查看文章 |
远在身边的字典法密码破解
2008年03月11日 星期二 12:09
一个很普通的下午,本本安静地工作着,系统负荷0.xx,一直很安静。 作为一台ssh服务器,除了允许我的手机连接进来,在寂寞中无声无息地向这个世界开了一道门缝。 检查系统日志的时候发现,有“不法分子”想撬开这道门,高频试验着各种的用户/密码组合,企图做些可能令我痛苦万分的“伟大”的事情。当然,事实是,他们连用户名都猜不对,只好碰壁了(管理员root是存在的,但是已被设置成不能通过ssh登录)。 下面就是这样的一段系统日志,其中的IP地址指向遥远的台湾。截至今天,类似的情况还有两次,一次来自浙江,一次来自吉林。 (注:省略了一些内容,使用方括号表示了重复的内容,日期是3月2日,全部是ssh2协议。) 16:25:26 Did not receive identification string from 140.113.225.193 16:28:55 Invalid user admin from 140.113.225.193 [5] 16:28:55 pam: check pass; user unknown [1] 16:28:55 pam: authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=oasis4.ee.nctu.edu.tw [2] 16:28:57 Failed password for invalid user [4] admin from 140.113.225.193 port 39160 16:28:58 [2]user=root 16:29:00 Failed password for root from 140.113.225.193 [3] port 39187 16:29:01 [5]stud 16:29:01 [1] 16:29:01 [2] 16:29:03 [4]stud port 39205 16:29:04 [5]trash 16:29:04 [1] 16:29:04 [2] 16:29:05 [4]trash port 39224 16:29:07 [5]aaron 16:29:07 [1] 16:29:07 [2] 16:29:09 [4]aaron port 40045 16:29:10 [5]gt05 16:29:10 [1] 16:29:10 [2] 16:29:12 [4]gt05 port 40907 16:29:13 [5]william 16:29:13 [1] 16:29:13 [2] 16:29:15 [4]william port 41728 16:29:16 [5]stephanie 16:29:16 [1] 16:29:16 [2] 16:29:18 [4]stephanie port 41771 16:29:19 [2]user=root 16:29:21 [3]port 42588 16:29:22 [2]user=root 16:29:24 [3]port 43450 16:29:25 [2]user=root 16:29:27 [3]port 44261 16:29:28 [2]user=root 16:29:30 [3]port 44335 16:29:31 [2]user=root 16:29:33 [3]port 45124 16:29:34 [5]gary 16:29:34 [1] 16:29:34 [2] 16:29:37 [4]gary port 46002 16:29:38 [2]user=root 16:29:40 [3]port 46859 16:29:41 [5]guest 16:29:41 [1] 16:29:41 [2] 16:29:43 [4]guest port 47954 16:29:44 [5]test 16:29:44 [1] 16:29:44 [2] 16:29:46 [4]test port 48084 16:29:47 [5]oracle 16:29:47 [1] 16:29:47 [2] 16:29:49 [4]oracle port 48785 16:29:51 [2]user=root 16:29:52 [3]port 49595 16:29:54 [2]user=root 16:29:56 [3]port 50407 16:29:57 [2]user=root 16:29:59 [3]port 51222 16:30:00 [2]user=root 16:30:02 [3]port 51354 16:30:03 [2]user=root 16:30:05 [3]port 52051 16:30:06 [2]user=root 16:30:08 [3]port 52862 16:30:10 [2]user=root 16:30:11 [3]port 53676 16:30:12 [2]user=root 16:30:14 [3]port 53807 16:30:15 [2]user=root 16:30:17 [3]port 54509 16:30:18 [2]user=root 16:30:20 [3]port 55316 16:30:21 [2]user=root 16:30:23 [3]port 56128 16:30:25 [2]user=root 16:30:27 [3]port 56260 16:30:29 [2]user=root 16:30:31 [3]port 57079 16:30:32 [2]user=root 16:30:35 [3]port 57892 16:30:36 [2]user=root 16:30:38 [3]port 58707 16:30:39 [2]user=root 16:30:41 [3]port 59410 16:30:42 [2]user=root 16:30:44 [3]port 60356 16:30:45 [2]user=root 16:30:47 [3]port 32938 16:30:48 [2]user=root 16:30:51 [3]port 33097 16:30:52 [2]user=root 16:30:54 [3]port 34158 16:30:55 [2]user=root 16:30:57 [3]port 36245 16:30:58 [5]apache 16:30:58 [1] 16:30:58 [2] 16:31:00 [4]apache port 37059 16:31:02 [2]user=root 16:31:04 [3]port 38437 16:31:08 [2]user=root 16:31:11 [3]port 39344 16:31:12 [5]lab 16:31:12 [1] 16:31:12 [2] 16:31:14 [4]lab port 40547 16:31:15 [2]user=root 16:31:17 [3]port 40990 16:31:18 [5]oracle 16:31:18 [1] 16:31:18 [2] 16:31:20 [4]oracle port 41807 16:31:21 [5]svn 16:31:21 [1] 16:31:21 [2] 16:31:23 [4]svn port 42620 16:31:24 [5]iraf 16:31:24 [1] 16:31:24 [2] 16:31:26 [4]iraf port 43011 16:31:28 [5]swsoft 16:31:28 [1] 16:31:28 [2] 16:31:29 [4]swsoft port 43440 16:31:33 [5]production 16:31:33 [1] 16:31:33 [2] 16:31:36 [4]production port 44249 16:31:37 [5]guest 16:31:37 [1] 16:31:37 [2] 16:31:39 [4]guest port 45865 16:31:40 [5]gast 16:31:40 [1] 16:31:40 [2] 16:31:42 [4]gast port 46255 16:31:43 [5]gast 16:31:43 [1] 16:31:43 [2] 16:31:45 [4]gast port 46683 16:31:46 [5]oliver 16:31:46 [1] 16:31:46 [2] 16:31:48 [4]oliver port 47490 16:31:50 [5]sirsi 16:31:50 [1] 16:31:50 [2] 16:31:52 [4]sirsi port 48298 16:31:53 [5]nagios 16:31:53 [1] 16:31:53 [2] 16:31:56 [4]nagios port 49108 16:31:57 [5]nagios 16:31:57 [1] 16:31:57 [2] 16:31:59 [4]nagios port 49917 16:32:00 [5]nagios 16:32:00 [1] 16:32:00 [2] 16:32:03 [4]nagios port 50304 16:32:04 [5]nagios 16:32:04 [1] 16:32:04 [2] 16:32:06 [4]nagios port 51113 16:32:07 [5]backuppc 16:32:07 [1] 16:32:07 [2] 16:32:09 [4]backuppc port 51540 16:32:10 [5]wolfgang 16:32:10 [1] 16:32:10 [2] 16:32:12 [4]wolfgang port 52346 16:32:13 [5]vmware 16:32:13 [1] 16:32:13 [2] 16:32:15 [4]vmware port 53157 16:32:16 [5]stats 16:32:16 [1] 16:32:16 [2] 16:32:19 [4]stats port 53550 16:32:20 [5]kor 16:32:20 [1] 16:32:20 [2] 16:32:23 [4]kor port 54361 16:32:24 [5]wei 16:32:24 [1] 16:32:24 [2] 16:32:26 [4]wei port 55171 16:32:28 [5]cvsuser 16:32:28 [1] 16:32:28 [2] 16:32:30 [4]cvsuser port 55603 16:32:31 [5]cvsuser 16:32:31 [1] 16:32:31 [2] 16:32:33 [4]cvsuser port 56414 16:32:40 [5]cvsuser 16:32:40 [1] 16:32:40 [2] 16:32:42 [4]cvsuser port 33067 16:32:43 [5]javi 16:32:43 [1] 16:32:43 [2] 16:32:46 [4]javi port 34691 16:32:52 [5]ubuntu 16:32:52 [1] 16:32:52 [2] 16:32:54 [4]ubuntu port 35501 16:32:55 [5]blog 16:32:55 [1] 16:32:55 [2] 16:32:57 [4]blog port 37316 16:32:59 [2]user=root 16:33:01 [3]port 38319 16:33:02 [2]user=root 16:33:04 [3]port 39333 16:33:05 [2]user=root 16:33:08 [3]port 40647 16:33:09 [2]user=root 16:33:11 [3]port 41515 16:33:15 [5]diane 16:33:15 [1] 16:33:15 [2] 16:33:17 [4]diane port 41911 16:33:19 [5]fred 16:33:19 [1] 16:33:19 [2] 16:33:21 [4]fred port 43262 16:33:22 [5]student 16:33:22 [1] 16:33:22 [2] 16:33:24 [4]student port 44071 16:33:25 [5]test 16:33:25 [1] 16:33:25 [2] 16:33:27 [4]test port 44757 16:33:29 [5]guest 16:33:29 [1] 16:33:29 [2] 16:33:31 [4]guest port 45564 16:33:32 [5]guest 16:33:32 [1] 16:33:32 [2] 16:33:34 [4]guest port 45960 16:33:35 [5]test 16:33:35 [1] 16:33:35 [2] 16:33:37 [4]test port 46509 16:33:38 [5]student 16:33:38 [1] 16:33:38 [2] 16:33:41 [4]student port 47311 16:33:42 [5]admin 16:33:42 [1] 16:33:42 [2] 16:33:44 [4]admin port 48121 16:33:45 [5]admin 16:33:45 [1] 16:33:45 [2] 16:33:47 [4]admin port 48808 16:33:48 [5]user 16:33:48 [1] 16:33:48 [2] 16:33:50 [4]user port 48975 16:33:51 [5]user 16:33:51 [1] 16:33:51 [2] 16:33:53 [4]user port 48985 16:33:54 [5]core 16:33:54 [1] 16:33:54 [2] 16:33:56 [4]core port 48993 16:33:57 [5]mama 16:33:57 [1] 16:33:57 [2] 16:33:58 [4]mama port 49001 16:34:00 [5]mom 16:34:00 [1] 16:34:00 [2] 16:34:02 [4]mom port 49009 16:34:03 [5]mom 16:34:03 [1] 16:34:03 [2] 16:34:05 [4]mom port 49024 16:34:10 [5]festival 16:34:10 [1] 16:34:10 [2] 16:34:11 [4]festival port 49037 16:34:13 [5]files 16:34:13 [1] 16:34:13 [2] 16:34:15 [4]files port 49064 16:34:16 [5]frei 16:34:16 [1] 16:34:16 [2] 16:34:18 [4]frei port 49881 16:34:24 [5]je 16:34:24 [1] 16:34:24 [2] 16:34:26 [4]je port 50696 16:34:27 [5]jean 16:34:27 [1] 16:34:27 [2] 16:34:29 [4]jean port 52334 16:34:30 [5]juan 16:34:30 [1] 16:34:30 [2] 16:34:32 [4]juan port 53141 16:34:34 [5]first 16:34:34 [1] 16:34:34 [2] 16:34:35 [4]first port 53165 16:34:42 [5]dank 16:34:42 [1] 16:34:42 [2] 16:34:44 [4]dank port 58051 16:34:45 [5]farrell 16:34:45 [1] 16:34:45 [2] 16:34:46 [4]farrell port 59692 16:34:48 [5]genoveva 16:34:48 [1] 16:34:48 [2] 16:34:50 [4]genoveva port 60493 16:34:51 [5]amanda 16:34:51 [1] 16:34:51 [2] 16:34:52 [4]amanda port 33077 16:34:54 [5]amanda 16:34:54 [1] 16:34:54 [2] 16:34:56 [4]amanda port 33097 16:34:57 [5]video 16:34:57 [1] 16:34:57 [2] 16:34:58 [4]video port 34589 16:34:59 [5]video 16:34:59 [1] 16:34:59 [2] 16:35:01 [4]video port 36007 16:35:02 [5]martin 16:35:02 [1] 16:35:02 [2] 16:35:04 [4]martin port 36917 16:35:05 [5]martin 16:35:05 [1] 16:35:05 [2] 16:35:07 [4]martin port 36983 16:35:09 [5]hans 16:35:09 [1] 16:35:09 [2] 16:35:10 [4]hans port 37790 16:35:11 [5]nickelan 16:35:11 [1] 16:35:11 [2] 16:35:13 [4]nickelan port 38600 16:35:14 [5]nickelan 16:35:14 [1] 16:35:14 [2] 16:35:16 [4]nickelan port 39410 16:35:18 [5]nick 16:35:18 [1] 16:35:18 [2] 16:35:19 [4]nick port 39437 16:35:20 [5]nick 16:35:20 [1] 16:35:20 [2] 16:35:23 [4]nick port 40240 16:35:24 [5]vwalker 16:35:24 [1] 16:35:24 [2] 16:35:26 [4]vwalker port 41053 16:35:27 [2]user=root 16:35:29 [3]port 41866 16:35:30 [2]user=root 16:35:32 [3]port 42672 16:35:36 [2]user=root 16:35:38 [3]port 42698 16:35:39 [5]test 16:35:39 [1] 16:35:39 [2] 16:35:40 [4]test port 44312 16:35:42 [5]admin 16:35:42 [1] 16:35:42 [2] 16:35:43 [4]admin port 45120 16:35:44 [5]guest 16:35:44 [1] 16:35:44 [2] 16:35:47 [4]guest port 45137 16:35:48 [5]student 16:35:48 [1] 16:35:48 [2] 16:35:50 [4]student port 45953 16:35:52 [5]matt 16:35:52 [1] 16:35:52 [2] 16:35:53 [4]matt port 46766 16:35:54 [5]user 16:35:54 [1] 16:35:54 [2] 16:35:56 [4]user port 47574 16:36:02 [5]amanda 16:36:02 [1] 16:36:02 [2] 16:36:05 [4]amanda port 47599 16:36:06 [5]vnc 16:36:06 [1] 16:36:06 [2] 16:36:08 [4]vnc port 50020 16:36:10 [5]spamd 16:36:10 [1] 16:36:10 [2] 16:36:11 [4]spamd port 50048 16:36:17 [5]user 16:36:17 [1] 16:36:17 [2] 16:36:19 [4]user port 50852 16:36:20 [5]michel 16:36:20 [1] 16:36:20 [2] 16:36:22 [4]michel port 52482 16:36:23 [5]michaels 16:36:23 [1] 16:36:23 [2] 16:36:25 [4]michaels port 53295 16:36:26 [5]hallo 16:36:26 [1] 16:36:26 [2] 16:36:29 [4]hallo port 54104 16:36:30 [5]der 16:36:30 [1] 16:36:30 [2] 16:36:32 [4]der port 54919 16:36:33 [5]bernd 16:36:33 [1] 16:36:33 [2] 16:36:35 [4]bernd port 54948 16:36:37 [2]user=root 16:36:39 [3]port 55755 16:36:40 [5]tomcat5 16:36:40 [1] 16:36:40 [2] 16:36:42 [4]tomcat5 port 56568 16:36:47 [5]denis 16:36:47 [1] 16:36:47 [2] 16:36:49 [4]denis port 57379 16:36:50 [5]test2 16:36:50 [1] 16:36:50 [2] 16:36:52 [4]test2 port 59002 16:36:53 [5]test 16:36:53 [1] 16:36:53 [2] 16:36:55 [4]test port 59032 16:36:57 [5]test 16:36:57 [1] 16:36:57 [2] 16:36:59 [4]test port 59845 16:37:00 [5]test 16:37:00 [1] 16:37:00 [2] 16:37:02 [4]test port 60974 16:37:04 [5]test 16:37:04 [1] 16:37:04 [2] 16:37:06 [4]test port 34152 16:37:07 [5]test 16:37:07 [1] 16:37:07 [2] 16:37:09 [4]test port 36405 16:37:10 [5]test 16:37:10 [1] 16:37:10 [2] 16:37:12 [4]test port 37220 16:37:13 [5]test 16:37:13 [1] 16:37:13 [2] 16:37:16 [4]test port 37761 16:37:17 [5]test 16:37:17 [1] 16:37:17 [2] 16:37:19 [4]test port 38578 16:37:20 [5]test 16:37:20 [1] 16:37:20 [2] 16:37:22 [4]test port 38977 16:37:24 [5]test 16:37:24 [1] 16:37:24 [2] 16:37:26 [4]test port 39699 16:37:27 [5]test 16:37:27 [1] 16:37:27 [2] 16:37:29 [4]test port 40514 16:37:30 [5]test 16:37:30 [1] 16:37:30 [2] 16:37:32 [4]test port 41304 16:37:34 [5]test3 16:37:34 [1] 16:37:34 [2] 16:37:36 [4]test3 port 41845 16:37:37 [5]test4 16:37:37 [1] 16:37:37 [2] 16:37:39 [4]test4 port 42659 16:37:41 [5]test5 16:37:41 [1] 16:37:41 [2] 16:37:42 [4]test5 port 43060 16:37:44 [5]test6 16:37:44 [1] 16:37:44 [2] 16:37:46 [4]test6 port 43780 16:37:47 [5]test7 16:37:47 [1] 16:37:47 [2] 16:37:49 [4]test7 port 44597 16:37:51 [5]test8 16:37:51 [1] 16:37:51 [2] 16:37:53 [4]test8 port 45389 16:37:54 [5]test9 16:37:54 [1] 16:37:54 [2] 16:37:56 [4]test9 port 46963 16:37:57 [5]test10 16:37:57 [1] 16:37:57 [2] 16:37:59 [4]test10 port 47540 16:38:00 [5]test11 16:38:00 [1] 16:38:00 [2] 16:38:02 [4]test11 port 48077 16:38:03 [5]test12 16:38:03 [1] 16:38:03 [2] 16:38:05 [4]test12 port 48989 16:38:10 [5]ts 16:38:10 [1] 16:38:10 [2] 16:38:12 [4]ts port 49778 16:38:13 [5]im 16:38:13 [1] 16:38:13 [2] 16:38:15 [4]im port 51073 16:38:16 [5]delta 16:38:16 [1] 16:38:16 [2] 16:38:18 [4]delta port 51544 16:38:19 [5]visitor 16:38:19 [1] 16:38:19 [2] 16:38:22 [4]visitor port 52358 16:38:23 [5]armen 16:38:23 [1] 16:38:23 [2] 16:38:25 [4]armen port 53075 16:38:26 [2]user=root 16:38:28 [3]port 53866 16:38:30 [5]fabrice 16:38:30 [1] 16:38:30 [2] 16:38:31 [4]fabrice port 54680 16:38:32 [5]fabrice 16:38:32 [1] 16:38:32 [2] 16:38:35 [4]fabrice port 54814 16:38:41 [5]benjamin 16:38:41 [1] 16:38:41 [2] 16:38:43 [4]benjamin port 55654 16:38:45 [5]test 16:38:45 [1] 16:38:45 [2] 16:38:47 [4]test port 57286 16:38:48 [5]test 16:38:48 [1] 16:38:48 [2] 16:38:50 [4]test port 58101 16:38:51 [2]user=root 16:38:53 [3]port 58811 16:38:54 [2]user=root 16:38:56 [3]port 59043 16:38:57 [5]valas 16:38:57 [1] 16:38:57 [2] 16:38:59 [4]valas port 59056 16:39:01 [5]moshutzu 16:39:01 [1] 16:39:01 [2] 16:39:03 [4]moshutzu port 59068 16:39:05 [2]user=root 16:39:06 [3]port 59084 16:39:08 [5]admin 16:39:08 [1] 16:39:08 [2] 16:39:10 [4]admin port 59102 16:39:12 [5]admin 16:39:12 [1] 16:39:12 [2] 16:39:14 [4]admin port 59118 16:39:20 [5]wrestling 16:39:20 [1] 16:39:20 [2] 16:39:23 [4]wrestling port 59134 16:39:29 [5]toto 16:39:29 [1] 16:39:29 [2] 16:39:32 [4]toto port 32914 16:39:33 [5]admin 16:39:33 [1] 16:39:33 [2] 16:39:35 [4]admin port 35199 16:39:36 [2]user=root 16:39:38 [3]port 36215 16:39:40 [5]carlos 16:39:40 [1] 16:39:40 [2] 16:39:41 [4]carlos port 37190 16:39:43 [5]cyrus 16:39:43 [1] 16:39:43 [2] 16:39:45 [4]cyrus port 37276 16:39:46 [5]hermes 16:39:46 [1] 16:39:46 [2] 16:39:49 [4]hermes port 38306 16:39:50 [5]test 16:39:50 [1] 16:39:50 [2] 16:39:52 [4]test port 39257 16:39:54 [5]test 16:39:54 [1] 16:39:54 [2] 16:39:56 [4]test port 40056 16:39:57 [2]user=root 16:39:59 [3]port 40869 16:40:01 [5]sid 16:40:01 [1] 16:40:01 [2] 16:40:02 [4]sid port 41742 16:40:04 [5]vincent 16:40:04 [1] 16:40:04 [2] 16:40:06 [4]vincent port 42622 16:40:07 [2]user=root 16:40:09 [3]port 43586 16:40:10 [5]stella 16:40:10 [1] 16:40:10 [2] 16:40:12 [4]stella port 43897 16:40:13 [5]ernie 16:40:13 [1] 16:40:13 [2] 16:40:15 [4]ernie port 44697 16:40:16 [2]user=root 16:40:19 [3]port 45593 16:40:20 [2]user=root 16:40:22 [3]port 46502 16:40:23 [2]user=root 16:40:25 [3]port 47289 16:40:26 [2]user=root 16:40:28 [3]port 47548 16:40:30 [2]user=root 16:40:32 [3]port 48232 16:40:33 [2]user=root 16:40:35 [3]port 49229 16:40:36 [2]user=root 16:40:38 [3]port 50180 16:40:40 [5]nokia 16:40:40 [1] 16:40:40 [2] 16:40:42 [4]nokia port 51055 16:40:44 [5]download 16:40:44 [1] 16:40:44 [2] 16:40:46 [4]download port 52078 16:40:47 [5]transfer 16:40:47 [1] 16:40:47 [2] 16:40:49 [4]transfer port 53106 16:40:51 [5]oracle 16:40:51 [1] 16:40:51 [2] 16:40:53 [4]oracle port 53427 16:40:54 [5]admin 16:40:54 [1] 16:40:54 [2] 16:40:56 [4]admin port 54512 16:40:58 [5]michal 16:40:58 [1] 16:40:58 [2] 16:40:59 [4]michal port 55248 16:41:02 [5]informix 16:41:02 [1] 16:41:02 [2] 16:41:04 [4]informix port 56156 16:41:05 [5]xbox 16:41:05 [1] 16:41:05 [2] 16:41:07 [4]xbox port 57334 16:41:08 [2]user=root 16:41:10 [3]port 58390 16:41:12 [5]cindy 16:41:12 [1] 16:41:12 [2] 16:41:13 [4]cindy port 59317 16:41:15 [5]reboot 16:41:15 [1] 16:41:15 [2] 16:41:16 [4]reboot port 59726 16:41:18 [5]restart 16:41:18 [1] 16:41:18 [2] 16:41:20 [4]restart port 60768 16:41:21 [5]anna 16:41:21 [1] 16:41:21 [2] 16:41:23 [4]anna port 33483 16:41:32 [5]image 16:41:32 [1] 16:41:32 [2] 16:41:34 [4]image port 34488 |
最近读者: