• 请不要在回答技术问题时复制粘贴 AI 生成的内容
diveIntoWork
V2EX  ›  程序员

阿里云登录日志有未知 ip,很奇怪

  •  
  •   diveIntoWork · Apr 8, 2018 · 4311 views
    This topic created in 2981 days ago, the information mentioned may be changed or developed.

    root@master:~# last

    root pts/0 124.16.137.xxx Sun Apr 8 15:21 still logged in

    root pts/0 180.76.50.99 Wed Apr 4 10:13 - 10:13 (00:00)

    root pts/2 180.76.50.99 Wed Apr 4 10:01 - 10:01 (00:00)

    root pts/2 180.76.50.99 Wed Apr 4 09:42 - 09:42 (00:00)

    root pts/1 124.16.137.xxx Wed Apr 4 09:34 - 12:09 (02:35)

    root pts/1 180.76.50.99 Wed Apr 4 09:24 - 09:24 (00:00)

    root pts/1 180.76.50.99 Wed Apr 4 09:21 - 09:21 (00:00)

    root pts/1 180.76.50.99 Wed Apr 4 09:18 - 09:18 (00:00)

    除了我自己的本机 ip 外,一直有个 180.76.50.99 的 ip 登录,而且也是秒登秒下,查了一下是海淀百度的 ip。检查了一下集群,crontab 里也没有异常,不过最近阿里云倒经常发短信提醒主机被扫描。 有大神分析一波吗?

    19 replies    2018-04-09 13:15:51 +08:00
    udev
        1
    udev  
       Apr 8, 2018
    阿里云盾卸载了吗?
    diveIntoWork
        2
    diveIntoWork  
    OP
       Apr 8, 2018
    @udev 好像没装这项服务
    harwck
        3
    harwck  
       Apr 8, 2018 via iPhone
    密钥登陆搞了吗?密码登录关了吗?
    mokeyjay
        4
    mokeyjay  
       Apr 8, 2018
    @diveIntoWork #2 这是预装的
    niubee1
        5
    niubee1  
       Apr 8, 2018
    很显然有人在企图搞你, follow #3 楼的步骤加固一下
    diveIntoWork
        6
    diveIntoWork  
    OP
       Apr 8, 2018
    @harwck ssh 配了免密登录,密码登录没有关
    diveIntoWork
        7
    diveIntoWork  
    OP
       Apr 8, 2018
    @niubee1 我觉得被扫描挺正常,需不需要把 sshd 的 22 端口换一下?或者无视,暴力破解应该也没那么容易
    hcymk2
        8
    hcymk2  
       Apr 8, 2018
    http://180.76.50.99:8888/login
    这什么鬼?
    yexm0
        9
    yexm0  
       Apr 8, 2018 via iPhone
    @hcymk2 百度在搞黑产吧
    f2f2f
        10
    f2f2f  
       Apr 8, 2018
    @yexm0 这网址进去明显是装的宝塔面板然后换了标题……
    diveIntoWork
        11
    diveIntoWork  
    OP
       Apr 8, 2018
    @hcymk2 wtf,有点意思了,为什么查出来是百度的 ip 呢
    fengyj
        12
    fengyj  
       Apr 8, 2018 via Android
    @f2f2f 还真是,点下忘了密码,跳转到 bt.cn😂🤣
    wekw
        13
    wekw  
       Apr 8, 2018
    确认过日志,你被黑了,重装吧
    Tink
        14
    Tink  
    PRO
       Apr 8, 2018
    被黑了
    labxx
        15
    labxx  
       Apr 8, 2018
    被人搞了
    wspsxing
        16
    wspsxing  
       Apr 8, 2018
    我 TM 6 号才上车,禁止了 root 登录,而且根本没有 admin。。太可怕
    ```sh
    ~> sudo lastb
    admin ssh:notty 113.172.191.116 Sun Apr 8 05:48 - 05:48 (00:00)
    admin ssh:notty 113.172.191.116 Sun Apr 8 05:48 - 05:48 (00:00)
    admin ssh:notty 123.118.206.182 Sun Apr 8 05:48 - 05:48 (00:00)
    admin ssh:notty 123.118.206.182 Sun Apr 8 05:48 - 05:48 (00:00)
    admin ssh:notty 171.5.36.149 Sun Apr 8 05:47 - 05:47 (00:00)
    admin ssh:notty 171.5.36.149 Sun Apr 8 05:47 - 05:47 (00:00)
    admin ssh:notty 163.172.190.197 Sat Apr 7 19:59 - 19:59 (00:00)
    admin ssh:notty 163.172.190.197 Sat Apr 7 19:59 - 19:59 (00:00)
    root ssh:notty 163.172.190.197 Sat Apr 7 19:59 - 19:59 (00:00)
    admin ssh:notty 190.167.110.213 Sat Apr 7 17:31 - 17:31 (00:00)
    admin ssh:notty 190.167.110.213 Sat Apr 7 17:31 - 17:31 (00:00)
    admin ssh:notty 14.161.42.248 Sat Apr 7 17:31 - 17:31 (00:00)
    admin ssh:notty 14.161.42.248 Sat Apr 7 17:31 - 17:31 (00:00)
    admin ssh:notty 116.101.151.71 Sat Apr 7 17:31 - 17:31 (00:00)
    admin ssh:notty 116.101.151.71 Sat Apr 7 17:31 - 17:31 (00:00)
    admin ssh:notty 202.125.167.187 Sat Apr 7 04:59 - 04:59 (00:00)
    admin ssh:notty 202.125.167.187 Sat Apr 7 04:59 - 04:59 (00:00)
    root ssh:notty 202.125.167.187 Sat Apr 7 04:59 - 04:59 (00:00)
    admin ssh:notty 217.182.252.114 Sat Apr 7 01:18 - 01:18 (00:00)
    admin ssh:notty 217.182.252.114 Sat Apr 7 01:18 - 01:18 (00:00)
    ```
    projectzoo
        17
    projectzoo  
       Apr 8, 2018
    吓得我赶紧看一下我的机器去。
    king2014
        18
    king2014  
       Apr 9, 2018 via Android
    第一件事情更换 ssh 端口,第二件事情密钥登录,第三件事情关闭密码登录,第四件事情禁止 root 登录,这个流程走一遍试试
    opengps
        19
    opengps  
       Apr 9, 2018 via Android
    换非常规端口是必然要做的,一大堆自动扫描器,扫到后就开始暴力破解
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   2641 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 53ms · UTC 11:50 · PVG 19:50 · LAX 04:50 · JFK 07:50
    ♥ Do have faith in what you're doing.