LinuxSir.cn,穿越时空的Linuxsir!

 找回密码
 注册
搜索
热搜: shell linux mysql
查看: 1254|回复: 13

救命啊,我的电脑好像被入侵了!

[复制链接]
发表于 2008-10-8 00:38:08 | 显示全部楼层 |阅读模式
以前一直没注意过,直到十一假期,忽然感觉不对。上log一看,才发现有麻烦了。之后,就跟着网上一些资料处理了一下。无非就是删除一些帐号,设置一下防火墙之类,但似乎作用不大。今天看log居然有是一对连接信息。我将log部分内容贴出来,请高手帮忙看看。这里谢谢先!
这个是Message里的信息:
Oct  8 00:08:56 localhost pppd[4501]: No response to 3 echo-requests
Oct  8 00:08:56 localhost pppd[4501]: Serial link appears to be disconnected.
Oct  8 00:08:56 localhost pppd[4501]: Connect time 42.7 minutes.
Oct  8 00:08:56 localhost pppd[4501]: Sent 239601 bytes, received 635054 bytes.
Oct  8 00:08:56 localhost ntpd[2045]: sendto(222.73.214.1) (fd=24): Invalid argument
Oct  8 00:08:57 localhost dnsmasq[2158]: reading /etc/resolv.conf
Oct  8 00:08:57 localhost dnsmasq[2158]: using nameserver 218.30.19.40#53
Oct  8 00:08:57 localhost dnsmasq[2158]: using nameserver 61.134.1.4#53
Oct  8 00:09:01 localhost NET[4914]: /etc/sysconfig/network-scripts/ifdown-post : updated /etc/resolv.conf
Oct  8 00:09:02 localhost pppd[4501]: Connection terminated.
Oct  8 00:09:02 localhost pppd[4501]: Modem hangup
Oct  8 00:09:03 localhost pppoe[4502]: read (asyncReadFromPPP): Session 8505: Input/output error
Oct  8 00:09:03 localhost pppoe[4502]: Sent PADT
Oct  8 00:09:03 localhost pppd[4501]: Exit.
Oct  8 00:09:04 localhost pppoe-connect: PPPoE connection lost; attempting re-connection.
Oct  8 00:09:10 localhost pppd[4931]: Warning: can't open options file /root/.ppprc: Permission denied
Oct  8 00:09:10 localhost pppd[4931]: pppd 2.4.4 started by root, uid 0
Oct  8 00:09:10 localhost pppd[4931]: Using interface ppp0
Oct  8 00:09:10 localhost pppd[4931]: Connect: ppp0 <--> /dev/pts/1
Oct  8 00:09:41 localhost pppd[4931]: LCP: timeout sending Config-Requests
Oct  8 00:09:41 localhost pppd[4931]: Connection terminated.
Oct  8 00:09:41 localhost pppd[4931]: Modem hangup
Oct  8 00:09:46 localhost pppoe[4932]: Timeout waiting for PADO packets
Oct  8 00:09:46 localhost pppd[4931]: Exit.
Oct  8 00:09:46 localhost pppoe-connect: PPPoE connection lost; attempting re-connection.
Oct  8 00:09:51 localhost pppd[4952]: Warning: can't open options file /root/.ppprc: Permission denied
Oct  8 00:09:51 localhost pppd[4952]: pppd 2.4.4 started by root, uid 0
Oct  8 00:09:51 localhost pppd[4952]: Using interface ppp0
Oct  8 00:09:51 localhost pppd[4952]: Connect: ppp0 <--> /dev/pts/1
Oct  8 00:09:51 localhost pppoe[4953]: PPP session is 1596 (0x63c)
Oct  8 00:09:54 localhost pppd[4952]: CHAP authentication succeeded: Authentication success,Welcome!
Oct  8 00:09:54 localhost pppd[4952]: CHAP authentication succeeded
Oct  8 00:09:55 localhost pppd[4952]: local  IP address 124.116.113.170
Oct  8 00:09:55 localhost pppd[4952]: remote IP address 124.116.112.1
Oct  8 00:09:55 localhost pppd[4952]: primary   DNS address 61.134.1.4
Oct  8 00:09:55 localhost pppd[4952]: secondary DNS address 218.30.19.40
Oct  8 00:09:55 localhost dnsmasq[2158]: no servers found in /etc/resolv.conf, will retry
Oct  8 00:09:56 localhost NET[4994]: /etc/sysconfig/network-scripts/ifup-post : updated /etc/resolv.conf
Oct  8 00:10:15 localhost ntpd[2045]: sendto(222.73.214.125) (fd=24): Invalid argument
Oct  8 00:10:34 localhost ntpd[2045]: sendto(61.129.66.79) (fd=24): Invalid argument
Oct  8 00:11:05 localhost ntpd[2045]: sendto(222.73.214.1) (fd=24): Invalid argument
Oct  8 00:11:40 localhost ntpd[2045]: Listening on interface #12 ppp0, 124.116.113.170#123 Enabled
Oct  8 00:11:40 localhost ntpd[2045]: Deleting interface #11 ppp0, 124.116.115.166#123, interface stats: received=33, sent=43, dropped=4, active_time=2700 secs
Oct  8 00:12:22 localhost ntpd[2045]: synchronized to 222.73.214.125, stratum 2


这个是secure里的信息:
[color="Red"]Oct  3 03:07:37 localhost su: pam_unix(su:session): session closed for user root
Oct  3 03:47:24 localhost sshd[9419]: Did not receive identification string from 202.99.122.136
Oct  3 04:06:48 localhost su: pam_unix(su:session): session closed for user root
Oct  3 04:07:24 localhost sshd[2050]: Received signal 15; terminating.
Oct  3 11:25:45 localhost sshd[2075]: Server listening on :: port 22.
Oct  3 11:25:45 localhost sshd[2075]: Server listening on 0.0.0.0 port 22.
Oct  3 11:26:38 localhost gdm-session-worker[2514]: pam_unix(gdm:session): session opened for user Jet.Z by (uid=0)
Oct  3 11:31:18 localhost userhelper[3060]: pam_timestamp(yumex:session): updated timestamp file `/var/run/sudo/Jet.Z/unknown:root'
Oct  3 11:31:18 localhost userhelper[3065]: running '/usr/share/yumex/yumex ' with root privileges on behalf of 'Jet.Z'
Oct  3 11:43:37 localhost su: pam_unix(su:session): session opened for user root by Jet.Z(uid=500)
Oct  3 11:43:57 localhost sshd[3382]: Did not receive identification string from 221.238.248.55
Oct  3 11:46:28 localhost sshd[3388]: Invalid user admin from 221.238.248.55
Oct  3 11:46:28 localhost sshd[3389]: input_userauth_request: invalid user admin
Oct  3 11:46:28 localhost sshd[3388]: pam_unix(sshd:auth): check pass; user unknown
Oct  3 11:46:28 localhost sshd[3388]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.238.248.55
Oct  3 11:46:28 localhost sshd[3388]: pam_succeed_if(sshd:auth): error retrieving information about user admin
Oct  3 11:46:30 localhost sshd[3388]: Failed password for invalid user admin from 221.238.248.55 port 15070 ssh2
Oct  3 11:46:30 localhost sshd[3389]: Received disconnect from 221.238.248.55: 11: Bye Bye
发表于 2008-10-8 05:07:32 | 显示全部楼层
这没什么的,是adsl连接和中断的记录
回复 支持 反对

使用道具 举报

发表于 2008-10-8 09:29:53 | 显示全部楼层
同意楼上的.

没看出来什么鸟人侵,真是桤人忧天.
回复 支持 反对

使用道具 举报

发表于 2008-10-8 11:37:43 | 显示全部楼层
我的电脑内的资料常被人删除,已排除本机操作,很可能是通过FTP和SSH进来的了。
回复 支持 反对

使用道具 举报

发表于 2008-10-8 12:55:03 | 显示全部楼层
Post by zhuoli76;1891688
我的电脑内的资料常被人删除,已排除本机操作,很可能是通过FTP和SSH进来的了。


解释一下,为什么要开 sshd 和 ftp 呢?
回复 支持 反对

使用道具 举报

发表于 2008-10-8 13:36:23 | 显示全部楼层
Post by zhuoli76;1891688
我的电脑内的资料常被人删除,已排除本机操作,很可能是通过FTP和SSH进来的了。


玩笑吧...ftp的话 除非你安全设置极为不当, 否则很难越权的,不管是vsftpd还是pureftpd ,安全性都是不错的,起码没什么严重的公开的exploit

至于sshd .... 你的密码被人暴力猜解了?
回复 支持 反对

使用道具 举报

 楼主| 发表于 2008-10-8 19:36:33 | 显示全部楼层
Post by pheyx;1891600
这没什么的,是adsl连接和中断的记录


pheyx兄,adsl会经常这样吗?汗一个!如果真这样,确实有些大惊小怪了!
回复 支持 反对

使用道具 举报

发表于 2008-10-8 19:41:47 | 显示全部楼层
ssh没进来吧。。 invalid user admin
yumex应该是你执行的。
回复 支持 反对

使用道具 举报

 楼主| 发表于 2008-10-8 20:34:42 | 显示全部楼层
Post by usertesting;1891821
ssh没进来吧。。 invalid user admin
yumex应该是你执行的。


usertesting兄,secure中的信息是否在表示他正通过ssh来破解我的root密码?
Oct 3 11:46:30 localhost sshd[3389]: Received disconnect from 221.238.248.55: 11: Bye Bye

这个Bye Bye是什么意思?
回复 支持 反对

使用道具 举报

发表于 2008-10-8 21:24:11 | 显示全部楼层
Post by 流羽;1891833
usertesting兄,secure中的信息是否在表示他正通过ssh来破解我的root密码?

这个Bye Bye是什么意思?


没有吧。。是用admin帐户尝试登录的,而你机器是没有这个用户。
不知道对不对。。。
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

本版积分规则

快速回复 返回顶部 返回列表