*1  SSH¤ËÂФ¹¤ë¥Ö¥ë¡¼¥È¥Õ¥©¡¼¥¹¹¶·â¤Ø¤ÎÂкö

sshd ¤Ø¤Î¥Ñ¥¹¥ï¡¼¥ÉÁíÅö¤¿¤ê¹¶·â¤Ïº£Ç¯¤ÎÁ°È¾¤¯¤é¤¤¤«¤éÈó¾ï¤ËÁý¤¨¤Æ¤¤¤Æ¡¢¡Ö¼ÂºÝ¤Ë guest ¤ä test ¤Ê¤É¤Î¥¢¥«¥¦¥ó¥È̾¤ò¾è¤Ã¼è¤é¤ì¤¿¡×¤È¸À¤¦¥±¡¼¥¹¤â¼Â¤Ï¤½¤³¤½¤³¤ÎÉÑÅÙ¤Çʹ¤¤¤Æ¤¤¤ë¡£»Å»ö¤Ç¤Ï´û¤ËËɸ楹¥¯¥ê¥×¥È¤ò»Å¹þ¤ó¤Ç¤¤¤ë¥µ¡¼¥Ð¤â¤¢¤ë¤¬¡¢ÌµËÉÈ÷¤Ê¥µ¡¼¥Ð¤Ë¼ÂºÝ¤Ë¤É¤ì¤¯¤é¤¤¤Î¹¶·â¤¬Íè¤Æ¤¤¤ë¤Î¤«¡¢¥í¥°¤ò¸«¤Æ¤ß¤¿¡£

*2  ¸ºß¤·¤Ê¤¤¥æ¡¼¥¶¤Ø¤Î¹¶·â

sshd ¤Ø¤Î¥¢¥¯¥»¥¹¤¬¼ºÇÔ¤¹¤ë¤È¡¢¾¯¤Ê¤¯¤È¤â FreeBSD ¤ä Debian ¤Ç¤Ï /var/log/auth.log ¤Ë¥á¥Ã¥»¡¼¥¸¤¬»Ä¤ë¡£¾å¤¬Â¸ºß¤·¤Ê¤¤¥æ¡¼¥¶¡¢²¼¤¬Â¸ºß¤¹¤ë¥æ¡¼¥¶¤Ø¤ÎÁíÅö¤¿¤ê¹¶·â¥í¥°¤ÎÎã

Nov 8 11:29:47 example sshd[81317]: Failed password for invalid user jiseitai from 211.93.0.248 port 59039 ssh2
Nov 8 11:29:47 example sshd[81317]: Failed password for root from 211.93.0.248 port 59039 ssh2

¤³¤ì¤ò ruby ¤Î¥ï¥ó¥é¥¤¥Ê¡¼¤Ç̾Á°¤ÎÉôʬ¤À¤±ÀÚ¤ê½Ð¤·¤Æ¤ß¤ë¡£°Ê²¼¤Ç»È¤Ã¤¿¤Î¤ÏË¿½ê¥µ¡¼¥Ð¤Î 11·îʬ¤Î¥í¥°¡£
# grep -c invalid /var/log/auth.log
18125
# ruby -e '
names = Array.new
File.open("/var/log/auth.log").each do |line|
  if /invalid user (\w+) from/ =~ line then
    names.push $1
  end
end
puts names.uniq.join(", ")' > list
# wc list
    1   8367   68752
8,367¼ïÎà¤Î¥¢¥«¥¦¥ó¥È̾¤Ç¡¢Ìó18,000²ó¤â¥¢¥¿¥Ã¥¯¤·¤Æ¤­¤Æ¤¤¤ë¤è¤¦¤À¡£

*3  ¹¶·â¸µ IP ¥¢¥É¥ì¥¹

¾åµ­¤Î ruby ¥ï¥ó¥é¥¤¥Ê¡¼¤ò¾¯¤·ÊѤ¨¤Æ ip ¥¢¥É¥ì¥¹¤òÃê½Ð¤·¤Æ¤ß¤ë¡£
# ruby -e '
ips = Hash.new(0)
File.open("/var/log/auth.log").each do |line|
  if /Failed password for .+ from ([0-9\.]+) port/ =~ line then
    ips[$1] += 1
  end
end
ips.sort{|a,b| b[1]<=>a[1]}.each do |ip, count|
  puts "#{count} - #{ip}"
end'
¤È¤¤¤¦´¶¤¸¤Ç¡£Àè¤Î¹¶·â¤Ï¸«¤Æ¤ß¤ë¤È 50 IP Addresses ¤«¤éÍè¤Æ¤ë¤è¤¦¤À¡£100·ï±Û¤¨¤¬ 17·ï¤Ç¡¢¤¦¤Á 1,000·ï±Û¤¨¤¬°Ê²¼¤Î 4·ï

5,272 - 219.240.75.45 (HANANET-HIGHBAN-MANTECH, Hananet Korean - hanaro.com)
3,387 - 211.93.0.248 (UNICOM, China United Telecommunication Corp. - cnuninet.com)
3,134 - 64.251.25.85 (INFOLINK-BLK-100, Infolink Information Services Inc. - infolink.com)
2,609 - 8.3.7.89 (LVLT, Level 3 Commucations, Inc. - level3.com)

whois ¤ÇÄ´¤Ù¤Æ¤ß¤ë¤È¡¢´Ú¹ñ¡¢Ãæ¹ñ¡¢Êƹñ¤È¤¤¤¦¸«»ö¤Ëŵ·¿Åª¤Ê¹¶·â¸µ¤Ë¤Ê¤Ã¤Æ¤¤¤ë¡£

*4  ÁíÅö¤¿¤ê¹¶·â¤òËɸ椹¤ë¥¹¥¯¥ê¥×¥È¤ä»ÅÁȤß

¤³¤¦¤·¤¿¹¶·â¤òËɱҤ¹¤ë¤Ë¤Ï¡¢Î㤨¤Ð sshd ¤ÎÂÔ¤Á¼õ¤± port ¤òɸ½à¤Î 22/tcp ¤«¤éÊѹ¹¤·¤¿¤ê¡¢knockd ¤ò»È¤Ã¤Æ port ¤òÊĤ¸¤¿¤ê¡¢¤Þ¤¿¤Ï ssh ¤Î¥Ñ¥¹¥ï¡¼¥É¤Ë¤è¤ëǧ¾Ú¤òÀڤäƤ·¤Þ¤¦ÊýË¡¤¬¤¢¤ë¡£¤·¤«¤·¤É¤ì¤â¥æ¡¼¥¶¤ËÄÌÃΤʤêÍøÍÑ·ÁÂÖ¤ÎÊѹ¹¤ò¶¯¤¤¤ë¤¿¤á¡¢ÂçÀª¤Ç»È¤Ã¤Æ¤¤¤ë¾ì¹ç¤Ë¤Ï¿¾¯Æ³Æþ¤·¿É¤¤¡£¤È¸À¤¦¤³¤È¤Ç¥µ¡¼¥Ð¦¤Ç¹¶·â¥¢¥¯¥»¥¹¤Î¤ß¤òµñÈݤ¹¤ë»ÅÁȤߤ¬¤¢¤ë¤ÈÊØÍø¤Ê¤³¤È¤â¿¤¤¡£

¸¶Íý¤È¤·¤Æ¤Ï´ðËÜŪ¤Ë¾åµ­¤Î¤è¤¦¤Ê¥í¥°¤«¤é ¹¶·â¸µ¤Î IP ¥¢¥É¥ì¥¹¤òÈ´¤­½Ð¤·¤Æ deny ¤¹¤ë¤â¤Î¤È¡¢¥Õ¥í¡¼À©¸æŪ¤Ëû»þ´Ö¤ËÊ£¿ô²ó¿ô¤Î ssh ¥¢¥¯¥»¥¹¤¬¤¢¤Ã¤¿¾ì¹ç¤Ë deny ¤¹¤ëÊýË¡¤¬¤¢¤ë¡£
maxlogins.pl
FreeBSD ÍѤȤʤäƤ¤¤ë¤¬ hosts.allow ¤ËÄɲ乤ë·Á¤Ê¤Î¤Ç Linux ¤¢¤¿¤ê¤Ç¤â»È¤¨¤½¤¦¡£¥í¥°¤ËÊ£¿ô²ó¤Î ssh login failure ¤¬¤¢¤ë¤È IP ¥¢¥É¥ì¥¹¤ò deny ¤ËÄɲ乤ë
sshdfilter
¤³¤ì¤â¸¶Íý¤Ï»÷¤¿¤è¤¦¤Ê¤â¤Î¤Ç¡¢libwrap ¤ÎÂå¤ï¤ê¤Ë iptables ¤ò»È¤¦¤Î¤¬°Û¤Ê¤ëÅÀ¡£ÅöÁ³ *BSD ¤Ç¤Ï»È¤¨¤Ê¤¤¤±¤É¡¢ipf ¤Ë½ñ¤­´¹¤¨¤ì¤Ð¤¤¤¤µ¤¤â¤¹¤ë¡£
Blocking repeated failed login attempts via SSH
¤³¤ì¤â»÷¤¿¤è¤¦¤Ê¤â¤Î¡£
ipt_recent
¤³¤ì¤Ï Linux iptables ¤Î ipt_recent ¥â¥¸¥å¡¼¥ë¤ò»È¤Ã¤Æ°ìÄê»þ´ÖÆâ¤ÎƱ°ì IP ¥¢¥É¥ì¥¹¤«¤é¤Î·«¤êÊÖ¤·¥¢¥¯¥»¥¹¤òµñÈݤ¹¤ë»ÅÁȤߡ£
¥í¥°²òÀϤò»È¤¦¤â¤Î¤Ï¡¢ÅöÁ³¥ê¥¢¥ë¥¿¥¤¥à¤ÎÂбþ¤Ï¤Ç¤­¤Ê¤¤¤·¡¢¤¢¤ëÄøÅÙ¤ÎÉÑÅÙ¤Ç¥í¥°¤Î¥¹¥­¥ã¥ó¤ò¹Ô¤¦É¬Íפ¬¤¢¤ë¤Î¤Ç¥í¥°¤ÎÈîÂç²½¤Ë¤Ïµ¤¤ò¤Ä¤±¤¿Êý¤¬¤¤¤¤¤À¤í¤¦¡£

*5  SSH brute force ¹¶·â¤«¤é¥µ¡¼¥Ð¤ò¼é¤ë - ¤Þ¤È¤á

ºÇ½é¤Ëµó¤²¤¿½Õ»³¤µ¤ó¤Î¤â¤Î¤È·ë¶É¤¿¤¤¤·¤ÆÊѤï¤é¤Ê¤¤¤ï¤±¤À¤¬°ì±þ½ñ¤¤¤È¤¯¡£
  1. ÆÃÄêIP¥¢¥É¥ì¥¹¤Î¤ß¤«¤é¤Î¥¢¥¯¥»¥¹¤òµö²Ä¤·¡¢Â¾¤ÏÁ´µñÈݤ¹¤ë
  2. sshd ¤Î listen port ¤ò 22/tcp ¤«¤é¾¤ÎǤ°Õ¤Î port ¤ËÊѹ¹¤¹¤ë
  3. ¥Ñ¥¹¥ï¡¼¥É¤Ë¤è¤ëǧ¾Ú¤ò¶Ø»ß¤¹¤ë (PasswordAuthentication no, ChallengeResponseAuthentication no)
  4. ÁíÅö¤¿¤ê¹¶·â¤ÎËɸ楹¥¯¥ê¥×¥È¤òƳÆþ¤¹¤ë
    • ¥í¥°¤«¤é¹¶·â¤ò¸¡ÃΤ·¡¢libwrap ¤ä iptables, ipf Åù¤ÇµñÈÝ
    • iptables ¤Îµ¡Ç½¤ò»È¤Ã¤ÆƱ¤¸IP¶õ¤ÎϢ³¥¢¥¯¥»¥¹¤ò¼«Æ°µñÈÝ
¤Á¤Ê¤ß¤Ë ssh ¤Ç¤Î root login ¤òµö²Ä (PermitRootLogin yes) ¤·¡¢¤·¤«¤â¥Ñ¥¹¥ï¡¼¥Éǧ¾Ú²Äǽ¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤Î¤Ï¡¢¸½»þÅÀ¤Ç¤Ï·ã¤·¤¯¤ª´«¤á½ÐÍè¤Ê¤¤¡£ÅöÁ³¤Ê¤¬¤é telnet ¤Ï¤½¤â¤½¤âµ¯Æ°¤·¤Ê¤¤¤« IP¥¢¥É¥ì¥¹¤Ç¥¢¥¯¥»¥¹¸µ¤ò¹Ê¤ë¤³¤È¡£

( Permalink | Comments (2) | tags: security  )
SSH¤ËÂФ¹¤ë¥Ö¥ë¡¼¥È¥Õ¥©¡¼¥¹¹¶·â¤Ø¤ÎÂй³ºö¤Î¤Þ¤È¤á([ssh:00251] Re: FYI: SSH¥µ¡¼¥Ð¡¼¤Ø¤Î¹¶·â¤¬Áý²Ã·¹¸þ¡¤¿¯Æþ¸å¤Ï¥Õ¥£¥Ã¥·¥ó¥°¡¦¥µ¥¤¥È¤Ë°­ÍѤâ) ¤ò¡¢¿·»³¤µ¤ó¤¬ssh@koka-in.org¥á¡¼¥ê¥ó¥°¥ê¥¹¥È¤ËÅê¹Æ¤·¤Æ²¼¤µ¤¤¤Þ¤·¤¿¡£°Ê²¼¤Ï¥á¡¼¥ë¤«¤é¤Î°úÍѤǤ¹¡£ ɸ½à¤Ç¤Ê¤¤¥Ý¡¼¥È (22/tcp°Ê³°) ¤ò»È¤¦.....
2. SSH ¥Ý¡¼¥È¤Ø¤Î¹¶·â from ¤×¤é¤×¤é¥Ö¥í¥° at 2005-11-21 14:55
¥µ¡¼¥Ðµ¡¤ÎÀßÄê¤Ê¤É¤Ë¤Ï SSH ¤ÈÄ̤·¤Æ¥³¥Þ¥ó¥É¥é¥¤¥ó¤Ç¹Ô¤Ã¤Æ¤¤¤ë¡£¡Ê£Ø¥µ¡¼¥Ð¤Ï...
3. Diary/2005-12-27 from PukiWiki Plus! (PukiWiki/TrackBack 0.3) at 2005-12-27 15:16
[memo] SSH ¤Ø¤ÎÁíÅö¤¿¤ê¹¶·â(brute force attack)¤ÈËÉ±Ò http://yoosee.net/d/archives/2005/11/08/002.html
4. Diary from PukiWiki Plus! (PukiWiki/TrackBack 0.3) at 2006-01-11 20:03
&lt;&lt; 2006.1 &gt;&gt; [Diary] Æü ·î ²Ð ¿å ÌÚ ¶â ÅÚ 1 2 3 4 5 6 7 .....
ºòÆü¤Þ¤Ç¤Ï ccs-tools ¥Ñ¥Ã¥±¡¼¥¸¤Ë´Þ¤Þ¤ì¤Æ¤¤¤ë¥µ¥ó¥×¥ë¥×¥í¥°¥é¥à¤Î¾Ò²ð¤ò¤·¤Æ¤­¤Þ¤·¤¿¡£ ccs-tools ¥Ñ¥Ã¥±¡¼¥¸¤Ë¤Ï´Þ¤Þ¤ì¤Æ¤¤¤Ê¤¤¥µ¥ó¥×¥ë¥×¥í¥°¥é¥à¤¬Â¾¤Ë¤â¤¿¤¯¤µ¤ó¤¢¤ê¤Þ¤¹¡£ ¤·¤«¤·¡¢¸ø³«µö²Ä¤¬½Ð¤Æ¤¤¤Ê¤¤¤Î¤Ç¾Ò²ð¤¹¤ë¤³¤È¤¬¤Ç¤­¤Þ¤»¤ó¡£ ¤½¤Î¤¿¤á¡¢¤È¤ê¤¢¤¨¤º¥Í¥¿ÀÚ.....
6. Brute Force from ¥²¡¼¥à´ØÏ¢¥ê¥¢¥ë¥¿¥¤¥à²Á³Ê¾ðÊó at 2006-03-25 00:44
&nbsp;&nbsp;&nbsp;4¿Í¤Î¥¨¥ê¡¼¥ÈÀï»Î¤«¤é¹½À®¤µ¤ì¤ë¾®Ââ¡¢¥Ö¥ë¡¼¥È¥Õ¥©¡¼¥¹¤òΨ¤¤¡¢6¤Ä¤Î¥ï¡¼¥ë¥É¤ò¤Þ¤¿¤Ë¤«¤±¤ÆÀ襤ȴ¤¤¤Æ¤¤¤¯¥¢¥¯¥·¥ç¥ó¥·¥å¡¼¥Æ¥£¥ó¥°¤À¡£À襤¤ò¤¯¤ê¹­¤²¤ëÀï»Î¤¿¤Á¤Ï¶Ã°ÛŪ¤ÊÀïƮǽÎϤȤ½¤ì¤¾¤ì¤Ë°Û¤Ê¤Ã¤¿Æü쥹¥­¥ë¤ò»ý¤Ä¥¹¥Ú¥·¥ã¥ê¥¹¥È¡£ÀïÆ®¤Î¾õ¶·¤Ë±þ¤¸¤ÆÈà¤é¤ò»È¤¤Ê¬¤±¤Æ¥²¡¼¥à¤ò¿Ê¤á¤Æ¤¤¤¯¡£ &nbsp;&nbsp;&nbsp;Ìó30¼ïÎàÍÑ°Õ¤µ¤ì¤¿Éð´ï¤Ï¡¢¶áµ÷Î¥ÍѤΤâ¤Î.....
Comments
1. PANDA at 2005-12-01 13:51
¶¯À©¥¢¥¯¥»¥¹À©¸æ¤òÍøÍѤ·¤Æǧ¾Ú¤ò¿½Å²½¤¹¤ì¤ÐÁ´Á³Éݤ¯¤Ê¤¤¤«¤â¡£ÍøÍѼԤˤϾ¯¤·Ééô¤¬Áý¤¨¤ë¤±¤É¡¢¤°¤Ã¤È°Â¿´¤Ç¤­¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¤è¤ó¢ö
http://sourceforge.jp/pro ... /2/winf2005.pdf
2. EroTDJ at 2009-02-01 23:45
¤Ò¤È¤³¤È¥³¥á¥ó¥È¤ò»Ä½ÁÛï߬º¼±ÇÛãúϳ´ØÍ¿øØѶËàòØÌ軶ú⵺ܼ¤ÒÜ·º¼úϳ´ØÍÆ꿶À°º¼úâ¿çÜÀ¤Ã¶ËØÍÀ°°Û¿¶À°º¼úâ¿çÜÀ¤ÃØÒ¿¶À°º¼úâ¿çÜÀ¤ÃÚÊúϳ´ØÍ¿øÍáØÑܼß̶˿¶À°º¼úâ¿çÜÀ¤ÃÍá´·ÞÓáú¿¶À°º¼úâ¿çÜÀ¤ÃËÒÀ°³´Î¸Íáúâßå¶ËØÓàÚËýÙà¹ÁÉ°Íá¾ö¶Ëúϳ´ØÍ¿øÝòÇù¶ËàòÛãÇùà²ÚïÉáÅòàÚÙàµôܼÀ°áÇÚÊâÎú§ÇùØÌ·ÉܼܴÛïØÒ³Íú§û¤ÇùãÓú»ºÏàòØÌ軶ú⵺ܼ¤Ò¡±É߶Ëú»ºÏúϳ´ØÍ¿øØÔÍá¿ø¶Ë·ÄܼÅòØÆÚÊúâßå¶ËØÓàÚËýÙàÉßÍáËÒµôØÆÚÊúâßå¶ËØÓàÚËýÙààΡ±Åòû´ÞÓÜ·úÞú»ºÏàòØÌ軶ú⵺ܼ¤Ò¡±¶ËúâµôâÎßÌú»ºÏúϳ´ØÍ¿ø¡±Éߺ¼´·ØÔ¶Ëú»ºÏàòØÌ軶ú⵺ܼ¤ÒØÌ¡±Ä¬Í躼¶ËØÆÚÊ¿¶À°º¼úâ¿çÜÀ¤ÃÀ¢¡±´·ÞÓáúú»ºÏàòØÌ軶ú⵺ܼ¤Ò´ºØÒÚÊÍáû´É°´·Î¸ØÆÚÊ¿¶À°º¼úâ¿çÜÀ¤ÃÏ´Íá·Éߩܼ¶ËÛïúÞ

Please write your comment. email address won't appear. Cannot use any HTML tags in comment.
¥³¥á¥ó¥È¤ò¤ª½ñ¤­²¼¤µ¤¤¡£¥á¡¼¥ë¥¢¥É¥ì¥¹¤Ï¸ø³«¤µ¤ì¤Þ¤»¤ó¡£ ¤Þ¤¿HTML¥¿¥°¤ÏÍøÍѤǤ­¤Þ¤»¤ó¡£
Name   E-mail   URL
Comment

About W.W.Walker

World Wide Walker ¤Ï yoosee ¤Ë¤è¤ë blog ¤Ç¤¹¡£PDA, Web¡¦¥µ¡¼¥Ðµ»½Ñ, ÈþÌ£¤·¤¤¿©¤Ùʪ¤Ê¤É¤ÎÏÃÂê¤ò¼è¤ê¾å¤²¤Æ¤¤¤Þ¤¹... read more

¤³¤Î¥¨¥ó¥È¥ê¡¼¤Î¥Ö¥Ã¥¯¥Þ¡¼¥¯

Monthly Archives

Select Month to read