怎么每天都有一些人来试着暴力破解ROOT密码..

2013-11-26 10:01:09 +08:00
 gouera
Nov 26 07:26:50 localhost sshd[7692]: User root from 219.243.208.158 not allowed because not listed in AllowUsers
Nov 26 07:26:50 localhost sshd[7693]: input_userauth_request: invalid user root
Nov 26 07:26:51 localhost sshd[7693]: Received disconnect from 219.243.208.158: 11: Bye Bye
Nov 26 07:26:52 localhost sshd[7694]: User root from 219.243.208.158 not allowed because not listed in AllowUsers
Nov 26 07:26:52 localhost sshd[7695]: input_userauth_request: invalid user root
Nov 26 07:26:52 localhost sshd[7695]: Received disconnect from 219.243.208.158: 11: Bye Bye
Nov 26 07:26:52 localhost sshd[7696]: User root from 219.243.208.158 not allowed because not listed in AllowUsers
Nov 26 07:26:52 localhost sshd[7697]: input_userauth_request: invalid user root
Nov 26 07:26:52 localhost sshd[7697]: Received disconnect from 219.243.208.158: 11: Bye Bye
Nov 26 07:26:53 localhost sshd[7698]: User root from 219.243.208.158 not allowed because not listed in AllowUsers

这些人是闲着蛋疼吗? 我的2台服务器都会这样。
5257 次点击
所在节点    服务器
12 条回复
DearMark
2013-11-26 10:11:39 +08:00
对,蛋疼
subpo
2013-11-26 10:14:12 +08:00
正常,脚本小子多的是
gouera
2013-11-26 10:30:24 +08:00
@subpo 这个是怎么回事啊。 写个脚本在广域网扫端口,然后暴力破解?
ultragtx
2013-11-26 10:45:25 +08:00
把root的远程登陆关了啊 ssh端口改了啊
qdvictory
2013-11-26 10:50:53 +08:00
ssh关root- -
yylzcom
2013-11-26 10:57:00 +08:00
脚本泛滥的后果啊
subpo
2013-11-26 11:13:54 +08:00
@gouera vps商的ip段基本上算是公开的吧,直接弱密码扫ip段就行了,我小时候就干过这样的事情- -一个软件,一天能扫出一堆,不过不明觉厉,不知道用来干嘛。
现在想想,啧。
GordianZ
2013-11-26 11:38:11 +08:00
Fail2ban is your friend.
hadoop
2013-11-26 11:48:45 +08:00
denyhost也不错啊,简单方便

其实直接禁止密码登陆更彻底
princeofwales
2013-11-26 12:07:49 +08:00
我把ssh的端口改成443了,然后禁止密码登录
gouera
2013-11-26 12:58:31 +08:00
@hadoop
@princeofwales
我知道啊,早就禁止root用户和密码登录了, 现在都是用密钥对登录的。 只是好奇他们的目的,难道真的是扫来做肉鸡吗
hadoop
2013-11-26 13:23:43 +08:00
@gouera 他们有机器自动扫ip,成本非常低,几万台能搞到一台就赚了啊

这是一个专为移动设备优化的页面(即为了让你能够在 Google 搜索结果里秒开这个页面),如果你希望参与 V2EX 社区的讨论,你可以继续到 V2EX 上打开本讨论主题的完整版本。

https://www.v2ex.com/t/90634

V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。

V2EX is a community of developers, designers and creative people.

© 2021 V2EX