Feb 2 22:18:31 kurlaev-netbook sshd[12252]: reverse mapping checking getaddrinfo for 121.242.15.135.static-kolkata.vsnl.net.in [121.242.15.135] failed - POSSIBLE BREAK-IN ATTEMPT!
Feb 2 22:18:31 kurlaev-netbook sshd[12252]: Invalid user oracle from 121.242.15.135
Feb 2 22:18:35 kurlaev-netbook sshd[12257]: reverse mapping checking getaddrinfo for 121.242.15.135.static-kolkata.vsnl.net.in [121.242.15.135] failed - POSSIBLE BREAK-IN ATTEMPT!
Feb 2 22:18:35 kurlaev-netbook sshd[12257]: Invalid user test from 121.242.15.135
Feb 3 03:52:48 kurlaev-netbook sshd[18604]: Did not receive identification string from 119.62.128.113
Feb 4 00:53:51 kurlaev-netbook sshd[25258]: Did not receive identification string from 202.106.212.231
Feb 4 03:06:00 kurlaev-netbook sshd[3469]: Did not receive identification string from 221.122.58.228
Feb 9 02:26:38 kurlaev-netbook sshd[3645]: Invalid user oracle from 168.126.28.24
Feb 9 02:26:40 kurlaev-netbook sshd[3651]: Invalid user test from 168.126.28.24
Feb 9 02:26:43 kurlaev-netbook sshd[3655]: Invalid user guest from 168.126.28.24
Feb 9 02:26:45 kurlaev-netbook sshd[3662]: Invalid user marta from 168.126.28.24
Feb 9 02:26:47 kurlaev-netbook sshd[3669]: Invalid user anti from 168.126.28.24
Feb 9 02:26:49 kurlaev-netbook sshd[3673]: Invalid user dragon from 168.126.28.24
Feb 9 02:26:52 kurlaev-netbook sshd[3680]: Invalid user test from 168.126.28.24
Feb 9 02:26:54 kurlaev-netbook sshd[3685]: Invalid user backup from 168.126.28.24
Feb 9 02:26:59 kurlaev-netbook sshd[3695]: Invalid user mike from 168.126.28.24
Feb 9 02:27:04 kurlaev-netbook sshd[3703]: Invalid user mythtv from 168.126.28.24
Feb 9 02:27:24 kurlaev-netbook sshd[3729]: Invalid user gnax from 168.126.28.24
Feb 9 02:27:32 kurlaev-netbook sshd[3741]: Invalid user mythtv from 168.126.28.24
Feb 9 02:27:36 kurlaev-netbook sshd[3751]: Invalid user upload from 168.126.28.24
Feb 9 02:27:38 kurlaev-netbook sshd[3759]: Invalid user status from 168.126.28.24
Feb 9 02:27:43 kurlaev-netbook sshd[3767]: Invalid user tomcat from 168.126.28.24
Feb 9 02:27:45 kurlaev-netbook sshd[3772]: Invalid user postgres from 168.126.28.24
Feb 9 02:27:48 kurlaev-netbook sshd[3777]: Invalid user anonymous from 168.126.28.24
Feb 9 02:27:50 kurlaev-netbook sshd[3782]: Invalid user worker from 168.126.28.24
Feb 9 02:27:52 kurlaev-netbook sshd[3787]: Invalid user craig from 168.126.28.24
Feb 9 02:27:54 kurlaev-netbook sshd[3792]: Invalid user webmaster from 168.126.28.24
Feb 9 02:27:57 kurlaev-netbook sshd[3796]: Invalid user user from 168.126.28.24
Feb 9 02:28:04 kurlaev-netbook sshd[3817]: Invalid user michael from 168.126.28.24
Feb 9 02:28:06 kurlaev-netbook sshd[3822]: Invalid user short from 168.126.28.24
Feb 9 02:28:09 kurlaev-netbook sshd[3828]: Invalid user admin from 168.126.28.24
Feb 9 02:28:13 kurlaev-netbook sshd[3847]: Invalid user music from 168.126.28.24
Feb 9 02:28:15 kurlaev-netbook sshd[3853]: Invalid user jessie from 168.126.28.24
Feb 9 02:28:18 kurlaev-netbook sshd[3861]: Invalid user notes from 168.126.28.24
Feb 9 02:28:20 kurlaev-netbook sshd[3868]: Invalid user turbo from 168.126.28.24
Feb 9 02:28:23 kurlaev-netbook sshd[3874]: Invalid user usuario from 168.126.28.24
Feb 9 02:28:25 kurlaev-netbook sshd[3878]: Invalid user spamfiltrer from 168.126.28.24
Feb 9 02:28:28 kurlaev-netbook sshd[3882]: Invalid user elite from 168.126.28.24
Feb 9 02:28:30 kurlaev-netbook sshd[3887]: Invalid user ftpuser from 168.126.28.24
Feb 9 02:28:32 kurlaev-netbook sshd[3891]: Invalid user radmin from 168.126.28.24
Feb 9 02:28:35 kurlaev-netbook sshd[3895]: Invalid user portal from 168.126.28.24
Feb 9 02:28:38 kurlaev-netbook sshd[3899]: Invalid user master from 168.126.28.24
Feb 9 02:28:40 kurlaev-netbook sshd[3903]: Invalid user sales from 168.126.28.24
Feb 9 02:28:42 kurlaev-netbook sshd[3907]: Invalid user util1 from 168.126.28.24
Feb 9 02:28:45 kurlaev-netbook sshd[3911]: Invalid user anthony from 168.126.28.24
Feb 10 23:00:03 kurlaev-netbook sshd[10381]: Invalid user place from 88.208.232.46
Feb 10 23:00:11 kurlaev-netbook sshd[10420]: Invalid user sky from 88.208.232.46
Feb 10 23:00:13 kurlaev-netbook sshd[10423]: Invalid user palekar from 88.208.232.46
Feb 10 23:00:19 kurlaev-netbook sshd[10437]: Invalid user vic12opq from 88.208.232.46
Feb 10 23:00:21 kurlaev-netbook sshd[10440]: Invalid user cpanel from 88.208.232.46
В общем, я, как ССЗБ, зачем-то переадресовал на роутере 22-ой порт прямо себе в нетбук и недавно обнаружил в логах вот такое вот. Начинается в логах всё 17 января, а конец вы видите. Вроде по этим же логам, пройти они не смогли.
Что это за ботнет? Троян, червь или что это? Я нмапил несколько адресов, на них всех линуксы с сш, на одном было что-то оракловское даже, ещё запомнил, что на одном нмап сказал, что ядро скорее всего 2.6.18.
И почему они не пытались тупо подобрать пароль рута?
Может как-то можно сказать админам тех серверов, чтобы безопасность улучшили?)
И зачем им таки мой нетбук? Мой ип, конечно, гуглится, в том числе на лоре. Но они что, грепают весь интернет? Или сканят все ип подряд?