-

 -



[ ]

 - e-mail

 

 -

   altesack

 -

 LiveInternet.ru:
: 01.09.2008
: 874
: 3530
: 8981

:


((

, 23 2008 . 13:56 +
.
[root@caesar clamav]# last|grep "Dec 20"
clamav pts/0 211.96.28.102 Sat Dec 20 08:11 - 08:11 (00:00)
jabber pts/0 211.96.28.102 Sat Dec 20 08:11 - 08:11 (00:00)
clamav pts/0 88.81.228.100 Sat Dec 20 03:43 - 03:43 (00:00)


( ), . . . .

ssh. . IP . - . 8 -10 . .bash_history - jabber .

clamav
./clamdscan
./clamdscan
/usr/share/mc/extfs/rpm run /mnt/audit_asu/clamav-db-0.93.3-1.rh9.rf.i386.rpm INSTALL
/usr/share/mc/extfs/rpm run /mnt/audit_asu/clamav-0.93.3-1.rh9.rf.i386.rpm INSTALL



- . ( ??)

, , /etc/passwd, - . DES MD5.

- clamav...
clamav:1gLDmP/5C95cQ:580:581::/home/clamav:/bin/bash
jabber:XOTq2JrhWvK6Y:529:529:jabber:/home/jabber:/sbin/nologin

? ?

.

............
Dec 20 08:10:33 caesar sshd[17217]: Failed password for halt from 211.96.28.102 port 13511 ssh2
Dec 20 08:10:40 caesar sshd[17219]: Failed password for uucp from 211.96.28.102 port 13805 ssh2
Dec 20 08:10:44 caesar sshd[17221]: Illegal user smmsp from 211.96.28.102
Dec 20 08:10:47 caesar sshd[17223]: Illegal user dean from 211.96.28.102
Dec 20 08:10:51 caesar sshd[17225]: Illegal user unknown from 211.96.28.102
Dec 20 08:10:55 caesar sshd[17227]: Illegal user securityagent from 211.96.28.102
Dec 20 08:10:59 caesar sshd[17229]: Illegal user tokend from 211.96.28.102
Dec 20 08:11:02 caesar sshd[17231]: Illegal user windowserver from 211.96.28.102
Dec 20 08:11:06 caesar sshd[17233]: Illegal user appowner from 211.96.28.102
Dec 20 08:11:10 caesar sshd[17235]: Illegal user xgridagent from 211.96.28.102
Dec 20 08:11:14 caesar sshd[17237]: Illegal user agent from 211.96.28.102
Dec 20 08:11:17 caesar sshd[17239]: Illegal user xgridcontroller from 211.96.28.102
Dec 20 08:11:22 caesar sshd[17241]: Accepted password for jabber from 211.96.28.102 port 15959 ssh2
Dec 20 08:11:28 caesar sshd[17245]: Illegal user amavisd from 211.96.28.102
Dec 20 08:11:32 caesar sshd[17247]: Accepted password for clamav from 211.96.28.102 port 16420 ssh2
Dec 20 09:45:13 caesar sshd[17820]: Did not receive identification string from 202.99.122.136
Dec 20 11:32:56 caesar sshd[28665]: Failed password for root from 220.250.64.60 port 60612 ssh2
Dec 20 11:33:02 caesar sshd[28667]: Failed password for root from 220.250.64.60 port 60903 ssh2
Dec 20 11:33:08 caesar sshd[29232]: Failed password for root from 220.250.64.60 port 32956 ssh2
Dec 20 11:33:14 caesar sshd[30594]: Failed password for root from 220.250.64.60 port 33252 ssh2
Dec 20 11:33:20 caesar sshd[31281]: Failed password for root from 220.250.64.60 port 33543 ssh2
Dec 20 11:33:25 caesar sshd[31725]: Failed password for root from 220.250.64.60 port 33823 ssh2
Dec 20 11:33:31 caesar sshd[31727]: Failed password for root from 220.250.64.60 port 34122 ssh2
Dec 20 11:33:37 caesar sshd[31730]: Failed password for root from 220.250.64.60 port 34414 ssh2
Dec 20 11:33:43 caesar sshd[31732]: Failed password for root from 220.250.64.60 port 34731 ssh2
Dec 20 11:33:49 caesar sshd[31734]: Failed password for root from 220.250.64.60 port 35007 ssh2
Dec 20 11:33:55 caesar sshd[31736]: Failed password for root from 220.250.64.60 port 35318 ssh2
Dec 20 11:34:00 caesar sshd[31738]: Failed password for root from 220.250.64.60 port 35597 ssh2
Dec 20 11:34:06 caesar sshd[31740]: Failed password for root from 220.250.64.60 port 35915 ssh2
Dec 20 11:34:12 caesar sshd[31742]: Failed password for root from 220.250.64.60 port 36201 ssh2
.....................................................

3 , SSH .


! :
1. !!! ( )
2.
3. , , - /sbin/nologin

. .)))
:  

1

: [1] []
altesack   , 23 2008 . 14:09 ()
.. !!
4. IP-
5. SSH . (, )
   
dandr   , 23 2008 . 14:22 ()
, ))


: Meantraitors - Guts for sale - Winamp [Paused]
   
Inq   , 23 2008 . 14:35 ()
ftp-. :)
   
ungifted   , 23 2008 . 14:58 ()
. .
   
altesack   , 23 2008 . 15:34 ()
- ...
? )))
   
ungifted   , 23 2008 . 16:07 ()
. , .
- cd /.
   
ungifted   , 23 2008 . 16:14 ()
-
for i in `rpm -qa --root /mnt/disk` ; do rpm --root /mnt/disk --verify $i ; done
   
linux   , 23 2008 . 18:54 ()
" UNIX" : SSH . - xD
   
ungifted   , 23 2008 . 19:13 ()

linux

. . .
   
altesack   , 23 2008 . 21:56 ()
.
)
)
-
   
linux   , 23 2008 . 22:03 ()
ungifted, , , , - .
   
ungifted   , 23 2008 . 22:12 ()
altesack, .

. ftp ssh. ?
OpenPGP . Debian ...
   
Inq   , 24 2008 . 00:49 ()
, ?
?
   
ungifted   , 24 2008 . 01:06 ()

Inq

. ( ).
, ssh 4 .
   
Inq   , 24 2008 . 01:09 ()
ungifted, . . .
   
Glo_fish   , 24 2008 . 11:17 ()
:(
   
altesack   , 24 2008 . 11:45 ()
. . .
!
!
   
Glo_fish   , 25 2008 . 23:15 ()
altesack, :)) )))
   
: [1] []
 

:
: 

: ( )

:

  URL