6步教你封杀恶意登录服务器的ip(1)
创始人
2025-01-20 09:35:13
0

《一线大厂Java面试题解析+核心总结学习笔记+最新讲解视频+实战项目源码》点击传送门,即可获取!
Jun 5 12:51:19 localhost sshd[10394]: pam_unix(sshd:session): session opened for user root by (uid=

Jun 5 13:03:00 localhost sshd[10428]: pam_unix(sshd:auth): authentication failure; logname= uid=0 e

uid=0 tty=ssh ruser= rhost=192.168.10.1 user=root

Jun 5 13:03:00 localhost sshd[10428]: pam_succeed_if(sshd:auth): requirement “uid >= 1000” not met

by user “root”

Jun 5 13:03:02 localhost sshd[10428]: Failed password for root from 192.168.10.1 port 64400 ssh2

Jun 5 13:03:06 localhost sshd[10428]: pam_succeed_if(sshd:auth): requirement “uid >= 1000” not met

by user “root”

Jun 5 13:03:08 localhost sshd[10428]: Failed password for root from 192.168.10.1 port 64400 ssh2

Jun 5 13:03:14 localhost sshd[10428]: pam_succeed_if(sshd:auth): requirement “uid >= 1000” not met

–More–

  • 过滤其它ip,只看登录失败的ip地址

[root@localhost ~]# grep “Failed password” /var/log/secure

Jun 5 13:03:02 localhost sshd[10428]: Failed password for root from 192.168.10.1 port 64400 ssh2

Jun 5 13:03:08 localhost sshd[10428]: Failed password for root from 192.168.10.1 port 64400 ssh2

Jun 5 13:03:16 localhost sshd[10428]: Failed password for root from 192.168.10.1 port 64400 ssh2

Jun 5 13:03:27 localhost sshd[10431]: Failed password for root from 192.168.10.1 port 64438 ssh2

Jun 5 13:15:33 localhost sshd[10442]: Failed password for root from 192.168.10.10 port 49796 ssh2

Jun 5 13:15:38 localhost sshd[10442]: Failed password for root from 192.168.10.10 port 49796 ssh2

Jun 5 13:15:38 localhost sshd[10442]: Failed password for root from 192.168.10.10 port 49796 ssh2

Jun 5 13:15:46 localhost sshd[10444]: Failed password for root from 192.168.10.10 port 49798 ssh2

Jun 5 13:15:50 localhost sshd[10444]: Failed password for root from 192.168.10.10 port 49798 ssh2

Jun 5 13:15:53 localhost sshd[10444]: Failed password for root from 192.168.10.10 port 49798 ssh2

Jun 5 13:15:59 localhost sshd[10446]: Failed password for root from 192.168.10.10 port 49800 ssh2

Jun 5 13:16:00 localhost sshd[10446]: Failed password for root from 192.168.10.10 port 49800 ssh2

Jun 5 13:16:02 localhost sshd[10446]: Failed password for root from 192.168.10.10 port 49800 ssh2

[root@localhost ~]#


  • 打印登录失败的ip

[root@localhost ~]# grep “Failed password” /var/log/secure |awk ‘{print$(NF-3)}’

192.168.10.1

192.168.10.1

192.168.10.1

192.168.10.1

192.168.10.10

192.168.10.10

192.168.10.10

192.168.10.10

192.168.10.10

192.168.10.10

192.168.10.10

192.168.10.10

192.168.10.10

[root@localhost ~]#

  • 进行排序,统计次数

[root@localhost ~]# grep “Failed password” /var/log/secure |awk ‘{print$(NF-3)}’|sort|uniq -c|sort -nr

9 192.168.10.10

4 192.168.10.1

[root@localhost ~]#

  • 匹配恶意登录次数大于5次的ip

[root@localhost ~]# grep “Failed password” /var/log/secure |awk ‘{print$(NF-3)}’|sort|uniq -c|sort -nr|awk ‘{if ($1>=5) print $2}’

192.168.10.10

[root@localhost ~]#

  • 对匹配出来的做一个for循环,然后写入防火墙文件

[root@localhost ~]# for i in $(grep “Failed password” /var/log/secure|awk ‘{print $(NF-3)}’|sort|uniq -c|sort -nr|awk ‘{if($1>=5) print $2}’);do sed -i “/lo/a -A INPUT -s $i -j DROP” /etc/sysconfig/iptables ;done

总结

面试题总结

其它面试题(springboot、mybatis、并发、java中高级面试总结等)

《一线大厂Java面试题解析+核心总结学习笔记+最新讲解视频+实战项目源码》点击传送门,即可获取!
[外链图片转存中…(img-UTziSXNi-1714407491720)]

[外链图片转存中…(img-p7ePVW6n-1714407491720)]

《一线大厂Java面试题解析+核心总结学习笔记+最新讲解视频+实战项目源码》点击传送门,即可获取!

相关内容

热门资讯

八分钟了解!微扑克机器人,情怀... 八分钟了解!微扑克机器人,情怀麻将辅牌器免费,2025版教程(有挂方略)-哔哩哔哩;1、点击下载安装...
黑科技透视(AAPoKER)外... 黑科技透视(AAPoKER)外挂透明挂黑科技辅助神器(透视)wpk教程(2024已更新)(哔哩哔哩)...
第2分钟了解!德州ai辅助应用... 第2分钟了解!德州ai辅助应用场景,兴动互娱手机麻将神器,2025新版教程(的确有挂)-哔哩哔哩1、...
黑科技设备(来玩app德州)外... 黑科技设备(来玩app德州)外挂透明挂黑科技辅助器(透视)技巧教程(2023已更新)(哔哩哔哩)是一...
第七分钟了解!aapoker辅... 第七分钟了解!aapoker辅助,杭州都莱双扣辅助器是真是假,新2025教程(确实有挂)-哔哩哔哩;...
黑科技软件(poker)外挂透... 黑科技软件(poker)外挂透明挂黑科技辅助神器(透视)实用技巧(2026已更新)(哔哩哔哩)是一款...
第一分钟了解!aapoker记... 第一分钟了解!aapoker记牌器,财神十三张牌稳赢方法,教你攻略(真实有挂)-哔哩哔哩;所有人都在...
黑科技软件(德州wpk德州)外... 黑科技软件(德州wpk德州)外挂透明挂黑科技辅助器(透视)技巧教程(2023已更新)(哔哩哔哩);人...
八分钟了解!aapoker辅助... 八分钟了解!aapoker辅助透视,广东雀神挂件去哪买,透明挂教程(了解有挂)-哔哩哔哩暗藏猫腻,小...
黑科技智能(线上wpk德州ai... 黑科技智能(线上wpk德州ai)外挂透明挂黑科技辅助器(透视)2025新版(2022已更新)(哔哩哔...