logs: 网站安全问题的确值得重视

文章内容

  2012-03-11 11:00:31
网站安全问题的确值得重视, 下面是今天我机器上的一段log:有人试了几个月了, 用 root/user/admin login, 以前用人用Telnet试, 我关了Telnet 和ping, 现在用ssh 试。 刚才我把 ssh 也关了。

User [ root ] Protocol [ SSH ] attempted ADMIN logon.


719 03/11/2012 08:46:22.090 SEV=4 SSH/12 RPT=422
Closing socket 2 on invalid connection 0x2CD0001.

720 03/11/2012 08:46:22.380 SEV=4 SSH/14 RPT=41 121.14.212.107
Connection not accepted, too many existing connections.

721 03/11/2012 08:46:23.780 SEV=5 AUTH/31 RPT=165
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

723 03/11/2012 08:46:23.780 SEV=3 SSH/33 RPT=3 121.14.212.107
Login Failure for 'admin' (try 1)

724 03/11/2012 08:46:23.800 SEV=5 AUTH/31 RPT=166
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

726 03/11/2012 08:46:23.800 SEV=3 SSH/33 RPT=4 121.14.212.107
Login Failure for 'admin' (try 1)

727 03/11/2012 08:46:23.820 SEV=5 AUTH/31 RPT=167
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

729 03/11/2012 08:46:23.820 SEV=3 SSH/33 RPT=5 121.14.212.107
Login Failure for 'admin' (try 1)

730 03/11/2012 08:46:23.990 SEV=5 AUTH/31 RPT=168
User [ user ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

732 03/11/2012 08:46:23.990 SEV=3 SSH/33 RPT=6 121.14.212.107
Login Failure for 'user' (try 1)

733 03/11/2012 08:46:24.010 SEV=5 AUTH/31 RPT=169
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

735 03/11/2012 08:46:24.010 SEV=3 SSH/33 RPT=7 121.14.212.107
Login Failure for 'admin' (try 2)

736 03/11/2012 08:46:24.040 SEV=5 AUTH/31 RPT=170
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

738 03/11/2012 08:46:24.040 SEV=3 SSH/33 RPT=8 121.14.212.107
Login Failure for 'admin' (try 2)

739 03/11/2012 08:46:24.060 SEV=5 AUTH/31 RPT=171
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

741 03/11/2012 08:46:24.060 SEV=3 SSH/33 RPT=9 121.14.212.107
Login Failure for 'admin' (try 2)

742 03/11/2012 08:46:24.220 SEV=5 AUTH/31 RPT=172
User [ user ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

744 03/11/2012 08:46:24.220 SEV=3 SSH/33 RPT=10 121.14.212.107
Login Failure for 'user' (try 2)

745 03/11/2012 08:46:24.240 SEV=5 AUTH/31 RPT=173
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

747 03/11/2012 08:46:24.240 SEV=3 SSH/33 RPT=11 121.14.212.107
Login Failure for 'admin' (try 3)

748 03/11/2012 08:46:24.270 SEV=5 AUTH/31 RPT=174
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

750 03/11/2012 08:46:24.270 SEV=3 SSH/33 RPT=12 121.14.212.107
Login Failure for 'admin' (try 3)

751 03/11/2012 08:46:24.290 SEV=5 AUTH/31 RPT=175
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

753 03/11/2012 08:46:24.290 SEV=3 SSH/33 RPT=13 121.14.212.107
Login Failure for 'admin' (try 3)

754 03/11/2012 08:46:24.450 SEV=5 AUTH/31 RPT=176
User [ user ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

756 03/11/2012 08:46:24.450 SEV=3 SSH/33 RPT=14 121.14.212.107
Login Failure for 'user' (try 3)

757 03/11/2012 08:46:24.470 SEV=5 AUTH/31 RPT=177
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

759 03/11/2012 08:46:24.470 SEV=3 SSH/33 RPT=15 121.14.212.107
Login Failure for 'admin' (try 4)

760 03/11/2012 08:46:24.500 SEV=5 AUTH/31 RPT=178
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

762 03/11/2012 08:46:24.500 SEV=3 SSH/33 RPT=16 121.14.212.107
Login Failure for 'admin' (try 4)

763 03/11/2012 08:46:24.520 SEV=5 AUTH/31 RPT=179
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

765 03/11/2012 08:46:24.520 SEV=3 SSH/33 RPT=17 121.14.212.107
Login Failure for 'admin' (try 4)

766 03/11/2012 08:46:24.680 SEV=5 AUTH/31 RPT=180
User [ user ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

768 03/11/2012 08:46:24.680 SEV=3 SSH/33 RPT=18 121.14.212.107
Login Failure for 'user' (try 4)

770 03/11/2012 08:46:24.700 SEV=5 AUTH/31 RPT=181
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

772 03/11/2012 08:46:24.700 SEV=3 SSH/33 RPT=19 121.14.212.107
Login Failure for 'admin' (try 5)

773 03/11/2012 08:46:24.730 SEV=5 AUTH/31 RPT=182
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

775 03/11/2012 08:46:24.730 SEV=3 SSH/33 RPT=20 121.14.212.107
Login Failure for 'admin' (try 5)

776 03/11/2012 08:46:24.750 SEV=5 AUTH/31 RPT=183
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

778 03/11/2012 08:46:24.750 SEV=3 SSH/33 RPT=21 121.14.212.107
Login Failure for 'admin' (try 5)

779 03/11/2012 08:46:24.910 SEV=5 AUTH/31 RPT=184
User [ user ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

781 03/11/2012 08:46:24.910 SEV=3 SSH/33 RPT=22 121.14.212.107
Login Failure for 'user' (try 5)

782 03/11/2012 08:46:24.930 SEV=5 AUTH/31 RPT=185
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

784 03/11/2012 08:46:24.930 SEV=3 SSH/33 RPT=23 121.14.212.107
Login Failure for 'admin' (try 6)

785 03/11/2012 08:46:24.940 SEV=3 SSH/34 RPT=1 121.14.212.107
Too many authentication attempts for 'admin'.

786 03/11/2012 08:46:24.960 SEV=5 AUTH/31 RPT=186
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

788 03/11/2012 08:46:24.960 SEV=3 SSH/33 RPT=24 121.14.212.107
Login Failure for 'admin' (try 6)

789 03/11/2012 08:46:24.960 SEV=3 SSH/34 RPT=2 121.14.212.107
Too many authentication attempts for 'admin'.

790 03/11/2012 08:46:24.980 SEV=5 AUTH/31 RPT=187
User [ admin ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

792 03/11/2012 08:46:24.980 SEV=3 SSH/33 RPT=25 121.14.212.107
Login Failure for 'admin' (try 6)

793 03/11/2012 08:46:24.990 SEV=3 SSH/34 RPT=3 121.14.212.107
Too many authentication attempts for 'admin'.

794 03/11/2012 08:46:25.140 SEV=5 AUTH/31 RPT=188
User [ user ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

796 03/11/2012 08:46:25.140 SEV=3 SSH/33 RPT=26 121.14.212.107
Login Failure for 'user' (try 6)

797 03/11/2012 08:46:25.150 SEV=3 SSH/34 RPT=4 121.14.212.107
Too many authentication attempts for 'user'.

798 03/11/2012 08:46:25.370 SEV=4 SSH/39 RPT=1 121.14.212.107
More than one disconnect.

799 03/11/2012 08:46:25.370 SEV=5 SSH/56 RPT=718 121.14.212.107
Session ended: 'admin'

800 03/11/2012 08:46:25.390 SEV=4 SSH/39 RPT=2 121.14.212.107
More than one disconnect.

801 03/11/2012 08:46:25.390 SEV=5 SSH/56 RPT=719 121.14.212.107
Session ended: 'admin'

802 03/11/2012 08:46:25.410 SEV=4 SSH/39 RPT=3 121.14.212.107
More than one disconnect.

803 03/11/2012 08:46:25.410 SEV=5 SSH/56 RPT=720 121.14.212.107
Session ended: 'admin'

804 03/11/2012 08:46:25.570 SEV=4 SSH/39 RPT=4 121.14.212.107
More than one disconnect.

805 03/11/2012 08:46:25.570 SEV=5 SSH/56 RPT=721 121.14.212.107
Session ended: 'user'

806 03/11/2012 08:47:23.940 SEV=5 AUTH/31 RPT=189
User [ user ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

808 03/11/2012 08:47:23.940 SEV=3 SSH/33 RPT=27 121.14.212.107
Login Failure for 'user' (try 1)

809 03/11/2012 08:47:24.170 SEV=5 AUTH/31 RPT=190
User [ user ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

811 03/11/2012 08:47:24.170 SEV=3 SSH/33 RPT=28 121.14.212.107
Login Failure for 'user' (try 2)

812 03/11/2012 08:47:24.400 SEV=5 AUTH/31 RPT=191
User [ user ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

814 03/11/2012 08:47:24.400 SEV=3 SSH/33 RPT=29 121.14.212.107
Login Failure for 'user' (try 3)

815 03/11/2012 08:47:24.630 SEV=5 AUTH/31 RPT=192
User [ user ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

817 03/11/2012 08:47:24.630 SEV=3 SSH/33 RPT=30 121.14.212.107
Login Failure for 'user' (try 4)

818 03/11/2012 08:47:24.860 SEV=5 AUTH/31 RPT=193
User [ user ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

820 03/11/2012 08:47:24.860 SEV=3 SSH/33 RPT=31 121.14.212.107
Login Failure for 'user' (try 5)

821 03/11/2012 08:47:25.090 SEV=5 AUTH/31 RPT=194
User [ user ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

823 03/11/2012 08:47:25.090 SEV=3 SSH/33 RPT=32 121.14.212.107
Login Failure for 'user' (try 6)

824 03/11/2012 08:47:25.100 SEV=3 SSH/34 RPT=5 121.14.212.107
Too many authentication attempts for 'user'.

825 03/11/2012 08:47:25.400 SEV=5 SSH/56 RPT=722 121.14.212.107
Session ended: 'user'

826 03/11/2012 08:47:26.910 SEV=5 AUTH/31 RPT=195
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

828 03/11/2012 08:47:26.910 SEV=3 SSH/33 RPT=33 121.14.212.107
Login Failure for 'root' (try 1)

829 03/11/2012 08:47:26.920 SEV=5 AUTH/31 RPT=196
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

831 03/11/2012 08:47:26.920 SEV=3 SSH/33 RPT=34 121.14.212.107
Login Failure for 'root' (try 1)

832 03/11/2012 08:47:27.120 SEV=5 AUTH/31 RPT=197
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

834 03/11/2012 08:47:27.120 SEV=3 SSH/33 RPT=35 121.14.212.107
Login Failure for 'root' (try 1)

835 03/11/2012 08:47:27.140 SEV=5 AUTH/31 RPT=198
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

837 03/11/2012 08:47:27.140 SEV=3 SSH/33 RPT=36 121.14.212.107
Login Failure for 'root' (try 2)

838 03/11/2012 08:47:27.160 SEV=5 AUTH/31 RPT=199
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

840 03/11/2012 08:47:27.160 SEV=3 SSH/33 RPT=37 121.14.212.107
Login Failure for 'root' (try 2)

841 03/11/2012 08:47:27.350 SEV=5 AUTH/31 RPT=200
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

843 03/11/2012 08:47:27.350 SEV=3 SSH/33 RPT=38 121.14.212.107
Login Failure for 'root' (try 2)

844 03/11/2012 08:47:27.370 SEV=5 AUTH/31 RPT=201
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

846 03/11/2012 08:47:27.370 SEV=3 SSH/33 RPT=39 121.14.212.107
Login Failure for 'root' (try 3)

847 03/11/2012 08:47:27.390 SEV=5 AUTH/31 RPT=202
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

849 03/11/2012 08:47:27.390 SEV=3 SSH/33 RPT=40 121.14.212.107
Login Failure for 'root' (try 3)

850 03/11/2012 08:47:27.580 SEV=5 AUTH/31 RPT=203
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

852 03/11/2012 08:47:27.580 SEV=3 SSH/33 RPT=41 121.14.212.107
Login Failure for 'root' (try 3)

853 03/11/2012 08:47:27.600 SEV=5 AUTH/31 RPT=204
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

855 03/11/2012 08:47:27.600 SEV=3 SSH/33 RPT=42 121.14.212.107
Login Failure for 'root' (try 4)

856 03/11/2012 08:47:27.620 SEV=5 AUTH/31 RPT=205
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

858 03/11/2012 08:47:27.620 SEV=3 SSH/33 RPT=43 121.14.212.107
Login Failure for 'root' (try 4)

859 03/11/2012 08:47:27.810 SEV=5 AUTH/31 RPT=206
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

861 03/11/2012 08:47:27.810 SEV=3 SSH/33 RPT=44 121.14.212.107
Login Failure for 'root' (try 4)

862 03/11/2012 08:47:27.830 SEV=5 AUTH/31 RPT=207
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

864 03/11/2012 08:47:27.830 SEV=3 SSH/33 RPT=45 121.14.212.107
Login Failure for 'root' (try 5)

865 03/11/2012 08:47:27.850 SEV=5 AUTH/31 RPT=208
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

867 03/11/2012 08:47:27.850 SEV=3 SSH/33 RPT=46 121.14.212.107
Login Failure for 'root' (try 5)

868 03/11/2012 08:47:28.040 SEV=5 AUTH/31 RPT=209
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

870 03/11/2012 08:47:28.040 SEV=3 SSH/33 RPT=47 121.14.212.107
Login Failure for 'root' (try 5)

871 03/11/2012 08:47:28.060 SEV=5 AUTH/31 RPT=210
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

873 03/11/2012 08:47:28.060 SEV=3 SSH/33 RPT=48 121.14.212.107
Login Failure for 'root' (try 6)

874 03/11/2012 08:47:28.060 SEV=3 SSH/34 RPT=6 121.14.212.107
Too many authentication attempts for 'root'.

875 03/11/2012 08:47:28.080 SEV=5 AUTH/31 RPT=211
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

877 03/11/2012 08:47:28.080 SEV=3 SSH/33 RPT=49 121.14.212.107
Login Failure for 'root' (try 6)

878 03/11/2012 08:47:28.090 SEV=3 SSH/34 RPT=7 121.14.212.107
Too many authentication attempts for 'root'.

879 03/11/2012 08:47:28.270 SEV=5 AUTH/31 RPT=212
User [ root ] Protocol [ SSH ] attempted ADMIN logon.
Status: <REFUSED> authentication failure

881 03/11/2012 08:47:28.270 SEV=3 SSH/33 RPT=50 121.14.212.107
Login Failure for 'root' (try 6)

882 03/11/2012 08:47:28.280 SEV=3 SSH/34 RPT=8 121.14.212.107
Too many authentication attempts for 'root'.

883 03/11/2012 08:47:28.500 SEV=4 SSH/39 RPT=5 121.14.212.107
More than one disconnect.

884 03/11/2012 08:47:28.500 SEV=5 SSH/56 RPT=723 121.14.212.107
Session ended: 'root'

885 03/11/2012 08:47:28.510 SEV=4 SSH/39 RPT=6 121.14.212.107
More than one disconnect.
点击: 0 | 评论: 4 | 分类: 缺省 | 论坛: 网站建设 | 论坛帖子
QR Code
请用微信 扫一扫 扫描上面的二维码,然后点击页面右上角的 ... 图标,然后点击 发送给朋友分享到朋友圈,谢谢!
分享:
分享到微信

文章评论

  1. Caribou 说道: Untitled

    2012-03-11 11:07:39

    这 121.14.212.107 是个从中国来的IP:

    www.whoismind.com/ip/1...2.107.html




    121.14.212.107
    Host: no hostname.
    Country: cnChina


    Inetnum : 121.14.212.0 - 121.14.212.255
    Netname : TIANYING-COMPANY
    Descr : Shantou Tianyin Technology Co.,Ltd
    Country : CN
    Admin-c : ST-AP
    Tech-c : IC83-AP
    Mnt-by : MAINT-CHINANET-GD
    Changed : email 20080619
    Status : Allocated non-portable

    Route : 121.8.0.0/13
    Descr : From Guangdong Network of ChinaTelecom
    Origin : AS4134
    Mnt-by : MAINT-CHINANET
    Changed : email 20060707

    Person : SHANTOU WANJIAN
    Address : Telecom Building, Shan Zhang Road, Shantou, China
    Country : CN
    Phone : +86-754-8250440
    E-mail : email
    Nic-hdl : ST-AP
    Mnt-by : MAINT-CHINANET-GD
    Changed : email 20080328

    Person : IPMASTER CHINANET-GD
    Nic-hdl : IC83-AP
    E-mail : email
    Address : NO.1,RO.DONGYUANHENG,YUEXIUNAN,GUANGZHOU
    Phone : +86-20-83877223
    Fax-no : +86-20-83877223
    Country : CN
    Changed : email 20110418
    Mnt-by : MAINT-CHINANET-GD
    Abuse-mailbox : email
  2. grinder 说道: Untitled

    2012-03-11 11:51:03

    中国黑客,名不虚传
  3. Matrix 说道: Untitled

    2012-03-11 11:53:48

    入门级黑客的作品,big_shy.gif
  4. 3M 说道: Untitled

    2012-03-11 20:54:18

    这不奇怪。你要看到加西服务器的log就知道服务器的很多资源都被消耗在应付黑客上了

发表评论