Про китайских хакеров
Dec. 23rd, 2014 12:29 am![[personal profile]](https://www.dreamwidth.org/img/silk/identity/user.png)
Ковырялись в конфигурации некоего свитча, имеющего публичный IP адрес, и на всякий случай, чтоб не заблокировать самих себя, отключили access list, который не дает соединяться с железкой кому попало. В логи тут же полезло:
В результате работа встала, все с интересом смотрели в логи. Потом надоело, конечно, ибо тупизна несусветная, и включили access list обратно.
%AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user root#02##02# from 122.225.103.97 - sshd[7116]
%AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user root#02##02# from 122.225.103.97 - sshd[7113]
%AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user root#02##02# from 122.225.103.97 - sshd[7119]
%AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user root#02# from 122.225.103.97 - sshd[7397]
%AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user admin#02# from 122.225.103.97 - sshd[7398]
%AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user root#02##02# from 122.225.103.97 - sshd[7394]
%AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user root#02##02# from 122.225.103.97 - sshd[7397]
%AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user admin#02##02# from 122.225.103.97 - sshd[7398]
%AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user root from 122.225.103.97 - sshd[7418]
%AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user root#02# from 122.225.103.97 - sshd[7418]
%AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user root from 122.225.103.97 - sshd[7429]
%AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user root#02##02# from 122.225.103.97 - sshd[7418]
%AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user root#02# from 122.225.103.97 - sshd[7429]
%DAEMON-2-SYSTEM_MSG: fatal: Write failed: Broken pipe .Client is 122.225.103.97,length of packet causing error 84 84 - sshd[7536]
В результате работа встала, все с интересом смотрели в логи. Потом надоело, конечно, ибо тупизна несусветная, и включили access list обратно.