以下の意味するところはSSHと言う暗号化プロトコルを利用して
リモートコンピューターからあてずっぽうなユーザー名とパスワードを繰り返し入力し
何とか侵入できないかと試みた痕です。かなりしつこいよ〜!
--------------------- SSHD Begin ------------------------
Failed logins from these:
amanda/password from 210.127.243.140: 5 Time(s)
**Unmatched Entries**
Illegal user octavius from 210.127.243.140
Illegal user octavius from 210.127.243.140
Illegal user octavius from 210.127.243.140
Illegal user octavius from 210.127.243.140
Illegal user octavius from 210.127.243.140
Illegal user octavian from 210.127.243.140
Illegal user octavian from 210.127.243.140
Illegal user octavian from 210.127.243.140
Illegal user octavian from 210.127.243.140
Illegal user octavian from 210.127.243.140
Illegal user olaf from 210.127.243.140
Illegal user olaf from 210.127.243.140
Illegal user olaf from 210.127.243.140
Illegal user olaf from 210.127.243.140
Illegal user olaf from 210.127.243.140
Illegal user ole from 210.127.243.140
Illegal user ole from 210.127.243.140
Illegal user ole from 210.127.243.140
Illegal user ole from 210.127.243.140
Illegal user ole from 210.127.243.140
・・・(中略)・・・
Illegal user vanda from 210.127.243.140
Illegal user vanda from 210.127.243.140
Illegal user vanda from 210.127.243.140
Illegal user vanda from 210.127.243.140
Illegal user vanda from 210.127.243.140
Illegal user julian from 210.127.243.140
Illegal user julian from 210.127.243.140
Illegal user julian from 210.127.243.140
Illegal user julian from 210.127.243.140
Illegal user julian from 210.127.243.140
Illegal user romeo from 210.127.243.140
Illegal user romeo from 210.127.243.140
Illegal user romeo from 210.127.243.140
Illegal user romeo from 210.127.243.140
Illegal user romeo from 210.127.243.140
Illegal user service from 210.127.243.140
Illegal user service from 210.127.243.140
Illegal user service from 210.127.243.140
Illegal user service from 210.127.243.140
Illegal user service from 210.127.243.140
Illegal user card from 210.127.243.140
Illegal user card from 210.127.243.140
Illegal user card from 210.127.243.140
Illegal user card from 210.127.243.140
Illegal user card from 210.127.243.140
Illegal user welcome from 210.127.243.140
---------------------- SSHD End -------------------------
なんと同じIPアドレス(同一人物)から
約1400回の不正な試みが秒間2回のペースであったようです。
もちろん人間にそんな早業は出来ませんからハッキングツール(不正な試みを助けるプログラム)
を使ったんでしょうがこんなにしつこいのは初めて!
ネットワークの管理者に苦情のメールをしてやろうかと思い
Whoisネットワークに問い合わせをしてみたら
----------------------------------------------------
ReferralServer: whois://whois.apnic.net
NetRange: 210.0.0.0 - 211.255.255.255
CIDR: 210.0.0.0/7
NetName: APNIC-CIDR-BLK2
NetHandle: NET-210-0-0-0-1
Parent:
NetType: Allocated to APNIC
NameServer: NS1.APNIC.NET
NameServer: NS3.APNIC.NET
NameServer: NS4.APNIC.NET
NameServer: NS.RIPE.NET
NameServer: TINNIE.ARIN.NET
NameServer: DNS1.TELSTRA.NET
Comment: This IP address range is not registered in the ARIN database.
Comment: For details, refer to the APNIC Whois Database via
Comment: WHOIS.APNIC.NET or http://www.apnic.net/apnic-bin/whois2.pl
Comment: ** IMPORTANT NOTE: APNIC is the Regional Internet Registry
Comment: for the Asia Pacific region. APNIC does not operate networks
Comment: using this IP address range and is not able to investigate
Comment: spam or abuse reports relating to these addresses. For more
Comment: help, refer to http://www.apnic.net/info/faq/abuse
Comment:
RegDate: 1996-07-01
Updated: 2004-03-30
OrgTechHandle: AWC12-ARIN
OrgTechName: APNIC Whois Contact
OrgTechPhone: +61 7 3858 3100
OrgTechEmail: search-apnic-not-arin@apnic.net
# ARIN WHOIS database, last updated 2005-02-26 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
----------------------------------------------------
要約するとこのIPアドレスはアジア太平洋地域のものではあるが
現在のところ登録されていないアドレスであり偽装されたものであろうということだ。
うーん、プロキシサーバー経由ならその管理者に文句も言えるが
これでは誰に苦情を言って良いのやら?
どうしても嫌なら[ 210.0.0.0 - 211.255.255.255 ]のネットレンジのIPを
iptable(ファイヤーウォール)ではじくしかないのか〜・・・
なんかやられっぱなしで腹が立つな〜(▼▼)
まぁ今回のような数撃ちゃ当たる!?みたいな攻撃(ブルートフォースアタックと言う)が
通用するようなユーザー名とパスワードは使ってないから良いんだけどね。