silasmg
(usa Debian)
Enviado em 27/10/2015 - 15:03h
em auth.log encontrei algumas linhas assim:
Oct 25 11:47:11 saude sshd[26309]: Failed password for root from 177.19.238.210 port 54646 ssh2
Oct 25 11:47:11 saude sshd[26309]: Connection closed by 177.19.238.210 [preauth]
Oct 25 11:48:01 saude sshd[26315]: Address 177.19.238.210 maps to 177.19.238.210.static.gvt.net.br, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Oct 25 11:48:01 saude sshd[26315]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=177.19.238.210 user=root
Oct 25 11:48:04 saude sshd[26315]: Failed password for root from 177.19.238.210 port 33879 ssh2
Oct 25 11:48:04 saude sshd[26315]: Connection closed by 177.19.238.210 [preauth]
Oct 25 11:50:15 saude sshd[26359]: Address 177.19.238.210 maps to 177.19.238.210.static.gvt.net.br, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Oct 25 11:50:15 saude sshd[26359]: Invalid user admin from 177.19.238.210
Oct 25 11:50:15 saude sshd[26359]: input_userauth_request: invalid user admin [preauth]
Oct 25 11:50:15 saude sshd[26359]: pam_unix(sshd:auth): check pass; user unknown
Oct 25 11:50:15 saude sshd[26359]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=177.19.238.210
Oct 25 11:50:18 saude sshd[26359]: Failed password for invalid user admin from 177.19.238.210 port 53911 ssh2
Oct 25 11:50:18 saude sshd[26359]: Connection closed by 177.19.238.210 [preauth]
Oct 25 11:51:09 saude sshd[26369]: Address 177.19.238.210 maps to 177.19.238.210.static.gvt.net.br, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Oct 25 11:51:09 saude sshd[26369]: Invalid user admin from 177.19.238.210
Oct 25 11:51:09 saude sshd[26369]: input_userauth_request: invalid user admin [preauth]
Oct 25 11:51:09 saude sshd[26369]: pam_unix(sshd:auth): check pass; user unknown
Oct 25 11:51:09 saude sshd[26369]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=177.19.238.210
Oct 25 11:51:11 saude sshd[26369]: Failed password for invalid user admin from 177.19.238.210 port 33825 ssh2
Oct 25 11:51:11 saude sshd[26369]: Connection closed by 177.19.238.210 [preauth]
Oct 25 11:53:35 saude sshd[26410]: Address 177.19.238.210 maps to 177.19.238.210.static.gvt.net.br, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
e nos processos ainda encontrei isto:
xhlds 544 558 root 160u IPv4 3433830 0t0 UDP 189-73-173-78.paebv701.e.brasiltelecom.net.br:27157
xhlds 544 558 root 161u IPv4 3433831 0t0 UDP 189-73-173-78.paebv701.e.brasiltelecom.net.br:27158
xhlds 544 558 root 162u IPv4 3433832 0t0 UDP 189-73-173-78.paebv701.e.brasiltelecom.net.br:27159
xhlds 544 558 root 163u IPv4 3433833 0t0 UDP 189-73-173-78.paebv701.e.brasiltelecom.net.br:27160
xhlds 544 558 root 164u IPv4 3433834 0t0 UDP 189-73-173-78.paebv701.e.brasiltelecom.net.br:27161