| 关键词: nbsp scanssh 00 Jul 02 进程 ssh 口令 定时 21 |
入侵者一般利用oracle/sybase/nagios/tuxedo等常用Linux/UNIX的应用服务的用户名套passwd.txt等口令字典文件循环尝试用22端口ssh登录。 再在局域网中查找使用了弱口令的“肉鸡”的主机,试图入侵。 再一看进程,好多ssh-scan的进程。估计是密码设得太简单,被人家黑了。处理思路:找到ssh-scan进程的相应程序文件,删除之。先查看定时任务,没有看到有异常的定时任务。最后处理步骤如下:1、ps -ef|grep ssh-scan (或ps –ajxf)?123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596ps -ef|grep ssh500892310 Jul02 ? 00:00:22 ./scanssh500892810 Jul02 ? 00:00:22 ./scanssh500892910 Jul02 ? 00:00:20 ./scanssh500893710 Jul02 ? 00:00:18 ./scanssh500893810 Jul02 ? 00:00:21 ./scanssh500893910 Jul02 ? 00:00:21 ./scanssh500894110 Jul02 ? 00:00:18 ./scanssh500894810 Jul02 ? 00:00:17 ./scanssh500894910 Jul02 ? 00:00:14 ./scanssh500895310 Jul02 ? 00:00:21 ./scanssh500895510 Jul02 ? 00:00:17 ./scanssh500895710 Jul02 ? 00:00:27 ./scanssh500896610 Jul02 ? 00:00:22 ./scanssh500896710 Jul02 ? 00:00:22 ./scanssh500896810 Jul02 ? 00:00:22 ./scanssh500896910 Jul02 ? 00:00:10 ./scanssh500897110 Jul02 ? 00:00:21 ./scanssh500897510 Jul02 ? 00:00:00 ./scanssh500898010 Jul02 ? 00:00:00 ./scanssh500898410 Jul02 ? 00:00:18 ./scanssh500898610 Jul02 ? 00:00:06 ./scanssh500899610 Jul02 ? 00:00:03 ./scanssh500901510 Jul02 ? 00:00:31 ./scanssh500901610 Jul02 ? 00:00:21 ./scanssh500901910 Jul02 ? 00:00:19 ./scanssh500902510 Jul02 ? 00:00:21 ./scanssh500902610 Jul02 ? 00:00:20 ./scanssh500903110 Jul02 ? 00:00:37 ./scanssh500905910 Jul02 ? 00:00:
声明:文章版权归原作者所有 部分文章转自互联网 如有侵权请联系
[邮箱地址] 删除
|