自宅鯖のログに、こんなのが。 $ grep "Invalid user" $LOG |cat -n |tail -n1 43 Oct DD HH:MM:SS SERVER sshd[NUM]: Invalid user test from 211.192.229.4 そっちを適当につついて見たが、サーバソフトが軒並2年前のバージョンで、 当然脆弱性てんこ漏り... 要するに、此奴、踏台になってる模様。
Oct 22 15:02:11 SERVER postfix/smtpd[1227]: connect from unknown [221.140.55.88] Oct 22 15:02:12 SERVER postfix/smtpd[1227]: NOQUEUE: reject: RCPT from unknown[221.140.55.88]: 554 <moneyhunter99@daum.net>: Relay access denied; from=<ddhe2oo9uuhh44tyqg2@yahoo.com.au> to=<moneyhunter99@daum.net> proto=SMTP helo=<none> Oct 22 15:02:12 SERVER postfix/smtpd[1227]: disconnect from unknown [221.140.55.88] スパマー大っ嫌い。
KRNIC is not a ISP but a National Internet Registry similar to APNIC. The address is allocated yet Please contact following ISP for further information [ ISP Organization Information ] Org Name : NIDA Service Name : KRNIC-NET Org Address : Seocho 2-dong Seocho-gu SEOUL Org Detail Address: 1321-11 11th KTF B/D [ ISP IP Admin Contact Information ] Name : IP Adm Phone : +82-2-2186-4500 E-Mail : noc@nida.or.kr [ ISP IP Tech Contact Information ] Name : IP Tech Phone : +82-2-2186-4500 E-mail : noc@nida.or.kr [ ISP Network Abuse Contact Information ] Name : Abuse Manager Phone : +82-2-2186-4500 E-mail : noc@nida.or.kr - NIDA/KRNIC Whois Service - こいつ(202.30.50.120)がこの2時間で100回ぐらい仕掛けてきてる。 まじでチョン。
59 :
機能サーバーで足の小指打った。
60 :
↓こんなのが1回 GET /w00tw00t.at.ISC.SANS.DFind:) ↓こんなのが週数回 SEARCH /\x90\xc9\(略)\x90\ POST /_vti_bin/_vti_aut/fp30reg.dll
サーバーにハッキングしようとする悪質な輩を晒し上げ Failed logins from: 58.229.117.54: 3201 times 122.209.225.187: 26 times 125.54.44.56 (KD125054044056.ppp-bb.dion.ne.jp): 1 time
Illegal users from: 58.229.117.54: 2864 times 122.209.225.187: 1 time Failed logins from: 128.134.180.202: 38 times 202.108.201.158: 22 times 213.194.149.28 (ns4.hostinglmi.net): 30 times 218.12.196.5: 5 times 222.73.225.84: 124 times
Illegal users from: 128.134.180.202: 174 times 202.108.201.158: 31 times 213.194.149.28 (ns4.hostinglmi.net): 1043 times 218.12.196.5: 4 times 222.73.225.84: 144 times
サーバーにハッキングしようとする悪質な輩を晒し上げ 毎日こんな調子だわ orz Failed logins from: 74.52.28.122 (7a.1c.344a.static.theplanet.com): 13 times 80.232.45.118: 523 times 81.86.39.135 (81-86-39-135.dsl.pipex.com): 2 times 83.16.138.122 (afi122.internetdsl.tpnet.pl): 6 times 207.58.135.82 (pi.com): 114 times
Illegal users from: 74.52.28.122 (7a.1c.344a.static.theplanet.com): 2 times 80.232.45.118: 1608 times 81.86.39.135 (81-86-39-135.dsl.pipex.com): 1 time 83.16.138.122 (afi122.internetdsl.tpnet.pl): 788 times 207.58.135.82 (pi.com): 2030 times