiguen entrar, pero me gustaría se se puede
27 >> bloquear estas ips de forma automática durante un tiempo, para
28 >> impedir que sigan intentándolo.
29 >> Es decir:
30 >> Si desde la misma dirección ip se intenta acceder de varios usuarios
31 >> distintos y no lo consigue, bloquear esa ip durante un buen rato.
32 >>
33 >> Tenía pensado, mediante iptables, restringir el acceso ssh sólo si
34 >> accedo desde mi máquina, pero como no tengo ip fija. :(
35 >>
36 >> En el caso de poder hacer esto, cómo se llamaría la técnica. Lo digo
37 >> para buscar en el google.
38 >>
39 >> Un saludi y gracias.
40 >>
41 >> Os paso fragmentos del log:
42 >> ..............
43 >> Jul 19 03:06:03 [sshd] Invalid user lynx from 211.233.73.160
44 >> Jul 19 03:06:13 [sshd] Invalid user monkey from 211.233.73.160
45 >> Jul 19 03:06:22 [sshd] Invalid user lion from 211.233.73.160
46 >> Jul 19 03:06:30 [sshd] Invalid user heart from 211.233.73.160
47 >> Jul 19 03:06:39 [sshd] Invalid user michel from 211.233.73.160
48 >> Jul 19 03:06:48 [sshd] Invalid user alibaba from 211.233.73.160
49 >> Jul 19 03:06:56 [sshd] Invalid user bebe from 211.233.73.160
50 >> Jul 19 03:07:05 [sshd] Invalid user mp3 from 211.233.73.160
51 >> Jul 19 03:07:14 [sshd] Invalid user music from 211.233.73.160
52 >> Jul 19 03:07:23 [sshd] Invalid user spirit from 211.233.73.160
53 >> Jul 19 03:07:32 [sshd] Invalid user radu from 211.233.73.160
54 >> Jul 19 03:07:41 [sshd] Invalid user xxx from 211.233.73.160
55 >> Jul 19 03:07:50 [sshd] Invalid user sex from 211.233.73.160
56 >> Jul 19 03:07:59 [sshd] Invalid user lolita from 211.233.73.160
57 >> Jul 19 03:08:08 [sshd] Invalid user teen from 211.233.73.160
58 >> Jul 19 03:08:17 [sshd] Invalid user adult from 211.233.73.160
59 >> Jul 19 03:08:26 [sshd] Invalid user movie from 211.233.73.160
60 >> Jul 19 03:08:35 [sshd] Invalid user movies from 211.233.73.160
61 >> Jul 19 03:08:54 [sshd] Invalid user status from 211.233.73.160
62 >> Jul 19 03:09:04 [sshd] Invalid user iptables from 211.233.73.160
63 >> Jul 19 03:09:14 [sshd] Invalid user portal from 211.233.73.160
64 >> Jul 19 03:09:23 [sshd] Invalid user history from 211.233.73.160
65 >> Jul 19 03:09:32 [sshd] Invalid user dev from 211.233.73.160
66 >> Jul 19 03:09:40 [sshd] Invalid user egrep from 211.233.73.160
67 >> Jul 19 03:09:48 [sshd] Invalid user update from 211.233.73.160
68 >> Jul 19 07:53:08 [sshd] Invalid user test from 202.127.19.158
69 >> ..........
70 >> Jul 20 10:27:40 [sshd] Invalid user test from 213.61.160.9
71 >> - Last output repeated 25 times -
72 >> Jul 20 10:27:48 [sshd] Invalid user admin from 213.61.160.9
73 >> - Last output repeated 27 times -
74 >> Jul 20 10:27:57 [sshd] User guest not allowed because shell /dev/null
75 >> is not executable
76 >> - Last output repeated 20 times -
77 >> Jul 20 10:28:02 [sshd] Invalid user user from 213.61.160.9
78 >> - Last output repeated 22 times -
79 >> Jul 20 10:28:09 [sshd] Invalid user sales from 213.61.160.9
80 >> - Last output repeated 7 times -
81 >> Jul 20 10:28:14 [sshd] Invalid user webadmin from 213.61.160.9
82 >> - Last output repeated 8 times -
83 >> Jul 20 10:28:17 [sshd] Invalid user spam from 213.61.160.9
84 >> - Last output repeated 7 times -
85 >> Jul 20 10:28:20 [sshd] Invalid user virus from 213.61.160.9
86 >> - Last output repeated 7 times -
87 >> Jul 20 10:28:25 [sshd] Invalid user oracle from 213.61.160.9
88 >> - Last output repeated 7 times -
89 >> Jul 20 10:28:32 [sshd] Invalid user webmaster from 213.61.160.9
90 >> - Last output repeated 6 times -
91 >> Jul 20 10:28:42 [sshd] Invalid user linux from 213.61.160.9
92 >> - Last output repeated 2 times -
93 >> Jul 20 10:28:43 [sshd] Invalid user web from 213.61.160.9
94 >> - Last output repeated 3 times -
95 >> Jul 20 10:28:44 [sshd] Invalid user webmail from 213.61.160.9
96 >> - Last output repeated 5 times -
97 >> Jul 20 10:28:48 [sshd] Invalid user pgsql from 213.61.160.9
98 >> Jul 20 10:28:48 [sshd] Invalid user pqsql from 213.61.160.9
99 >> Jul 20 10:28:48 [sshd] Invalid user pgsql from 213.61.160.9
100 >> - Last output repeated 5 times -
101 >> Jul 20 10:28:52 [sshd] Invalid user info from 213.61.160.9
102 >> - Last output repeated 14 times -
103 >> Jul 20 10:28:56 [sshd] Invalid user library from 213.61.160.9
104 >> - Last output repeated 8 times -
105 >> ...............
106 >> Jul 23 23:32:37 [sshd] Invalid user jancsi from 218.188.14.243
107 >> Jul 23 23:32:39 [sshd] Invalid user jani from 218.188.14.243
108 >> Jul 23 23:32:42 [sshd] Invalid user janika from 218.188.14.243
109 >> Jul 23 23:32:44 [sshd] Invalid user janos from 218.188.14.243
110 >> Jul 23 23:32:47 [sshd] Invalid user jenci from 218.188.14.243
111 >> Jul 23 23:32:49 [sshd] Invalid user jeno from 218.188.14.243
112 >> Jul 23 23:32:52 [sshd] Invalid user johanna from 218.188.14.243
113 >> Jul 23 23:32:54 [sshd] Invalid user jolan from 218.188.14.243
114 >> Jul 23 23:32:57 [sshd] Invalid user jolanka from 218.188.14.243
115 >> Jul 23 23:32:59 [sshd] Invalid user levi from 218.188.14.243
116 >> Jul 23 23:33:02 [sshd] Invalid user levente from 218.188.14.243
117 >> Jul 23 23:33:04 [sshd] Invalid user isti from 218.188.14.243
118 >> Jul 23 23:33:07 [sshd] Invalid user pisti from 218.188.14.243
119 >> Jul 23 23:33:09 [sshd] Invalid user tibor from 218.188.14.243
120 >> Jul 23 23:33:12 [sshd] Invalid user karoly from 218.188.14.243
121 >> Jul 23 23:33:14 [sshd] Invalid user tibi from 218.188.14.243
122 >> Jul 23 23:33:17 [sshd] Invalid user norbi from 218.188.14.243
123 >> Jul 23 23:33:19 [sshd] Invalid user marta from 218.188.14.243
124 >> Jul 23 23:33:22 [sshd] Invalid user zoltan from 218.188.14.243
125 >> Jul 23 23:33:25 [sshd] Invalid user agape from 218.188.14.243
126 >> Jul 23 23:33:27 [sshd] Invalid user agapios from 218.188.14.243
127 >> Jul 23 23:33:30 [sshd] Invalid user agathe from 218.188.14.243
128 >> Jul 23 23:33:32 [sshd] Invalid user aglaia from 218.188.14.243
129 >> Jul 24 04:07:23 [sshd] Invalid user admin from 60.248.99.237
130 >> - Last output repeated 2 times -
131 >> Jul 24 04:07:32 [sshd] Invalid user ftpuser from 60.248.99.237
132 >> - Last output repeated 6 times -
133 >> Jul 24 04:07:54 [sshd] Invalid user mailtest from 60.248.99.237
134 >> - Last output repeated 5 times -
135 >> Jul 24 04:08:12 [sshd] Invalid user testuser from 60.248.99.237
136 >> - Last output repeated 5 times -
137 >> Jul 24 04:08:30 [sshd] Invalid user sales from 60.248.99.237
138 >> - Last output repeated 6 times -
139 >> Jul 24 04:09:53 [sshd] Invalid user student from 60.248.99.237
140 >> - Last output repeated 5 times -
141 >> Jul 24 04:10:12 [sshd] Invalid user service from 60.248.99.237
142 >> - Last output repeated 5 times -
143 >> ......
144 >> Y así hasta el infinito.
145 >>
146 >>
147 >>
148 >>
149 >
150
151
152 --
153 Ángel Cervera Claudio
154 Freelance / desarrollos j2ee
155 web: http://www.acervera.com
156 tlf: 670819234 / 916058546
157 email: angel@××××××××.com
158 msn: angelcervera@××××××××××.com
159 yahoo: angelcervera
160 aol: angelcervera
161 jabber: angelcervera en jabber.org
162
163 --
164 gentoo-user-es@g.o mailing list