今天一位同事用seo优化软件,seo优化软件检测到网页可能挂马,遂检查了一些secure日志,显示以下N多行:
Sep 5 03:57:02 localhost vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Sep 5 03:57:02 localhost vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=bbs rhost=116.30.153.35 Sep 5 03:57:02 localhost vsftpd: pam_succeed_if(vsftpd:auth): error retrieving information about user bbs Sep 5 03:57:06 localhost vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Sep 5 03:57:06 localhost vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=bbs rhost=116.30.153.35 Sep 5 03:57:06 localhost vsftpd: pam_succeed_if(vsftpd:auth):
................
|
应该是外部IP尝试连接ftp端口,破解账号,导致,问了下技术主管,ftp端口没人使用,关闭之。下面有时间研究一下监控secure日志。
阅读(1843) | 评论(0) | 转发(0) |