>> Edit article
이름
제목
패스워드
: 저희 사이트가 해킹을 당한것 같아..문의를 드립니다. : : 아침에 출근해 보니.. 사이트가 뜨질 않아. : 체크를 해보니 httpd.conf가 변형되어 있고.. : 다음 아래와 같이 로그화일에 저희와 관련이 없는 ip들이 접속했더군요.. : 추적을 해보니 캐나다 미국 이쪽인데.. : 현재.. 어떤게 대처를 해야 할지 모르겠습니다. : : 현재 시스템을 깨끗이 밀고.. 다시 까는 방법이 있지만. : 나중에 또 이런일이 발생할게 뻔한데.. : 이렇게 되풀이된다면.. : : 그리고. 전에 ssh-2.3.0-rpm을 깐적이 있는데.. : 이것에 어떤 조작을 해 놓아서 그런건 아닌지 의심이 갑니다. : : 그런 사례나, 해킹에 대한 관련 문의를 할수 있는 사이트를 알고 계시면.. : 부탁드리겠습니다. : : : : /var/log/secure : Jan 7 05:45:10 test in.telnetd[2320]: connect from 193.231.60.133 : Jan 7 06:46:32 test in.telnetd[2342]: connect from 193.231.60.133 : Jan 7 06:55:26 test in.telnetd[2348]: connect from 193.231.60.133 : Jan 7 07:00:29 test in.telnetd[2352]: connect from 193.231.60.133 : Jan 7 19:27:04 test in.ftpd[7813]: connect from 24.226.190.13 : : /var/log/message : Jan 5 23:00:38 test PAM_pwdb[26794]: (login) session closed for user oracle : Jan 5 23:00:38 test inetd[476]: pid 26793: exit status 1 : Jan 5 23:00:49 test sshd2[26654]: Local disconnected: Connection closed. : Jan 5 23:00:49 test sshd2[26654]: connection lost: 'Connection closed.' : Jan 5 23:00:49 test 1월 5 23:00:49 PAM_pwdb[26694]: (su) session closed for user root : Jan 6 04:02:00 test anacron[27178]: Updated timestamp for job `cron.daily' to 2001-01-06 : Jan 6 04:04:48 test PAM_pwdb[27291]: (su) session opened for user news by (uid=0) : Jan 6 04:04:48 test PAM_pwdb[27291]: (su) session closed for user news : Jan 6 09:29:54 test ftpd[27455]: lost connection to 211.203.134.101 [211.203.134.101] : Jan 6 09:29:54 test ftpd[27455]: FTP session closed : Jan 6 09:29:54 test inetd[476]: pid 27455: exit status 255 : Jan 7 19:26:53 test sshd[7811]: log: Generating 768 bit RSA key. : Jan 7 19:26:54 test sshd[7811]: log: RSA key generation complete. : Jan 7 19:26:54 test sshd[7811]: log: Connection from 24.226.190.13 port 1022 : Jan 7 19:26:55 test sshd[7811]: fatal: Connection closed by remote host. : n 7 19:27:14 test ftpd[7813]: FTP session closed : Jan 7 19:27:23 test sshd2[7629]: connection from "24.226.190.13" : Jan 7 19:27:23 test sshd[7814]: log: Generating 768 bit RSA key. : Jan 7 19:27:23 test sshd[7814]: log: RSA key generation complete. : Jan 7 19:27:23 test sshd[7814]: log: Connection from 24.226.190.13 port 1021 : Jan 7 19:27:28 test sshd[7814]: log: Closing connection to 24.226.190.13 : Jan 7 20:06:30 test sshd2[7629]: connection from "211.39.150.44" : Jan 7 20:06:30 test sshd2[7866]: DNS lookup failed for "211.39.150.44". : Jan 7 20:06:30 test sshd[7866]: log: Generating 768 bit RSA key. : Jan 7 20:06:31 test sshd[7866]: log: RSA key generation complete. : Jan 7 20:06:31 test sshd[7866]: log: Connection from 211.39.150.44 port 1023 : Jan 7 20:06:34 test sshd[7866]: log: Closing connection to 211.39.150.44 : Jan 8 04:02:00 test anacron[8078]: Updated timestamp for job `cron.daily' to 2001-01-08 : Jan 8 04:02:42 test PAM_pwdb[8192]: (su) session opened for user news by (uid=0) : Jan 8 04:02:42 test PAM_pwdb[8192]: (su) session closed for user news : Jan 8 08:02:54 test sshd2[7629]: connection from "211.52.242.146" : Jan 8 08:02:58 test sshd2[8330]: DNS lookup failed for "211.52.242.146". : Jan 8 08:02:58 test sshd[8330]: log: Generating 768 bit RSA key. : Jan 8 08:02:59 test sshd[8330]: log: RSA key generation complete. : Jan 8 08:02:59 test sshd[8330]: log: Connection from 211.52.242.146 port 1023 : Jan 8 08:03:03 test sshd[8330]: log: Closing connection to 211.52.242.146 : : -- : 끝까지 읽어주셔서 감사합니다. 다 훓어보지 않고선 명확한 답변을 내리기 힘들겠네여. 대충보니 news란 아이디로 뚫린거 같은데요. ssh로 접속을 했군요. 리눅스를 새로 까시는게 가장 안전한 방법입니다. 백업하는 습관을 기릅시당 :)--모두 째수조은 하루 되세여.
Copyleft
1999-2026 by
JSBoard Open Project
Theme Designed by
IDOO
All right reserved