: 저희 사이트가 해킹을 당한것 같아..문의를 드립니다.
:
: 아침에 출근해 보니.. 사이트가 뜨질 않아.
: 체크를 해보니 httpd.conf가 변형되어 있고..
: 다음 아래와 같이 로그화일에 저희와 관련이 없는 ip들이 접속했더군요..
: 추적을 해보니 캐나다 미국 이쪽인데..
: 현재.. 어떤게 대처를 해야 할지 모르겠습니다.
:
: 현재 시스템을 깨끗이 밀고.. 다시 까는 방법이 있지만.
: 나중에 또 이런일이 발생할게 뻔한데..
: 이렇게 되풀이된다면..
:
: 그리고. 전에 ssh-2.3.0-rpm을 깐적이 있는데..
: 이것에 어떤 조작을 해 놓아서 그런건 아닌지 의심이 갑니다.
:
: 그런 사례나, 해킹에 대한 관련 문의를 할수 있는 사이트를 알고 계시면..
: 부탁드리겠습니다.
:
:
:
: /var/log/secure
: Jan 7 05:45:10 test in.telnetd[2320]: connect from 193.231.60.133
: Jan 7 06:46:32 test in.telnetd[2342]: connect from 193.231.60.133
: Jan 7 06:55:26 test in.telnetd[2348]: connect from 193.231.60.133
: Jan 7 07:00:29 test in.telnetd[2352]: connect from 193.231.60.133
: Jan 7 19:27:04 test in.ftpd[7813]: connect from 24.226.190.13
:
: /var/log/message
: Jan 5 23:00:38 test PAM_pwdb[26794]: (login) session closed for user oracle
: Jan 5 23:00:38 test inetd[476]: pid 26793: exit status 1
: Jan 5 23:00:49 test sshd2[26654]: Local disconnected: Connection closed.
: Jan 5 23:00:49 test sshd2[26654]: connection lost: 'Connection closed.'
: Jan 5 23:00:49 test 1월 5 23:00:49 PAM_pwdb[26694]: (su) session closed for user root
: Jan 6 04:02:00 test anacron[27178]: Updated timestamp for job `cron.daily' to 2001-01-06
: Jan 6 04:04:48 test PAM_pwdb[27291]: (su) session opened for user news by (uid=0)
: Jan 6 04:04:48 test PAM_pwdb[27291]: (su) session closed for user news
: Jan 6 09:29:54 test ftpd[27455]: lost connection to 211.203.134.101 [211.203.134.101]
: Jan 6 09:29:54 test ftpd[27455]: FTP session closed
: Jan 6 09:29:54 test inetd[476]: pid 27455: exit status 255
: Jan 7 19:26:53 test sshd[7811]: log: Generating 768 bit RSA key.
: Jan 7 19:26:54 test sshd[7811]: log: RSA key generation complete.
: Jan 7 19:26:54 test sshd[7811]: log: Connection from 24.226.190.13 port 1022
: Jan 7 19:26:55 test sshd[7811]: fatal: Connection closed by remote host.
: n 7 19:27:14 test ftpd[7813]: FTP session closed
: Jan 7 19:27:23 test sshd2[7629]: connection from "24.226.190.13"
: Jan 7 19:27:23 test sshd[7814]: log: Generating 768 bit RSA key.
: Jan 7 19:27:23 test sshd[7814]: log: RSA key generation complete.
: Jan 7 19:27:23 test sshd[7814]: log: Connection from 24.226.190.13 port 1021
: Jan 7 19:27:28 test sshd[7814]: log: Closing connection to 24.226.190.13
: Jan 7 20:06:30 test sshd2[7629]: connection from "211.39.150.44"
: Jan 7 20:06:30 test sshd2[7866]: DNS lookup failed for "211.39.150.44".
: Jan 7 20:06:30 test sshd[7866]: log: Generating 768 bit RSA key.
: Jan 7 20:06:31 test sshd[7866]: log: RSA key generation complete.
: Jan 7 20:06:31 test sshd[7866]: log: Connection from 211.39.150.44 port 1023
: Jan 7 20:06:34 test sshd[7866]: log: Closing connection to 211.39.150.44
: Jan 8 04:02:00 test anacron[8078]: Updated timestamp for job `cron.daily' to 2001-01-08
: Jan 8 04:02:42 test PAM_pwdb[8192]: (su) session opened for user news by (uid=0)
: Jan 8 04:02:42 test PAM_pwdb[8192]: (su) session closed for user news
: Jan 8 08:02:54 test sshd2[7629]: connection from "211.52.242.146"
: Jan 8 08:02:58 test sshd2[8330]: DNS lookup failed for "211.52.242.146".
: Jan 8 08:02:58 test sshd[8330]: log: Generating 768 bit RSA key.
: Jan 8 08:02:59 test sshd[8330]: log: RSA key generation complete.
: Jan 8 08:02:59 test sshd[8330]: log: Connection from 211.52.242.146 port 1023
: Jan 8 08:03:03 test sshd[8330]: log: Closing connection to 211.52.242.146
:
: --
: 끝까지 읽어주셔서 감사합니다.
다 훓어보지 않고선 명확한 답변을 내리기 힘들겠네여.
대충보니 news란 아이디로 뚫린거 같은데요.
ssh로 접속을 했군요.
리눅스를 새로 까시는게 가장 안전한 방법입니다.
백업하는 습관을 기릅시당 :)--모두 째수조은 하루 되세여.