Aug 26 22:17:01 Quarzo CRON[3034]: (pam_unix) session
closed for user root
Aug 26 22:20:15 Quarzo sshd[3046]: Did not receive identification string
from 217.72.251.207
Aug 26 22:25:02 Quarzo sshd[3047]: Invalid user t1na from 217.72.251.207
Aug 26 22:25:04 Quarzo sshd[3049]: Invalid user t1na from 217.72.251.207
Aug 26 22:25:07 Quarzo sshd[3051]: Invalid user logic from 217.72.251.207
Aug 26 22:25:09 Quarzo sshd[3053]: Invalid user diablo from 217.72.251.207
Aug 26 22:25:11 Quarzo sshd[3055]: Invalid user b1ablo from 217.72.251.207
Aug 26 22:25:13 Quarzo sshd[3057]: Invalid user paradise from
217.72.251.207
Aug 26 22:25:16 Quarzo sshd[3059]: Invalid user paradisse from
217.72.251.207
Aug 28 01:05:42 Quarzo sshd[23729]: Invalid user postmaster from
208.113.188.28
Aug 28 01:05:44 Quarzo sshd[23731]: Invalid user testuser from
208.113.188.28
Aug 28 01:05:46 Quarzo sshd[23733]: Invalid user tester from 208.113.188.28
Aug 28 01:05:53 Quarzo sshd[23741]: Invalid user knoppix from 208.113.188.28
Aug 28 01:05:57 Quarzo sshd[23745]: Invalid user design from 208.113.188.28
Aug 28 01:06:00 Quarzo sshd[23749]: Invalid user public from 208.113.188.28
Este es el inicio y el final del archivo del log, despues ponia esto:
Aug 28 05:17:01 Quarzo CRON[23967]: (pam_unix) session closed for user root
Aug 28 05:39:01 Quarzo CRON[23980]: (pam_unix) session opened for user root
by (uid=0)
Aug 28 05:39:01 Quarzo CRON[23980]: (pam_unix) session closed for user root
Aug 28 06:09:01 Quarzo CRON[24001]: (pam_unix) session opened for user root
by (uid=0)
Aug 28 06:09:01 Quarzo CRON[24001]: (pam_unix) session closed for user root
Aug 28 06:17:01 Quarzo CRON[24009]: (pam_unix) session opened for user root
by (uid=0)
Aug 28 06:17:01 Quarzo CRON[24009]: (pam_unix) session closed for user root
Aug 28 06:25:01 Quarzo CRON[24022]: (pam_unix) session opened for user root
by (uid=0)
En fin, Que opinais?
Pues que han intentado entrar por ataque de usuario / passwd con un
diccionario y que no han conseguido nada. Recibimos ataques de esos
todos los días de lamers que con una pequeña herramienta en Windows
quieren graduarse de forma rápida.
Por lo de la sesión abierta del root es normal que lo abra el proceso
cron para ejecutar sus tareas periódicas...
--
Rafa Couto -
http://caligari.treboada.net
GNU/Linux user #99126 -
http://counter.li.org