09-14-2008, 02:37 PM
bueno. antes que nada. parte de la culpa es mia. Drago me enseño a "asegurar" el router pero estube haciendo unos testeos y deje todo abierto... pensaba seguir hoy. por ende. "culpa mia"
no obstante me gustaría ver si este tipo pudo entrar o no. por lo que puedo interpretar de los logs no pudo.
parte de los logs...
no obstante me gustaría ver si este tipo pudo entrar o no. por lo que puedo interpretar de los logs no pudo.
parte de los logs...
Código:
Sep 14 05:36:01 localhost sshd[22363]: Invalid user dario from 218.26.94.149
Sep 14 05:36:01 localhost sshd[22364]: input_userauth_request: invalid user dario
Sep 14 05:36:01 localhost sshd[22363]: pam_unix(sshd:auth): check pass; user unknown
Sep 14 05:36:01 localhost sshd[22363]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=218.26.94.149
Sep 14 05:36:01 localhost sshd[22363]: pam_succeed_if(sshd:auth): error retrieving information about user dario
Sep 14 05:36:03 localhost sshd[22363]: Failed password for invalid user dario from 218.26.94.149 port 42304 ssh2
Sep 14 05:36:04 localhost sshd[22364]: Received disconnect from 218.26.94.149: 11: Bye Bye
Sep 14 05:36:04 localhost sshd[22367]: Invalid user virginia from 218.26.94.149
Sep 14 05:36:04 localhost sshd[22370]: input_userauth_request: invalid user virginia
Sep 14 05:36:04 localhost sshd[22367]: pam_unix(sshd:auth): check pass; user unknown
Sep 14 05:36:04 localhost sshd[22367]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=218.26.94.149
Sep 14 05:36:04 localhost sshd[22367]: pam_succeed_if(sshd:auth): error retrieving information about user virginia
Sep 14 05:36:04 localhost sshd[22368]: Invalid user robot from 218.26.94.149
Sep 14 05:36:04 localhost sshd[22371]: input_userauth_request: invalid user robot
Sep 14 05:36:04 localhost sshd[22368]: pam_unix(sshd:auth): check pass; user unknown
Sep 14 05:36:04 localhost sshd[22368]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=218.26.94.149
Sep 14 05:36:04 localhost sshd[22368]: pam_succeed_if(sshd:auth): error retrieving information about user robot
Sep 14 05:36:04 localhost unix_chkpwd[22373]: password check failed for user (nobody)
Sep 14 05:36:04 localhost sshd[22369]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=218.26.94.149 user=nobody
Sep 14 05:36:06 localhost sshd[22367]: Failed password for invalid user virginia from 218.26.94.149 port 46956 ssh2
Sep 14 05:36:06 localhost sshd[22368]: Failed password for invalid user robot from 218.26.94.149 port 46986 ssh2
Sep 14 05:36:06 localhost sshd[22369]: Failed password for nobody from 218.26.94.149 port 47006 ssh2
Sep 14 05:36:10 localhost sshd[22370]: Connection closed by 218.26.94.149
Sep 14 05:36:10 localhost sshd[22371]: Connection closed by 218.26.94.149
Sep 14 05:36:10 localhost sshd[22372]: Connection closed by 218.26.94.149
Sep 14 05:36:14 localhost sshd[22376]: Connection closed by 218.26.94.149
aca dejo un txt con el log security completo.
http://rapidshare.com/files/145260129/logs.txt.html
existe alguna forma de poner que despues de no se... 4 o 5 intentos de acceso el ip quede banneada o restringida por 48hs algo asi?
saludos
