
jackl007
Eta
Programador
Verificación en dos pasos activada
Hola amigos, resulta que hace unos meses mi servidor VPS estuvo compremetido en un ataque de Phishing y me lo habían cerrado. Luego de demostrar que yo no tenia nada que ver me volvieron a activar el VPS y todo quedó ahí. Como diablos fue mi VPS comprometido? pues alguien entró como root a mi VPS y lo modificó a su conveniencia. Yo pense que me habían robado la clave desde mi Pc, cambié todas las claves y lo deje ahí.
Mi servidor VPS anda consumiendo recursos y tenia sospechas de que me estaban atacando DDOS, e investigando encontré también una forma de protegerte de ataques de fuerza bruta y publicaron vi este comando:
Me quede impresionado al ver esto (voy a poner un fragmento porque es inmenso el archivo):
Cientos de intentos de conexión fallados diariamente, pues por FUERZA BRUTA están intentando obtener mi clave de mi VPS.
Entre los ultimos 4 dias tengo 6 IPs distintas que buscan obtener mi usuario.
Ahora he instalado el famoso programita: DenyHosts, el cual examina esos logs y bloquea las IPS que quieren conectarse al VPS.
Les recomiendo que instalen el DenyHosts y eviten que alguien les robe la clave, a mi me decifraron una clave de 10 dígitos con numeros y letras, seguro habrán tardado varios días en probar los cientos de miles de combinaciones hasta que la encontraron.
Espero que les sea de ayuda a los que tienen un VPS unmanagment como yo ...
Mi servidor VPS anda consumiendo recursos y tenia sospechas de que me estaban atacando DDOS, e investigando encontré también una forma de protegerte de ataques de fuerza bruta y publicaron vi este comando:
Insertar CODE, HTML o PHP:
grep sshd /var/log/messages
Me quede impresionado al ver esto (voy a poner un fragmento porque es inmenso el archivo):
Insertar CODE, HTML o PHP:
Oct 15 14:59:13 doxserver sshd[3409]: Failed password for root from 122.96.148.114 port 53356 ssh2
Oct 15 20:59:13 doxserver sshd[3411]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 20:59:13 doxserver sshd[3410]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:15 doxserver sshd[3412]: Failed password for root from 122.96.148.114 port 53438 ssh2
Oct 15 14:59:15 doxserver sshd[3413]: Failed password for root from 122.96.148.114 port 53435 ssh2
Oct 15 20:59:15 doxserver sshd[3414]: Received disconnect from 122.96.148.114: 11: Bye Bye
...
Oct 15 14:59:19 doxserver sshd[3418]: Failed password for root from 122.96.148.114 port 53648 ssh2
Oct 15 20:59:19 doxserver sshd[3419]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:21 doxserver sshd[3420]: Failed password for root from 122.96.148.114 port 53767 ssh2
Oct 15 20:59:21 doxserver sshd[3421]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:22 doxserver sshd[3422]: Failed password for root from 122.96.148.114 port 53854 ssh2
Oct 15 20:59:23 doxserver sshd[3423]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:24 doxserver sshd[3424]: Failed password for root from 122.96.148.114 port 53975 ssh2
Oct 15 20:59:24 doxserver sshd[3425]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:26 doxserver sshd[3426]: Failed password for root from 122.96.148.114 port 54060 ssh2
Oct 15 20:59:26 doxserver sshd[3427]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:28 doxserver sshd[3428]: Failed password for bin from 122.96.148.114 port 54171 ssh2
Oct 15 20:59:28 doxserver sshd[3430]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:30 doxserver sshd[3431]: Failed password for root from 122.96.148.114 port 54278 ssh2
Oct 15 20:59:30 doxserver sshd[3432]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:32 doxserver sshd[3433]: Failed password for root from 122.96.148.114 port 54400 ssh2
Oct 15 20:59:32 doxserver sshd[3434]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:34 doxserver sshd[3435]: Failed password for root from 122.96.148.114 port 54502 ssh2
Oct 15 20:59:34 doxserver sshd[3436]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:36 doxserver sshd[3437]: Failed password for root from 122.96.148.114 port 54665 ssh2
Oct 15 20:59:36 doxserver sshd[3438]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:37 doxserver sshd[3439]: Failed password for root from 122.96.148.114 port 54784 ssh2
Oct 15 20:59:38 doxserver sshd[3440]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:39 doxserver sshd[3442]: Invalid user msr from 122.96.148.114
Oct 15 20:59:39 doxserver sshd[3443]: input_userauth_request: invalid user msr
Oct 15 14:59:39 doxserver sshd[3442]: error: Could not get shadow information for NOUSER
Oct 15 14:59:39 doxserver sshd[3442]: Failed password for invalid user msr from 122.96.148.114 port 54944 ssh2
...
Oct 15 20:59:41 doxserver sshd[3449]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:43 doxserver sshd[3451]: Failed password for root from 122.96.148.114 port 55192 ssh2
Oct 15 20:59:43 doxserver sshd[3452]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:45 doxserver sshd[3456]: Failed password for root from 122.96.148.114 port 55268 ssh2
Oct 15 20:59:45 doxserver sshd[3457]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:47 doxserver sshd[3458]: Failed password for root from 122.96.148.114 port 55394 ssh2
Oct 15 20:59:47 doxserver sshd[3459]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:49 doxserver sshd[3460]: Failed password for root from 122.96.148.114 port 55470 ssh2
Oct 15 20:59:49 doxserver sshd[3462]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:51 doxserver sshd[3463]: Failed password for root from 122.96.148.114 port 55590 ssh2
Oct 15 20:59:51 doxserver sshd[3464]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:52 doxserver sshd[3466]: Failed password for root from 122.96.148.114 port 55673 ssh2
Oct 15 20:59:53 doxserver sshd[3467]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 14:59:54 doxserver sshd[3468]: Failed password for root from 122.96.148.114 port 55799 ssh2
...
Oct 15 15:00:02 doxserver sshd[3478]: Failed password for bin from 122.96.148.114 port 56217 ssh2
Oct 15 21:00:02 doxserver sshd[3479]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 15:00:04 doxserver sshd[3480]: Failed password for root from 122.96.148.114 port 56295 ssh2
Oct 15 21:00:04 doxserver sshd[3481]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 15:00:06 doxserver sshd[3482]: Failed password for root from 122.96.148.114 port 56426 ssh2
Oct 15 21:00:06 doxserver sshd[3483]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 15:00:07 doxserver sshd[3486]: Failed password for root from 122.96.148.114 port 56502 ssh2
Oct 15 21:00:08 doxserver sshd[3487]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 15:00:09 doxserver sshd[3489]: Failed password for root from 122.96.148.114 port 56592 ssh2
Oct 15 21:00:10 doxserver sshd[3490]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 15:00:11 doxserver sshd[3491]: Failed password for root from 122.96.148.114 port 56709 ssh2
Oct 15 21:00:11 doxserver sshd[3492]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 15:00:13 doxserver sshd[3493]: Failed password for root from 122.96.148.114 port 56800 ssh2
Oct 15 21:00:13 doxserver sshd[3494]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 15:00:15 doxserver sshd[3495]: Failed password for root from 122.96.148.114 port 56914 ssh2
Oct 15 21:00:15 doxserver sshd[3496]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 15:00:17 doxserver sshd[3497]: Failed password for bin from 122.96.148.114 port 56981 ssh2
Oct 15 21:00:17 doxserver sshd[3498]: Received disconnect from 122.96.148.114: 11: Bye Bye
Oct 15 15:00:17 doxserver sshd[3501]: refused connect from 122.96.148.114 (122.96.148.114)
Oct 15 15:00:54 doxserver sshd[3535]: Did not receive identification string from 79.174.218.234
Oct 15 15:00:54 doxserver sshd[3536]: Did not receive identification string from 79.174.218.234
Cientos de intentos de conexión fallados diariamente, pues por FUERZA BRUTA están intentando obtener mi clave de mi VPS.
Entre los ultimos 4 dias tengo 6 IPs distintas que buscan obtener mi usuario.
Ahora he instalado el famoso programita: DenyHosts, el cual examina esos logs y bloquea las IPS que quieren conectarse al VPS.
Les recomiendo que instalen el DenyHosts y eviten que alguien les robe la clave, a mi me decifraron una clave de 10 dígitos con numeros y letras, seguro habrán tardado varios días en probar los cientos de miles de combinaciones hasta que la encontraron.
Espero que les sea de ayuda a los que tienen un VPS unmanagment como yo ...