sshguard-pf 无法阻挡ssh攻击,不知何解
时间:2010-12-26
来源:互联网
安装配置sshguard
cd /usr/ports/security/sshguard-pf
make install clean
vi etc/syslog.conf
添加
复制代码
服务器有两个网卡,so
vi /etc/pf.conf 内容如下
复制代码
/etc/rc.d/syslog reload
top found
复制代码
tail -f /var/log/auth.log
测试ssh攻击,看起来sshguard没有发挥作用
复制代码
cd /usr/ports/security/sshguard-pf
make install clean
vi etc/syslog.conf
添加
- auth.info;authpriv.info |exec /usr/local/sbin/sshguard
vi /etc/pf.conf 内容如下
- table <sshguard> persist
-
- set skip on lo
-
- scrub in
-
- block in quick on egress proto tcp from <sshguard> to any port 22 label "ssh bruteforce"
- pass in
- pass out
top found
- 7907 root 2 44 0 7184K 1612K nanslp 4 0:00 0.00% sshguard
测试ssh攻击,看起来sshguard没有发挥作用
- Dec 26 10:29:47 b sshd[1077]: Server listening on 0.0.0.0 port 22.
- Dec 26 10:29:47 b sshguard[1079]: Started successfully [(a,p,s)=(4, 420, 1200)],now ready to scan.
- Dec 26 10:32:18 b sshd[1202]: error: PAM: authentication error for illegal user a from 10.0.0.88
- Dec 26 10:32:18 b sshd[1202]: Failed keyboard-interactive/pam for invalid user a from 10.0.0.88 port 49700 ssh2
- Dec 26 10:32:18 b sshd[1202]: error: PAM: authentication error for illegal user a from 10.0.0.88
- Dec 26 10:32:18 b sshd[1202]: Failed keyboard-interactive/pam for invalid user a from 10.0.0.88 port 49700 ssh2
- Dec 26 10:32:23 b sshd[1206]: Invalid user a from 10.0.0.88
- Dec 26 10:32:23 b sshd[1206]: error: PAM: authentication error for illegal user a from 10.0.0.88
- Dec 26 10:32:23 b sshd[1206]: Failed keyboard-interactive/pam for invalid user a from 10.0.0.88 port 49701 ssh2
- Dec 26 10:32:23 b sshd[1206]: error: PAM: authentication error for illegal user a from 10.0.0.88
- Dec 26 10:32:23 b sshd[1206]: Failed keyboard-interactive/pam for invalid user a from 10.0.0.88 port 49701 ssh2
- Dec 26 10:32:29 b sshd[1210]: Invalid user a from 10.0.0.88
- Dec 26 10:32:29 b sshd[1210]: error: PAM: authentication error for illegal user a from 10.0.0.88
- Dec 26 10:32:29 b sshd[1210]: Failed keyboard-interactive/pam for invalid user a from 10.0.0.88 port 49702 ssh2
- Dec 26 10:32:29 b sshd[1210]: error: PAM: authentication error for illegal user a from 10.0.0.88
- Dec 26 10:32:29 b sshd[1210]: Failed keyboard-interactive/pam for invalid user a from 10.0.0.88 port 49702 ssh2
- Dec 26 10:32:34 b sshd[1214]: Invalid user a from 10.0.0.88
- Dec 26 10:32:34 b sshd[1214]: error: PAM: authentication error for illegal user a from 10.0.0.88
- Dec 26 10:32:34 b sshd[1214]: Failed keyboard-interactive/pam for invalid user a from 10.0.0.88 port 49703 ssh2
- Dec 26 10:32:34 b sshd[1214]: error: PAM: authentication error for illegal user a from 10.0.0.88
- Dec 26 10:32:34 b sshd[1214]: Failed keyboard-interactive/pam for invalid user a from 10.0.0.88 port 49703 ssh2
- Dec 26 10:32:39 b sshd[1218]: Invalid user a from 10.0.0.88
- Dec 26 10:32:39 b sshd[1218]: error: PAM: authentication error for illegal user a from 10.0.0.88
- Dec 26 10:32:39 b sshd[1218]: Failed keyboard-interactive/pam for invalid user a from 10.0.0.88 port 49704 ssh2
- Dec 26 10:32:39 b sshd[1218]: error: PAM: authentication error for illegal user a from 10.0.0.88
- Dec 26 10:32:39 b sshd[1218]: Failed keyboard-interactive/pam for invalid user a from 10.0.0.88 port 49704 ssh2
- Dec 26 10:32:43 b sshd[1222]: Invalid user a from 10.0.0.88
- Dec 26 10:32:44 b sshd[1222]: error: PAM: authentication error for illegal user a from 10.0.0.88
- Dec 26 10:32:44 b sshd[1222]: Failed keyboard-interactive/pam for invalid user a from 10.0.0.88 port 49705 ssh2
- Dec 26 10:32:44 b sshd[1222]: error: PAM: authentication error for illegal user a from 10.0.0.88
- Dec 26 10:32:44 b sshd[1222]: Failed keyboard-interactive/pam for invalid user a from 10.0.0.88 port 49705 ssh2
- Dec 26 10:32:48 b sshd[1226]: Invalid user a from 10.0.0.88
作者: f5b 发布时间: 2010-12-26
环境
freebsd 8.1 release
sshguard 1.4
freebsd 8.1 release
sshguard 1.4
作者: f5b 发布时间: 2010-12-26
相关阅读 更多
热门阅读
-
office 2019专业增强版最新2021版激活秘钥/序列号/激活码推荐 附激活工具
阅读:74
-
如何安装mysql8.0
阅读:31
-
Word快速设置标题样式步骤详解
阅读:28
-
20+道必知必会的Vue面试题(附答案解析)
阅读:37
-
HTML如何制作表单
阅读:22
-
百词斩可以改天数吗?当然可以,4个步骤轻松修改天数!
阅读:31
-
ET文件格式和XLS格式文件之间如何转化?
阅读:24
-
react和vue的区别及优缺点是什么
阅读:121
-
支付宝人脸识别如何关闭?
阅读:21
-
腾讯微云怎么修改照片或视频备份路径?
阅读:28