Toffel
Registered User
heY!
ich habe mir heute mal durch Zufall die login Datein angeschaut und musste feststellen das da irgendwas nicht stimmt:
Das sieht so aus als wenn da jemand probiert rein zukommen oder?
Was kann ich da jetzt am besten machen?
thx und viel fun!
Edit:
Damit kann ich auch nichts anfange:
ich habe mir heute mal durch Zufall die login Datein angeschaut und musste feststellen das da irgendwas nicht stimmt:
Jan 6 06:35:32 h622498 sshd[20523]: Received disconnect from ::ffff:62.33.195.102: 11: Bye Bye
Jan 6 06:35:34 h622498 sshd[20524]: Illegal user webmaster from ::ffff:62.33.195.102
Jan 6 06:35:34 h622498 sshd[20524]: input_userauth_request: illegal user webmaster
Jan 6 06:35:34 h622498 sshd[20524]: Failed password for illegal user webmaster from ::ffff:62.33.195.102 port 36268 ssh2
Jan 6 06:35:34 h622498 kernel: SuSE-FW-ACCEPT IN=eth0 OUT= MAC=00:04:61:73:92:2b:00:11:5d:f2:80:00:08:00 SRC=62.33.195.102 DST=81.169.130.199 LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=9200 DF PROTO=TCP SPT=36427 DPT=22 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40402080A2D90A58E0000000001030302)
Jan 6 06:35:34 h622498 sshd[20524]: Received disconnect from ::ffff:62.33.195.102: 11: Bye Bye
Jan 6 06:35:35 h622498 sshd[20525]: Failed password for root from ::ffff:62.33.195.102 port 36427 ssh2
Jan 6 06:35:35 h622498 sshd[20525]: Received disconnect from ::ffff:62.33.195.102: 11: Bye Bye
Jan 6 06:35:35 h622498 kernel: SuSE-FW-ACCEPT IN=eth0 OUT= MAC=00:04:61:73:92:2b:00:11:5d:f2:80:00:08:00 SRC=62.33.195.102 DST=81.169.130.199 LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=3781 DF PROTO=TCP SPT=36568 DPT=22 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40402080A2D90AADC0000000001030302)
Jan 6 06:35:36 h622498 sshd[20526]: Illegal user admin from ::ffff:62.33.195.102
Jan 6 06:35:36 h622498 sshd[20526]: input_userauth_request: illegal user admin
Jan 6 06:35:36 h622498 sshd[20526]: Failed password for illegal user admin from ::ffff:62.33.195.102 port 36568 ssh2
Jan 6 06:35:36 h622498 sshd[20526]: Received disconnect from ::ffff:62.33.195.102: 11: Bye Bye
Jan 6 06:35:36 h622498 kernel: SuSE-FW-ACCEPT IN=eth0 OUT= MAC=00:04:61:73:92:2b:00:11:5d:f2:80:00:08:00 SRC=62.33.195.102 DST=81.169.130.199 LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=60860 DF PROTO=TCP SPT=36718 DPT=22 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40402080A2D90B00F0000000001030302)
Jan 6 06:35:38 h622498 sshd[20527]: Illegal user administrator from ::ffff:62.33.195.102
Jan 6 06:35:38 h622498 sshd[20527]: input_userauth_request: illegal user administrator
Jan 6 06:35:38 h622498 sshd[20527]: Failed password for illegal user administrator from ::ffff:62.33.195.102 port 36718 ssh2
Jan 6 06:35:38 h622498 kernel: SuSE-FW-ACCEPT IN=eth0 OUT= MAC=00:04:61:73:92:2b:00:11:5d:f2:80:00:08:00 SRC=62.33.195.102 DST=81.169.130.199 LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=4458 DF PROTO=TCP SPT=36878 DPT=22 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405B40402080A2D90B5720000000001030302)
Das sieht so aus als wenn da jemand probiert rein zukommen oder?
Was kann ich da jetzt am besten machen?
thx und viel fun!
Edit:
Damit kann ich auch nichts anfange:
Jan 6 11:17:56 h622498 kernel: SuSE-FW-ACCEPT IN=eth0 OUT= MAC=00:04:61:73:92:2b:00:11:5d:f2:80:00:08:00 SRC=84.179.24.51 DST=81.169.130.199 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=47569 DF PROTO=TCP SPT=35907 DPT=80 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405AC0402080AE7F40DBE0000000001030302)
Jan 6 11:18:00 h622498 /USR/SBIN/CRON[29714]: (root) CMD (killall -HUP authdaemond.plain > /dev/null)
Jan 6 11:18:00 h622498 /USR/SBIN/CRON[29715]: (root) CMD (/usr/local/visas/server/visas-event.sh)
Jan 6 11:18:00 h622498 authdaemond.plain: authdaemon: modules="authcustom authcram authuserdb authvchkpw authshadow authpwd", daemons=5
Jan 6 11:18:01 h622498 kernel: SuSE-FW-ACCEPT IN=eth0 OUT= MAC=00:04:61:73:92:2b:00:11:5d:f2:80:00:08:00 SRC=80.133.182.158 DST=81.169.130.199 LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=16460 DF PROTO=TCP SPT=61766 DPT=80 WINDOW=64240 RES=0x00 SYN URGP=0 OPT (020405AC01010402)
Jan 6 11:18:13 h622498 kernel: SuSE-FW-ACCEPT IN=eth0 OUT= MAC=00:04:61:73:92:2b:00:11:5d:f2:80:00:08:00 SRC=84.179.24.51 DST=81.169.130.199 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=61877 DF PROTO=TCP SPT=35985 DPT=80 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405AC0402080AE7F44EAC0000000001030302)
Jan 6 11:18:23 h622498 kernel: SuSE-FW-ACCEPT IN=eth0 OUT= MAC=00:04:61:73:92:2b:00:11:5d:f2:80:00:08:00 SRC=84.179.24.51 DST=81.169.130.199 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=9120 DF PROTO=TCP SPT=36056 DPT=80 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405AC0402080AE7F478620000000001030302)
Jan 6 11:18:24 h622498 kernel: SuSE-FW-ACCEPT IN=eth0 OUT= MAC=00:04:61:73:92:2b:00:11:5d:f2:80:00:08:00 SRC=84.179.184.85 DST=81.169.130.199 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=36754 DF PROTO=TCP SPT=5785 DPT=80 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405AC0402080AE7F47B300000000001030302)
Jan 6 11:18:27 h622498 kernel: SuSE-FW-ACCEPT IN=eth0 OUT= MAC=00:04:61:73:92:2b:00:11:5d:f2:80:00:08:00 SRC=84.179.24.51 DST=81.169.130.199 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=23586 DF PROTO=TCP SPT=36063 DPT=80 WINDOW=5840 RES=0x00 SYN URGP=0 OPT (020405AC0402080AE7F486E80000000001030302)
Jan 6 11:18:29 h622498 kernel: SuSE-FW-ACCEPT IN=eth0 OUT= MAC=00:04:61:73:92:2b:00:11:5d:f2:80:00:08:00 SRC=84.177.198.49 DST=81.169.130.199 LEN=52 TOS=0x00 PREC=0x00 TTL=119 ID=1758 DF PROTO=TCP SPT=1144 DPT=80 WINDOW=32767 RES=0x00 SYN URGP=0 OPT (020405AC0103030001010402)
Jan 6 11:18:37 h622498 kernel: SuSE-FW-ACCEPT IN=eth0 OUT= MAC=00:04:61:73:92:2b:00:11:5d:f2:80:00:08:00 SRC=84.177.198.49 DST=81.169.130.199 LEN=52 TOS=0x00 PREC=0x00 TTL=119 ID=1850 DF PROTO=TCP SPT=1148 DPT=80 WINDOW=32767 RES=0x00 SYN URGP=0 OPT (020405AC0103030001010402)
Jan 6 11:19:00 h622498 /USR/SBIN/CRON[29743]: (root) CMD (killall -HUP authdaemond.plain > /dev/null)
Jan 6 11:19:00 h622498 authdaemond.plain: authdaemon: modules="authcustom authcram authuserdb authvchkpw authshadow authpwd", daemons=5
Last edited by a moderator: