1 |
Curioso, pero estos ataques los llevo sufriendo desde hace mucho tiempo. |
2 |
|
3 |
De todas formas, ahí he podido encontrar direcciones que, aunque no |
4 |
hacen lo que comentaba, parecen muy interesantes: |
5 |
http://a.mongers.org/muppets/20040808-sshscan-1 |
6 |
|
7 |
Gracias. |
8 |
|
9 |
|
10 |
|
11 |
Fede Diaz (aka Nordri) wrote: |
12 |
|
13 |
> Tal vez te interese leer esto: |
14 |
> |
15 |
> http://barrapunto.com/article.pl?sid=05/07/24/106216&mode=thread |
16 |
> |
17 |
> Saludos |
18 |
> |
19 |
> Angel Cervera Claudio escribió: |
20 |
> |
21 |
>> Hola a todos. |
22 |
>> Tengo un problemilla. |
23 |
>> Todos los días recibo "ataques". |
24 |
>> Es una tontería. Simplemente intentan logarse en mi máquina mediante |
25 |
>> ssh con diferentes usuario. |
26 |
>> Lógicamente no consiguen entrar, pero me gustaría se se puede |
27 |
>> bloquear estas ips de forma automática durante un tiempo, para |
28 |
>> impedir que sigan intentándolo. |
29 |
>> Es decir: |
30 |
>> Si desde la misma dirección ip se intenta acceder de varios usuarios |
31 |
>> distintos y no lo consigue, bloquear esa ip durante un buen rato. |
32 |
>> |
33 |
>> Tenía pensado, mediante iptables, restringir el acceso ssh sólo si |
34 |
>> accedo desde mi máquina, pero como no tengo ip fija. :( |
35 |
>> |
36 |
>> En el caso de poder hacer esto, cómo se llamaría la técnica. Lo digo |
37 |
>> para buscar en el google. |
38 |
>> |
39 |
>> Un saludi y gracias. |
40 |
>> |
41 |
>> Os paso fragmentos del log: |
42 |
>> .............. |
43 |
>> Jul 19 03:06:03 [sshd] Invalid user lynx from 211.233.73.160 |
44 |
>> Jul 19 03:06:13 [sshd] Invalid user monkey from 211.233.73.160 |
45 |
>> Jul 19 03:06:22 [sshd] Invalid user lion from 211.233.73.160 |
46 |
>> Jul 19 03:06:30 [sshd] Invalid user heart from 211.233.73.160 |
47 |
>> Jul 19 03:06:39 [sshd] Invalid user michel from 211.233.73.160 |
48 |
>> Jul 19 03:06:48 [sshd] Invalid user alibaba from 211.233.73.160 |
49 |
>> Jul 19 03:06:56 [sshd] Invalid user bebe from 211.233.73.160 |
50 |
>> Jul 19 03:07:05 [sshd] Invalid user mp3 from 211.233.73.160 |
51 |
>> Jul 19 03:07:14 [sshd] Invalid user music from 211.233.73.160 |
52 |
>> Jul 19 03:07:23 [sshd] Invalid user spirit from 211.233.73.160 |
53 |
>> Jul 19 03:07:32 [sshd] Invalid user radu from 211.233.73.160 |
54 |
>> Jul 19 03:07:41 [sshd] Invalid user xxx from 211.233.73.160 |
55 |
>> Jul 19 03:07:50 [sshd] Invalid user sex from 211.233.73.160 |
56 |
>> Jul 19 03:07:59 [sshd] Invalid user lolita from 211.233.73.160 |
57 |
>> Jul 19 03:08:08 [sshd] Invalid user teen from 211.233.73.160 |
58 |
>> Jul 19 03:08:17 [sshd] Invalid user adult from 211.233.73.160 |
59 |
>> Jul 19 03:08:26 [sshd] Invalid user movie from 211.233.73.160 |
60 |
>> Jul 19 03:08:35 [sshd] Invalid user movies from 211.233.73.160 |
61 |
>> Jul 19 03:08:54 [sshd] Invalid user status from 211.233.73.160 |
62 |
>> Jul 19 03:09:04 [sshd] Invalid user iptables from 211.233.73.160 |
63 |
>> Jul 19 03:09:14 [sshd] Invalid user portal from 211.233.73.160 |
64 |
>> Jul 19 03:09:23 [sshd] Invalid user history from 211.233.73.160 |
65 |
>> Jul 19 03:09:32 [sshd] Invalid user dev from 211.233.73.160 |
66 |
>> Jul 19 03:09:40 [sshd] Invalid user egrep from 211.233.73.160 |
67 |
>> Jul 19 03:09:48 [sshd] Invalid user update from 211.233.73.160 |
68 |
>> Jul 19 07:53:08 [sshd] Invalid user test from 202.127.19.158 |
69 |
>> .......... |
70 |
>> Jul 20 10:27:40 [sshd] Invalid user test from 213.61.160.9 |
71 |
>> - Last output repeated 25 times - |
72 |
>> Jul 20 10:27:48 [sshd] Invalid user admin from 213.61.160.9 |
73 |
>> - Last output repeated 27 times - |
74 |
>> Jul 20 10:27:57 [sshd] User guest not allowed because shell /dev/null |
75 |
>> is not executable |
76 |
>> - Last output repeated 20 times - |
77 |
>> Jul 20 10:28:02 [sshd] Invalid user user from 213.61.160.9 |
78 |
>> - Last output repeated 22 times - |
79 |
>> Jul 20 10:28:09 [sshd] Invalid user sales from 213.61.160.9 |
80 |
>> - Last output repeated 7 times - |
81 |
>> Jul 20 10:28:14 [sshd] Invalid user webadmin from 213.61.160.9 |
82 |
>> - Last output repeated 8 times - |
83 |
>> Jul 20 10:28:17 [sshd] Invalid user spam from 213.61.160.9 |
84 |
>> - Last output repeated 7 times - |
85 |
>> Jul 20 10:28:20 [sshd] Invalid user virus from 213.61.160.9 |
86 |
>> - Last output repeated 7 times - |
87 |
>> Jul 20 10:28:25 [sshd] Invalid user oracle from 213.61.160.9 |
88 |
>> - Last output repeated 7 times - |
89 |
>> Jul 20 10:28:32 [sshd] Invalid user webmaster from 213.61.160.9 |
90 |
>> - Last output repeated 6 times - |
91 |
>> Jul 20 10:28:42 [sshd] Invalid user linux from 213.61.160.9 |
92 |
>> - Last output repeated 2 times - |
93 |
>> Jul 20 10:28:43 [sshd] Invalid user web from 213.61.160.9 |
94 |
>> - Last output repeated 3 times - |
95 |
>> Jul 20 10:28:44 [sshd] Invalid user webmail from 213.61.160.9 |
96 |
>> - Last output repeated 5 times - |
97 |
>> Jul 20 10:28:48 [sshd] Invalid user pgsql from 213.61.160.9 |
98 |
>> Jul 20 10:28:48 [sshd] Invalid user pqsql from 213.61.160.9 |
99 |
>> Jul 20 10:28:48 [sshd] Invalid user pgsql from 213.61.160.9 |
100 |
>> - Last output repeated 5 times - |
101 |
>> Jul 20 10:28:52 [sshd] Invalid user info from 213.61.160.9 |
102 |
>> - Last output repeated 14 times - |
103 |
>> Jul 20 10:28:56 [sshd] Invalid user library from 213.61.160.9 |
104 |
>> - Last output repeated 8 times - |
105 |
>> ............... |
106 |
>> Jul 23 23:32:37 [sshd] Invalid user jancsi from 218.188.14.243 |
107 |
>> Jul 23 23:32:39 [sshd] Invalid user jani from 218.188.14.243 |
108 |
>> Jul 23 23:32:42 [sshd] Invalid user janika from 218.188.14.243 |
109 |
>> Jul 23 23:32:44 [sshd] Invalid user janos from 218.188.14.243 |
110 |
>> Jul 23 23:32:47 [sshd] Invalid user jenci from 218.188.14.243 |
111 |
>> Jul 23 23:32:49 [sshd] Invalid user jeno from 218.188.14.243 |
112 |
>> Jul 23 23:32:52 [sshd] Invalid user johanna from 218.188.14.243 |
113 |
>> Jul 23 23:32:54 [sshd] Invalid user jolan from 218.188.14.243 |
114 |
>> Jul 23 23:32:57 [sshd] Invalid user jolanka from 218.188.14.243 |
115 |
>> Jul 23 23:32:59 [sshd] Invalid user levi from 218.188.14.243 |
116 |
>> Jul 23 23:33:02 [sshd] Invalid user levente from 218.188.14.243 |
117 |
>> Jul 23 23:33:04 [sshd] Invalid user isti from 218.188.14.243 |
118 |
>> Jul 23 23:33:07 [sshd] Invalid user pisti from 218.188.14.243 |
119 |
>> Jul 23 23:33:09 [sshd] Invalid user tibor from 218.188.14.243 |
120 |
>> Jul 23 23:33:12 [sshd] Invalid user karoly from 218.188.14.243 |
121 |
>> Jul 23 23:33:14 [sshd] Invalid user tibi from 218.188.14.243 |
122 |
>> Jul 23 23:33:17 [sshd] Invalid user norbi from 218.188.14.243 |
123 |
>> Jul 23 23:33:19 [sshd] Invalid user marta from 218.188.14.243 |
124 |
>> Jul 23 23:33:22 [sshd] Invalid user zoltan from 218.188.14.243 |
125 |
>> Jul 23 23:33:25 [sshd] Invalid user agape from 218.188.14.243 |
126 |
>> Jul 23 23:33:27 [sshd] Invalid user agapios from 218.188.14.243 |
127 |
>> Jul 23 23:33:30 [sshd] Invalid user agathe from 218.188.14.243 |
128 |
>> Jul 23 23:33:32 [sshd] Invalid user aglaia from 218.188.14.243 |
129 |
>> Jul 24 04:07:23 [sshd] Invalid user admin from 60.248.99.237 |
130 |
>> - Last output repeated 2 times - |
131 |
>> Jul 24 04:07:32 [sshd] Invalid user ftpuser from 60.248.99.237 |
132 |
>> - Last output repeated 6 times - |
133 |
>> Jul 24 04:07:54 [sshd] Invalid user mailtest from 60.248.99.237 |
134 |
>> - Last output repeated 5 times - |
135 |
>> Jul 24 04:08:12 [sshd] Invalid user testuser from 60.248.99.237 |
136 |
>> - Last output repeated 5 times - |
137 |
>> Jul 24 04:08:30 [sshd] Invalid user sales from 60.248.99.237 |
138 |
>> - Last output repeated 6 times - |
139 |
>> Jul 24 04:09:53 [sshd] Invalid user student from 60.248.99.237 |
140 |
>> - Last output repeated 5 times - |
141 |
>> Jul 24 04:10:12 [sshd] Invalid user service from 60.248.99.237 |
142 |
>> - Last output repeated 5 times - |
143 |
>> ...... |
144 |
>> Y así hasta el infinito. |
145 |
>> |
146 |
>> |
147 |
>> |
148 |
>> |
149 |
> |
150 |
|
151 |
|
152 |
-- |
153 |
Ángel Cervera Claudio |
154 |
Freelance / desarrollos j2ee |
155 |
web: http://www.acervera.com |
156 |
tlf: 670819234 / 916058546 |
157 |
email: angel@××××××××.com |
158 |
msn: angelcervera@××××××××××.com |
159 |
yahoo: angelcervera |
160 |
aol: angelcervera |
161 |
jabber: angelcervera en jabber.org |
162 |
|
163 |
-- |
164 |
gentoo-user-es@g.o mailing list |