Gentoo Archives: gentoo-user-es

From: "Fede Diaz (aka Nordri)" <fede3birras@×××××.es>
To: gentoo-user-es@l.g.o
Subject: Re: [gentoo-user-es] Intentos de acceso ssh
Date: Mon, 25 Jul 2005 16:46:25
Message-Id: 42E51741.7050405@yahoo.es
In Reply to: [gentoo-user-es] Intentos de acceso ssh by Angel Cervera Claudio
1 Tal vez te interese leer esto:
2
3 http://barrapunto.com/article.pl?sid=05/07/24/106216&mode=thread
4
5 Saludos
6
7 Angel Cervera Claudio escribió:
8
9 > Hola a todos.
10 > Tengo un problemilla.
11 > Todos los días recibo "ataques".
12 > Es una tontería. Simplemente intentan logarse en mi máquina mediante
13 > ssh con diferentes usuario.
14 > Lógicamente no consiguen entrar, pero me gustaría se se puede bloquear
15 > estas ips de forma automática durante un tiempo, para impedir que
16 > sigan intentándolo.
17 > Es decir:
18 > Si desde la misma dirección ip se intenta acceder de varios usuarios
19 > distintos y no lo consigue, bloquear esa ip durante un buen rato.
20 >
21 > Tenía pensado, mediante iptables, restringir el acceso ssh sólo si
22 > accedo desde mi máquina, pero como no tengo ip fija. :(
23 >
24 > En el caso de poder hacer esto, cómo se llamaría la técnica. Lo digo
25 > para buscar en el google.
26 >
27 > Un saludi y gracias.
28 >
29 > Os paso fragmentos del log:
30 > ..............
31 > Jul 19 03:06:03 [sshd] Invalid user lynx from 211.233.73.160
32 > Jul 19 03:06:13 [sshd] Invalid user monkey from 211.233.73.160
33 > Jul 19 03:06:22 [sshd] Invalid user lion from 211.233.73.160
34 > Jul 19 03:06:30 [sshd] Invalid user heart from 211.233.73.160
35 > Jul 19 03:06:39 [sshd] Invalid user michel from 211.233.73.160
36 > Jul 19 03:06:48 [sshd] Invalid user alibaba from 211.233.73.160
37 > Jul 19 03:06:56 [sshd] Invalid user bebe from 211.233.73.160
38 > Jul 19 03:07:05 [sshd] Invalid user mp3 from 211.233.73.160
39 > Jul 19 03:07:14 [sshd] Invalid user music from 211.233.73.160
40 > Jul 19 03:07:23 [sshd] Invalid user spirit from 211.233.73.160
41 > Jul 19 03:07:32 [sshd] Invalid user radu from 211.233.73.160
42 > Jul 19 03:07:41 [sshd] Invalid user xxx from 211.233.73.160
43 > Jul 19 03:07:50 [sshd] Invalid user sex from 211.233.73.160
44 > Jul 19 03:07:59 [sshd] Invalid user lolita from 211.233.73.160
45 > Jul 19 03:08:08 [sshd] Invalid user teen from 211.233.73.160
46 > Jul 19 03:08:17 [sshd] Invalid user adult from 211.233.73.160
47 > Jul 19 03:08:26 [sshd] Invalid user movie from 211.233.73.160
48 > Jul 19 03:08:35 [sshd] Invalid user movies from 211.233.73.160
49 > Jul 19 03:08:54 [sshd] Invalid user status from 211.233.73.160
50 > Jul 19 03:09:04 [sshd] Invalid user iptables from 211.233.73.160
51 > Jul 19 03:09:14 [sshd] Invalid user portal from 211.233.73.160
52 > Jul 19 03:09:23 [sshd] Invalid user history from 211.233.73.160
53 > Jul 19 03:09:32 [sshd] Invalid user dev from 211.233.73.160
54 > Jul 19 03:09:40 [sshd] Invalid user egrep from 211.233.73.160
55 > Jul 19 03:09:48 [sshd] Invalid user update from 211.233.73.160
56 > Jul 19 07:53:08 [sshd] Invalid user test from 202.127.19.158
57 > ..........
58 > Jul 20 10:27:40 [sshd] Invalid user test from 213.61.160.9
59 > - Last output repeated 25 times -
60 > Jul 20 10:27:48 [sshd] Invalid user admin from 213.61.160.9
61 > - Last output repeated 27 times -
62 > Jul 20 10:27:57 [sshd] User guest not allowed because shell /dev/null
63 > is not executable
64 > - Last output repeated 20 times -
65 > Jul 20 10:28:02 [sshd] Invalid user user from 213.61.160.9
66 > - Last output repeated 22 times -
67 > Jul 20 10:28:09 [sshd] Invalid user sales from 213.61.160.9
68 > - Last output repeated 7 times -
69 > Jul 20 10:28:14 [sshd] Invalid user webadmin from 213.61.160.9
70 > - Last output repeated 8 times -
71 > Jul 20 10:28:17 [sshd] Invalid user spam from 213.61.160.9
72 > - Last output repeated 7 times -
73 > Jul 20 10:28:20 [sshd] Invalid user virus from 213.61.160.9
74 > - Last output repeated 7 times -
75 > Jul 20 10:28:25 [sshd] Invalid user oracle from 213.61.160.9
76 > - Last output repeated 7 times -
77 > Jul 20 10:28:32 [sshd] Invalid user webmaster from 213.61.160.9
78 > - Last output repeated 6 times -
79 > Jul 20 10:28:42 [sshd] Invalid user linux from 213.61.160.9
80 > - Last output repeated 2 times -
81 > Jul 20 10:28:43 [sshd] Invalid user web from 213.61.160.9
82 > - Last output repeated 3 times -
83 > Jul 20 10:28:44 [sshd] Invalid user webmail from 213.61.160.9
84 > - Last output repeated 5 times -
85 > Jul 20 10:28:48 [sshd] Invalid user pgsql from 213.61.160.9
86 > Jul 20 10:28:48 [sshd] Invalid user pqsql from 213.61.160.9
87 > Jul 20 10:28:48 [sshd] Invalid user pgsql from 213.61.160.9
88 > - Last output repeated 5 times -
89 > Jul 20 10:28:52 [sshd] Invalid user info from 213.61.160.9
90 > - Last output repeated 14 times -
91 > Jul 20 10:28:56 [sshd] Invalid user library from 213.61.160.9
92 > - Last output repeated 8 times -
93 > ...............
94 > Jul 23 23:32:37 [sshd] Invalid user jancsi from 218.188.14.243
95 > Jul 23 23:32:39 [sshd] Invalid user jani from 218.188.14.243
96 > Jul 23 23:32:42 [sshd] Invalid user janika from 218.188.14.243
97 > Jul 23 23:32:44 [sshd] Invalid user janos from 218.188.14.243
98 > Jul 23 23:32:47 [sshd] Invalid user jenci from 218.188.14.243
99 > Jul 23 23:32:49 [sshd] Invalid user jeno from 218.188.14.243
100 > Jul 23 23:32:52 [sshd] Invalid user johanna from 218.188.14.243
101 > Jul 23 23:32:54 [sshd] Invalid user jolan from 218.188.14.243
102 > Jul 23 23:32:57 [sshd] Invalid user jolanka from 218.188.14.243
103 > Jul 23 23:32:59 [sshd] Invalid user levi from 218.188.14.243
104 > Jul 23 23:33:02 [sshd] Invalid user levente from 218.188.14.243
105 > Jul 23 23:33:04 [sshd] Invalid user isti from 218.188.14.243
106 > Jul 23 23:33:07 [sshd] Invalid user pisti from 218.188.14.243
107 > Jul 23 23:33:09 [sshd] Invalid user tibor from 218.188.14.243
108 > Jul 23 23:33:12 [sshd] Invalid user karoly from 218.188.14.243
109 > Jul 23 23:33:14 [sshd] Invalid user tibi from 218.188.14.243
110 > Jul 23 23:33:17 [sshd] Invalid user norbi from 218.188.14.243
111 > Jul 23 23:33:19 [sshd] Invalid user marta from 218.188.14.243
112 > Jul 23 23:33:22 [sshd] Invalid user zoltan from 218.188.14.243
113 > Jul 23 23:33:25 [sshd] Invalid user agape from 218.188.14.243
114 > Jul 23 23:33:27 [sshd] Invalid user agapios from 218.188.14.243
115 > Jul 23 23:33:30 [sshd] Invalid user agathe from 218.188.14.243
116 > Jul 23 23:33:32 [sshd] Invalid user aglaia from 218.188.14.243
117 > Jul 24 04:07:23 [sshd] Invalid user admin from 60.248.99.237
118 > - Last output repeated 2 times -
119 > Jul 24 04:07:32 [sshd] Invalid user ftpuser from 60.248.99.237
120 > - Last output repeated 6 times -
121 > Jul 24 04:07:54 [sshd] Invalid user mailtest from 60.248.99.237
122 > - Last output repeated 5 times -
123 > Jul 24 04:08:12 [sshd] Invalid user testuser from 60.248.99.237
124 > - Last output repeated 5 times -
125 > Jul 24 04:08:30 [sshd] Invalid user sales from 60.248.99.237
126 > - Last output repeated 6 times -
127 > Jul 24 04:09:53 [sshd] Invalid user student from 60.248.99.237
128 > - Last output repeated 5 times -
129 > Jul 24 04:10:12 [sshd] Invalid user service from 60.248.99.237
130 > - Last output repeated 5 times -
131 > ......
132 > Y así hasta el infinito.
133 >
134 >
135 >
136 >
137
138 --
139
140
141 ______________________________________________
142 Renovamos el Correo Yahoo!
143 Nuevos servicios, más seguridad
144 http://correo.yahoo.es
145 --
146 gentoo-user-es@g.o mailing list

Replies

Subject Author
Re: [gentoo-user-es] Intentos de acceso ssh Angel Cervera Claudio <angel@××××××××.com>