ich habe fail2ban laufen, jedoch bannt er keine ips ? das obwohl ich unter /etc/fail2ban/ die config eingestellt habe fuer ssh und apache : /
Da vermehrt Angriffe auf meinen Server waren in den letzten 48 Stunden, habe ich die ganze Zeit tail -f /var/log/messages laufen und schaue immer mal wieder rauf, wenn ich surfe. Nach dem Einkaufen meinte ein Freund, dass unser Forum (www.entwickler-runde.de) down ist, ein Blick auf die Logs zeigte mir, dass ich wieder angegriffen worden bin und der Server nun Down ist. Hier einmal die letzten Log Eintraege, die ich an hatte:
Code: Select all
Jan 4 17:10:38 gameservershome sshd[16355]: reverse mapping checking getaddrinfo for fw.tablemac.com [200.13.253.122] failed - POSSIBLE BREAK-IN ATTEMPT!
Jan 4 17:10:38 gameservershome sshd[16355]: Invalid user cvs from 200.13.253.122
Jan 4 17:12:29 gameservershome sshd[16365]: Invalid user cvs from 205.232.166.6
Jan 4 17:12:57 gameservershome sshd[16374]: Invalid user dan from 89.181.112.226
Jan 4 17:13:00 gameservershome sshd[16376]: Invalid user jenkins from 89.181.112.226
Jan 4 17:13:02 gameservershome sshd[16378]: Invalid user jonhattan from 89.181.112.226
Jan 4 17:13:05 gameservershome sshd[16380]: Invalid user allcomputersystems from 89.181.112.226
Jan 4 17:13:15 gameservershome sshd[16386]: Invalid user jai from 89.181.112.226
Jan 4 17:13:19 gameservershome sshd[16390]: Invalid user prabhu from 89.181.112.226
Jan 4 17:13:24 gameservershome sshd[16392]: Invalid user funk from 89.181.112.226
Jan 4 17:13:30 gameservershome sshd[16396]: Invalid user mhi from 89.181.112.226
Jan 4 17:13:33 gameservershome sshd[16398]: Invalid user vino from 89.181.112.226
Jan 4 17:13:41 gameservershome sshd[16401]: Invalid user inn from 89.181.112.226
Jan 4 17:13:43 gameservershome sshd[16404]: Invalid user shan from 89.181.112.226
Jan 4 17:14:37 gameservershome sshd[16438]: Invalid user cvs from 202.153.229.198
Jan 4 17:16:21 gameservershome sshd[16480]: Invalid user cvs from 196.3.166.128
Jan 4 17:18:23 gameservershome sshd[16487]: Invalid user cvs from 84.246.69.21
Jan 4 17:22:15 gameservershome sshd[16502]: Invalid user cvsup from 200.142.77.236
Jan 4 17:24:12 gameservershome sshd[16510]: reverse mapping checking getaddrinfo for static-ip-cr1901468058.cable.net.co [190.146.80.58] failed - POSSIBLE BREAK-IN ATTEMPT!
Jan 4 17:24:12 gameservershome sshd[16510]: Invalid user cvsupin from 190.146.80.58
Jan 4 17:26:03 gameservershome sshd[16524]: Invalid user cwang from 193.174.152.195
Jan 4 17:31:58 gameservershome sshd[16614]: Invalid user cwchang from 193.138.250.159
Jan 4 17:34:05 gameservershome sshd[16623]: Invalid user cyb from 83.64.222.58
Jan 4 17:35:57 gameservershome sshd[16625]: Invalid user cyber from 199.33.217.42
Jan 4 17:37:57 gameservershome sshd[16628]: Invalid user cybev from 130.89.10.78
Jan 4 17:40:13 gameservershome sshd[16630]: Invalid user cychang from 80.37.88.65
Jan 4 17:41:58 gameservershome sshd[16656]: Invalid user cychao from 199.33.217.42
Jan 4 17:44:01 gameservershome sshd[16660]: Invalid user cychen from 60.30.26.187
Jan 4 17:46:04 gameservershome sshd[16683]: Invalid user cyeh from 93.153.215.26
Jan 4 17:48:06 gameservershome sshd[16686]: Invalid user cyh from 60.240.249.92
Jan 4 17:50:01 gameservershome sshd[16688]: Invalid user cyho from 67.63.223.23
Jan 4 17:52:02 gameservershome sshd[16692]: Invalid user cyku from 196.30.141.132
Jan 4 17:54:06 gameservershome sshd[16696]: Invalid user cylee from 70.104.137.12
Jan 4 17:56:08 gameservershome sshd[16699]: Invalid user cyliang from 84.40.139.54
Jan 4 17:58:05 gameservershome sshd[16752]: Invalid user cylin from 58.60.106.24
Jan 4 18:00:01 gameservershome /usr/sbin/cron[16764]: (root) CMD (perl /usr/local/awstats/wwwroot/cgi-bin/awstats.pl -config=www.entwickler-runde.de -update >> /tmp/awstatsupdate)
Jan 4 18:00:02 gameservershome sshd[16785]: Invalid user cynthia from 130.89.10.78
Jan 4 18:02:12 gameservershome sshd[16787]: Invalid user cyr from 211.115.234.143
Jan 4 18:04:06 gameservershome sshd[16798]: Invalid user cyrano from 130.89.10.78
Jan 4 18:06:11 gameservershome sshd[16801]: Invalid user cyril from 61.74.75.56
Jan 4 18:08:09 gameservershome sshd[16808]: Invalid user cyrus from 193.127.37.9
Jan 4 18:08:34 gameservershome syslog-ng[1630]: Log statistics; dropped='pipe(/dev/xconsole)=0', dropped='pipe(/dev/tty10)=0', processed='center(queued)=6542', processed='center(received)=5790', processed='destination(newsnotice)=0', processed='destination(acpid)=0', processed='destination(firewall)=3625', processed='destination(null)=0', processed='destination(mail)=782', processed='destination(mailinfo)=615', processed='destination(console)=18', processed='destination(newserr)=0', processed='destination(newscrit)=0', processed='destination(messages)=1383', processed='destination(mailwarn)=37', processed='destination(localmessages)=2', processed='destination(netmgm)=0', processed='destination(mailerr)=1', processed='destination(xconsole)=18', processed='destination(warn)=61', processed='source(src)=5790'
Jan 4 18:10:14 gameservershome sshd[16819]: Invalid user cytsao from 193.174.152.195
Jan 4 18:12:19 gameservershome sshd[16821]: Invalid user cywu from 132.230.36.60
Jan 4 18:14:20 gameservershome sshd[16848]: Invalid user d01 from 142.103.235.8
Jan 4 18:18:35 gameservershome sshd[16895]: Invalid user d03 from 87.139.25.251
Jan 4 18:20:38 gameservershome sshd[16898]: Invalid user d04 from 83.149.227.134
Jan 4 18:22:39 gameservershome sshd[16902]: Invalid user d05 from 91.90.24.250
Jan 4 18:24:50 gameservershome sshd[16907]: Invalid user daisy from 84.246.69.21
Jan 4 18:26:54 gameservershome sshd[16910]: Invalid user dak from 195.251.15.4
Jan 4 18:28:50 gameservershome named[3781]: client 193.47.99.3#36768: query (cache) 'raffael-otte.de/SOA/IN' denied
Jan 4 18:29:04 gameservershome sshd[16928]: Invalid user dale from 81.222.236.2
Jan 4 18:31:08 gameservershome sshd[16954]: Invalid user dance from 93.153.215.26
Jan 4 18:35:31 gameservershome sshd[16973]: Invalid user dance from 124.31.204.53
Jan 4 18:37:50 gameservershome sshd[16975]: reverse mapping checking getaddrinfo for static-ip-cr19014624636.cable.net.co [190.146.246.36] failed - POSSIBLE BREAK-IN ATTEMPT!
Jan 4 18:37:50 gameservershome sshd[16975]: Invalid user dance from 190.146.246.36
Jan 4 18:40:42 gameservershome named[3781]: client 213.133.105.6#54143: query (cache) 'raffael-otte.de/SOA/IN' denied
Jan 4 18:41:46 gameservershome sshd[16985]: Invalid user dance from 213.246.42.69
Jan 4 18:43:57 gameservershome sshd[16991]: Invalid user dance from 190.34.172.5
Jan 4 18:46:05 gameservershome sshd[17024]: reverse mapping checking getaddrinfo for pbc-02-servant-slave.publiccom.cz [89.235.30.186] failed - POSSIBLE BREAK-IN ATTEMPT!
Jan 4 18:46:05 gameservershome sshd[17024]: Invalid user daniel from 89.235.30.186
Jan 4 18:48:19 gameservershome sshd[17037]: Invalid user dank from 149.89.1.27
Jan 4 18:50:24 gameservershome sshd[17043]: Invalid user dar from 18.208.0.160
Jan 4 18:52:36 gameservershome sshd[17046]: Invalid user darin from 212.192.189.42
Jan 4 18:54:50 gameservershome sshd[17051]: Invalid user darren from 92.48.127.202
Jan 4 18:57:01 gameservershome sshd[17060]: Invalid user dashi from 195.80.118.50
Jan 4 18:59:11 gameservershome sshd[17069]: Invalid user daury from 69.112.187.173
Jan 4 19:00:01 gameservershome /usr/sbin/cron[17074]: (root) CMD (perl /usr/local/awstats/wwwroot/cgi-bin/awstats.pl -config=www.entwickler-runde.de -update >> /tmp/awstatsupdate)
Jan 4 19:03:37 gameservershome sshd[17098]: Invalid user davidh from 81.222.236.2
Jan 4 19:05:52 gameservershome sshd[17100]: Invalid user davidwu from 61.74.75.62
Jan 4 19:08:11 gameservershome sshd[17107]: Invalid user dawei from 217.8.61.146
Jan 4 19:08:34 gameservershome syslog-ng[1630]: Log statistics; dropped='pipe(/dev/xconsole)=0', dropped='pipe(/dev/tty10)=0', processed='center(queued)=6816', processed='center(received)=6045', processed='destination(newsnotice)=0', processed='destination(acpid)=0', processed='destination(firewall)=3825', processed='destination(null)=0', processed='destination(mail)=807', processed='destination(mailinfo)=634', processed='destination(console)=18', processed='destination(newserr)=0', processed='destination(newscrit)=0', processed='destination(messages)=1413', processed='destination(mailwarn)=37', processed='destination(localmessages)=2', processed='destination(netmgm)=0', processed='destination(mailerr)=1', processed='destination(xconsole)=18', processed='destination(warn)=61', processed='source(src)=6045'
Jan 4 19:09:31 gameservershome sshd[17111]: Invalid user test from 66.241.66.199
Jan 4 19:10:13 gameservershome sshd[17116]: Invalid user daynight from 120.132.134.130
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: renewing lease of 88.198.14.170
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: leased 88.198.14.170 for 172800 seconds
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: removing default route via 88.198.14.161 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding IP address 88.198.14.170/27
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/32 metric 0
Jan 4 19:11:23 gameservershome dhcpcd[2776]: eth0: adding route to 0.0.0.0/0 metric 0
Jan 4 19:11:23 gameservershome ifup: eth0 device: Realtek Semiconductor Co., Ltd. RTL8111/8168B PCI Express Gigabit Ethernet controller (rev 01)
Code: Select all
checking getaddrinfo for fw.tablemac.com [200.13.253.122] failed - POSSIBLE BREAK-IN ATTEMPT!
Was soll ich denn nun machen ?
Ich habe ein Komplettes Backup von Gestern von den Ordnern:
/srv/www/
/var/log
Wie sollte ich nun weiter vorgehen, was sollte ich einstellen?
Mein System ist OpenSuse 11.2