Questa mattina, proprio mentre lavoravo in remoto sul server, quarda un po' che ti vedo arrivare tra gli allarmi?
un bel tentativo di intrusione in diretta da parte di un pc in cina che sicuramente monta qualche programmino automatico che prova, per tentativi ad crackkare le password di sistema :
Jan 5 07:57:22 ts114626 sshd[25394]: message repeated 2 times: [ Failed password for root from 113.195.145.21 port 41596 ssh2]
Jan 5 07:57:22 ts114626 sshd[25394]: Received disconnect from 113.195.145.21: 11: [preauth]
Jan 5 07:57:22 ts114626 sshd[25394]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=113.195.145.21 user=root
Jan 5 07:57:31 ts114626 saslauthd[1218]: pam_unix(smtp:auth): check pass; user unknown
Jan 5 07:57:31 ts114626 saslauthd[1218]: pam_unix(smtp:auth): authentication failure; logname= uid=0 euid=0 tty= ruser= rhost=
Jan 5 07:57:33 ts114626 saslauthd[1218]: DEBUG: auth_pam: pam_authenticate failed: Authentication failure
Jan 5 07:57:33 ts114626 saslauthd[1218]: do_auth : auth failure: [user=ubuntu] [service=smtp] [realm=] [mech=pam] [reason=PAM auth error]
Jan 5 07:57:47 ts114626 sshd[25398]: reverse mapping checking getaddrinfo for 21.145.195.113.adsl-pool.jx.chinaunicom.com [113.195.145.21] failed - POSSIBLE BREAK-IN ATTEMPT!
Jan 5 07:57:48 ts114626 sshd[25398]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=113.195.145.21 user=root
Jan 5 07:57:50 ts114626 sshd[25398]: Failed password for root from 113.195.145.21 port 38139 ssh2
Jan 5 07:57:55 ts114626 sshd[25398]: message repeated 2 times: [ Failed password for root from 113.195.145.21 port 38139 ssh2]
Jan 5 07:57:55 ts114626 sshd[25398]: Received disconnect from 113.195.145.21: 11: [preauth]
Jan 5 07:57:55 ts114626 sshd[25398]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=113.195.145.21 user=root
Jan 5 07:58:16 ts114626 sshd[25409]: reverse mapping checking getaddrinfo for 21.145.195.113.adsl-pool.jx.chinaunicom.com [113.195.145.21] failed - POSSIBLE BREAK-IN ATTEMPT!
Jan 5 07:58:17 ts114626 sshd[25409]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=113.195.145.21 user=root
Jan 5 07:58:18 ts114626 sshd[25409]: Failed password for root from 113.195.145.21 port 58339 ssh2
Jan 5 07:58:23 ts114626 sshd[25409]: message repeated 2 times: [ Failed password for root from 113.195.145.21 port 58339 ssh2]
Jan 5 07:58:23 ts114626 sshd[25409]: Received disconnect from 113.195.145.21: 11: [preauth]
Jan 5 07:58:23 ts114626 sshd[25409]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=113.195.145.21 user=root
Nulla impedira` al sole di sorgere ancora, nemmeno la notte piu buia, perche` dietro alla nera cortina della notte c’e` un’alba che ci aspetta