PDA

توجه ! این یک نسخه آرشیو شده میباشد و در این حالت شما عکسی را مشاهده نمیکنید برای مشاهده کامل متن و عکسها بر روی لینک مقابل کلیک کنید : گزارش های Csf



1Mizban
January 26th, 2010, 11:46
سلام
یه مدت csf برام ایمل می فرسته که یعضی هاش رو نمیدونم چیه

مثلا


Time: Tue Jan 26 01:29:01 2010 -0500
PID: 4309
Account: nobody
Uptime: 602 seconds


Executable:

/usr/local/apache/bin/httpd (deleted)

The file system shows this process is running an executable file that has been deleted. This typically happens when the original file has been replaced by a new file when the application is updated. To prevent this being reported again, restart the process that runs this excecutable file. See csf.conf and the PT_DELETED text for more information about the security implications of processes running deleted executable files.


Command Line (often faked in exploits):

/usr/local/apache/bin/httpd -k start -DSSL


Network connections by the process (if any):

tcp: 0.0.0.0:80 -> 0.0.0.0:0
tcp: 0.0.0.0:443 -> 0.0.0.0:0
tcp: 74.81.165.134:80 -> 85.236.147.6:58075


Files open by the process (if any):


2 )



The following list of files have FAILED the md5sum comparison test. This means that the file has been changed in some way. This could be a result of an OS update or application upgrade. If the change is unexpected it should be investigated:

/usr/bin/php: FAILED
/usr/bin/php5: FAILED
/usr/bin/php5-cgi: FAILED
/usr/bin/php5-cli: FAILED
/usr/bin/php-cgi: FAILED
/usr/bin/php-cli: FAILED
/usr/local/bin/php: FAILED

3 )



IP: 218.75.79.18 (CN/China/-)
Failures: 5 (sshd)
Interval: 300 seconds
Blocked: Permanent Block

Log entries:

Jan 26 22:19:08 74-81-165-134 sshd[10953]: Failed password for root from 218.75.79.18 port 32881 ssh2
Jan 26 22:19:09 74-81-165-134 sshd[10955]: Failed password for root from 218.75.79.18 port 60265 ssh2
Jan 26 22:19:13 74-81-165-134 sshd[10966]: Failed password for root from 218.75.79.18 port 33084 ssh2
Jan 26 22:19:14 74-81-165-134 sshd[10970]: Failed password for root from 218.75.79.18 port 60490 ssh2
Jan 26 22:19:18 74-81-165-134 sshd[10984]: Failed password for root from 218.75.79.18 port 60732 ssh2


این رو فکر کنم بدونم ، ولی پورت SSH عوض نمیشه.

فعلا همینا
علتش چیه ؟ برای رفعش باید چی کار کرد ؟

Woshka
January 26th, 2010, 12:03
/usr/local/apache/bin/httpd (deleted)
وقتی آپاچی رو ریکامپایب میکنی فایل ها قبلی رو دیلیت میکنه میتونی بگی گزارش نده

1Mizban
January 26th, 2010, 12:52
/usr/local/apache/bin/httpd (deleted)
وقتی آپاچی رو ریکامپایب میکنی فایل ها قبلی رو دیلیت میکنه میتونی بگی گزارش نده

ممنون وشکا جان
این رو درستش کردم
این چیه


/usr/local/apache/bin/httpd -k start -DSSL

Woshka
January 26th, 2010, 13:45
/usr/local/apache/bin/httpd -k start -dssl
یعنی آپاچی داره پردازش میکنه :)

Arashdn
January 26th, 2010, 13:49
ممنون وشکا جان
این رو درستش کردم
این چیه


/usr/local/apache/bin/httpd -k start -DSSL
اینم پروسس اپاچیه

HugeServer
January 26th, 2010, 14:48
IP: 218.75.79.18 (CN/China/-)
Failures: 5 (sshd)
Interval: 300 seconds
Blocked: Permanent Block

Log entries:

Jan 26 22:19:08 74-81-165-134 sshd[10953]: Failed password for root from 218.75.79.18 port 32881 ssh2
Jan 26 22:19:09 74-81-165-134 sshd[10955]: Failed password for root from 218.75.79.18 port 60265 ssh2
Jan 26 22:19:13 74-81-165-134 sshd[10966]: Failed password for root from 218.75.79.18 port 33084 ssh2
Jan 26 22:19:14 74-81-165-134 sshd[10970]: Failed password for root from 218.75.79.18 port 60490 ssh2
Jan 26 22:19:18 74-81-165-134 sshd[10984]: Failed password for root from 218.75.79.18 port 60732 ssh2
یکی داره به سرور brute force میده
5 بار اشتب پسورد زده بن شده...;)

1Mizban
January 26th, 2010, 15:13
یکی داره به سرور brute force میده
5 بار اشتب پسورد زده بن شده...;)

آره از چینه ول کن نیست کلا چین رو بلوک کردم
نمیدونم چرا پورت ssh عوض نمیشه

Vahid
January 26th, 2010, 22:18
برای عوض کردن پورت SSH فایل زیر رو ویرایش کن و عوض کن و بعد سرویسش رو ریستارت کن


/etc/ssh/sshd_config
service ssh restart

1Mizban
January 26th, 2010, 23:11
برای عوض کردن پورت ssh فایل زیر رو ویرایش کن و عوض کن و بعد سرویسش رو ریستارت کن


service ssh restart



سلام آقا وحید
آره میدونم اینکار رو کردم ولی عوض نمیشه باز با همون پورت 22 می آد بالا ، ریبوت هم دادم

Vahid
January 26th, 2010, 23:30
توب همون فایل پروتوکول رو بکن 2

1Mizban
January 26th, 2010, 23:42
توب همون فایل پروتوکول رو بکن 2

Protocol 2
2 هستش

1Mizban
January 27th, 2010, 12:47
این یکی رو هم میدونید یعنی چی؟



**Unmatched Entries**
adjusted limit on open files from 1024 to 1048576: 1 Time(s)
found 4 CPUs, using 4 worker threads: 1 Time(s)
network unreachable resolving 'AUTH02.NS.UU.NET/AAAA/IN': 2001:dc3::35#53: 1 Time(s)
network unreachable resolving 'NS1.NIC.ir/AAAA/IN': 2001:dc3::35#53: 1 Time(s)
network unreachable resolving 'NS5.UNIVIE.AC.AT/AAAA/IN': 2001:628:453:4302::53#53: 1 Time(s)
network unreachable resolving 'NS5.UNIVIE.AC.AT/AAAA/IN': 2001:678:d::cafe#53: 1 Time(s)
network unreachable resolving 'NS5.UNIVIE.AC.AT/AAAA/IN': 2001:dc3::35#53: 1 Time(s)
network unreachable resolving 'dns1.mihannic.COM/A/IN': 2001:500:2f::f#53: 1 Time(s)
network unreachable resolving 'dns1.mihannic.COM/A/IN': 2001:dc3::35#53: 1 Time(s)
network unreachable resolving 'dns1.mihannic.COM/AAAA/IN': 2001:500:2f::f#53: 1 Time(s)
network unreachable resolving 'dns1.mihannic.COM/AAAA/IN': 2001:dc3::35#53: 1 Time(s)
network unreachable resolving 'dns1.mihannic.com/A/IN': 2001:500:3::42#53: 1 Time(s)
network unreachable resolving 'dns1.mihannic.com/A/IN': 2001:503:ba3e::2:30#53: 1 Time(s)
network unreachable resolving 'dns1.mihannic.com/AAAA/IN': 2001:500:3::42#53: 1 Time(s)
network unreachable resolving 'dns1.mihannic.com/AAAA/IN': 2001:503:ba3e::2:30#53: 1 Time(s)
network unreachable resolving 'dns2.mihannic.COM/A/IN': 2001:500:2f::f#53: 1 Time(s)
network unreachable resolving 'dns2.mihannic.COM/A/IN': 2001:dc3::35#53: 1 Time(s)
network unreachable resolving 'dns2.mihannic.COM/AAAA/IN': 2001:500:2f::f#53: 1 Time(s)
network unreachable resolving 'dns2.mihannic.COM/AAAA/IN': 2001:dc3::35#53: 1 Time(s)
network unreachable resolving 'dns2.mihannic.com/A/IN': 2001:500:3::42#53: 1 Time(s)
network unreachable resolving 'dns2.mihannic.com/AAAA/IN': 2001:500:3::42#53: 1 Time(s)
network unreachable resolving 'ns2.mehrnet.ir/A/IN': 2001:500:2f::f#53: 1 Time(s)
network unreachable resolving 'ns2.mehrnet.ir/A/IN': 2001:503:c27::2:30#53: 1 Time(s)
network unreachable resolving 'ns2.mehrnet.ir/AAAA/IN': 2001:500:2f::f#53: 1 Time(s)
network unreachable resolving 'ns2.mehrnet.ir/AAAA/IN': 2001:503:c27::2:30#53: 1 Time(s)
the working directory is not writable: 25 Time(s)
using default UDP/IPv4 port range: [1024, 65535]: 25 Time(s)
using default UDP/IPv6 port range: [1024, 65535]: 25 Time(s)
using up to 4096 sockets: 1 Time(s)
zone arakshopping.com/IN/external: zone serial unchanged: 3 Time(s)
zone arakshopping.com/IN/internal: zone serial unchanged: 3 Time(s)
zone jfjghjfhgdfjg.cim/IN/external: zone serial unchanged: 3 Time(s)
zone jfjghjfhgdfjg.cim/IN/internal: zone serial unchanged: 3 Time(s)
zone pandashop2.com/IN/external: zone serial unchanged: 3 Time(s)
zone pandashop2.com/IN/internal: zone serial unchanged: 3 Time(s)

Arashdn
January 27th, 2010, 14:05
سرور مجازیه؟

HugeServer
January 27th, 2010, 14:17
نه خیر ایشون dedicated n دارند...:)

1Mizban
January 27th, 2010, 16:17
سرور مجازیه؟

سلام
Ded هستش ، فرق داره ؟