FB_security 板


I'm seeing the same thing in my log. It makes me think it is a virus because test, guest, and admin are not normal unix users. Jul 17 04:14:13 newman sshd[2630]: Illegal user test from 129.194.21.5 Jul 17 04:14:14 newman sshd[2632]: Illegal user guest from 129.194.21.5 Jul 24 19:29:26 newman sshd[43831]: Illegal user test from 69.0.134.72 Jul 24 19:29:26 newman sshd[43838]: Illegal user guest from 69.0.134.72 Jul 24 19:29:27 newman sshd[43840]: Illegal user admin from 69.0.134.72 Jul 24 19:29:27 newman sshd[43842]: Illegal user admin from 69.0.134.72 Jul 24 19:29:27 newman sshd[43844]: Illegal user user from 69.0.134.72 Jul 24 19:29:33 newman sshd[43853]: Illegal user test from 69.0.134.72 Jul 24 21:17:05 newman sshd[45031]: Illegal user test from 202.6.75.195 Jul 24 21:17:07 newman sshd[45033]: Illegal user guest from 202.6.75.195 Jul 25 02:04:17 newman sshd[34873]: Illegal user test from 211.202.3.148 Jul 25 02:04:19 newman sshd[34875]: Illegal user guest from 211.202.3.148 Jul 28 12:09:17 newman sshd[16613]: Illegal user test from 65.61.98.16 Jul 28 12:09:18 newman sshd[16615]: Illegal user guest from 65.61.98.16 Jul 31 08:18:09 newman sshd[98113]: Illegal user test from 65.194.200.129 Jul 31 08:18:10 newman sshd[98116]: Illegal user guest from 65.194.200.129 Aug 1 22:47:50 newman sshd[1520]: Illegal user test from 202.114.73.4 Aug 1 22:47:53 newman sshd[1522]: Illegal user guest from 202.114.73.4 Aug 4 21:09:11 newman sshd[39267]: Illegal user test from 218.38.216.168 Aug 4 21:09:13 newman sshd[39269]: Illegal user guest from 218.38.216.168 Aug 7 13:53:00 newman sshd[15889]: Illegal user test from 64.246.20.43 Aug 7 13:53:00 newman sshd[15891]: Illegal user guest from 64.246.20.43 Aug 7 13:53:01 newman sshd[15893]: Illegal user admin from 64.246.20.43 Aug 7 14:00:37 newman sshd[15970]: Illegal user test from 64.246.20.43 Aug 7 14:00:38 newman sshd[15972]: Illegal user guest from 64.246.20.43 Aug 7 14:00:39 newman sshd[15974]: Illegal user admin from 64.246.20.43 Aug 7 14:00:40 newman sshd[15976]: Illegal user admin from 64.246.20.43 Aug 7 14:00:41 newman sshd[15978]: Illegal user user from 64.246.20.43 Aug 7 14:00:44 newman sshd[15986]: Illegal user test from 64.246.20.43 Aug 8 06:48:05 newman sshd[51656]: Illegal user test from 64.151.89.172 Aug 8 06:48:06 newman sshd[51658]: Illegal user guest from 64.151.89.172 Aug 8 06:48:07 newman sshd[51660]: Illegal user admin from 64.151.89.172 Aug 8 06:48:08 newman sshd[51662]: Illegal user admin from 64.151.89.172 Aug 8 06:48:08 newman sshd[51664]: Illegal user user from 64.151.89.172 Aug 8 06:48:12 newman sshd[51672]: Illegal user test from 64.151.89.172 Aug 9 09:33:57 newman sshd[9346]: Illegal user test from 211.241.101.137 Aug 9 09:33:59 newman sshd[9348]: Illegal user guest from 211.241.101.137 Aug 9 09:34:01 newman sshd[9350]: Illegal user admin from 211.241.101.137 Aug 9 09:34:03 newman sshd[9352]: Illegal user admin from 211.241.101.137 Aug 9 09:34:04 newman sshd[9354]: Illegal user user from 211.241.101.137 Aug 9 09:34:13 newman sshd[9362]: Illegal user test from 211.241.101.137 Aug 9 15:54:37 newman sshd[11782]: Illegal user test from 80.64.104.66 Aug 9 15:54:39 newman sshd[11784]: Illegal user guest from 80.64.104.66 Aug 9 15:54:41 newman sshd[11786]: Illegal user admin from 80.64.104.66 Aug 9 15:54:43 newman sshd[11788]: Illegal user admin from 80.64.104.66 Aug 9 15:54:44 newman sshd[11790]: Illegal user user from 80.64.104.66 Aug 9 15:54:51 newman sshd[11798]: Illegal user test from 80.64.104.66 Aug 10 12:24:14 newman sshd[1392]: Illegal user test from 200.155.22.22 Aug 10 12:32:33 newman sshd[11361]: Illegal user test from 200.155.22.22 Aug 10 12:32:35 newman sshd[11364]: Illegal user guest from 200.155.22.22 Aug 10 12:32:37 newman sshd[11370]: Illegal user admin from 200.155.22.22 Aug 10 12:32:40 newman sshd[11372]: Illegal user admin from 200.155.22.22 Aug 10 12:32:42 newman sshd[11375]: Illegal user user from 200.155.22.22 Aug 10 12:32:51 newman sshd[11399]: Illegal user test from 200.155.22.22 Aug 10 20:22:59 newman sshd[1808]: Illegal user test from 63.251.144.88 Aug 16 04:41:53 newman sshd[31175]: Illegal user test from 210.223.178.180 Aug 16 04:41:54 newman sshd[31177]: Illegal user guest from 210.223.178.180 Aug 16 04:41:56 newman sshd[31179]: Illegal user admin from 210.223.178.180 Aug 16 04:41:58 newman sshd[31181]: Illegal user admin from 210.223.178.180 Aug 16 04:42:00 newman sshd[31183]: Illegal user user from 210.223.178.180 Aug 16 04:42:08 newman sshd[31191]: Illegal user test from 210.223.178.180 Aug 17 01:28:42 newman sshd[1507]: Illegal user test from 64.62.182.146 Aug 17 01:28:42 newman sshd[1509]: Illegal user guest from 64.62.182.146 Aug 17 01:28:43 newman sshd[1511]: Illegal user admin from 64.62.182.146 Aug 17 01:28:44 newman sshd[1513]: Illegal user admin from 64.62.182.146 Aug 17 01:28:45 newman sshd[1515]: Illegal user user from 64.62.182.146 Aug 17 01:28:48 newman sshd[1523]: Illegal user test from 64.62.182.146 On Friday 13 August 2004 09:05 am, Sandor Berta wrote: > Hi all, > I found similar sequences in the > /var/auth.log files of freebsd boxes, I supervise.: > Aug 13 13:56:08 www sshd[26091]: Illegal user test from 165.21.103.20 > Aug 13 13:56:11 www sshd[26093]: Illegal user guest from 165.21.103.20 > Aug 13 13:56:15 www sshd[26096]: Illegal user admin from 165.21.103.20 > Aug 13 13:56:18 www sshd[26103]: Illegal user admin from 165.21.103.20 > Aug 13 13:56:21 www sshd[26105]: Illegal user user from 165.21.103.20 > Aug 13 13:56:25 www sshd[26107]: Failed password for root from > 165.21.103.20 port 39678 ssh2 > Aug 13 13:56:28 www sshd[26109]: Failed password for root from > 165.21.103.20 port 39760 ssh2 > Aug 13 13:56:32 www sshd[26111]: Failed password for root from > 165.21.103.20 port 39836 ssh2 > Aug 13 13:56:35 www sshd[26113]: Illegal user test from 165.21.103.20 > Aug 13 14:25:36 www sshd[26485]: Illegal user test from 202.28.120.57 > Aug 13 14:25:41 www sshd[26487]: Illegal user guest from 202.28.120.57 > > What are these? > > bye > Sandor Berta > > _______________________________________________ > [email protected] mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to "[email protected]" _______________________________________________ [email protected] mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "[email protected]"







like.gif 您可能会有兴趣的文章
icon.png[问题/行为] 猫晚上进房间会不会有憋尿问题
icon.pngRe: [闲聊] 选了错误的女孩成为魔法少女 XDDDDDDDDDD
icon.png[正妹] 瑞典 一张
icon.png[心得] EMS高领长版毛衣.墨小楼MC1002
icon.png[分享] 丹龙隔热纸GE55+33+22
icon.png[问题] 清洗洗衣机
icon.png[寻物] 窗台下的空间
icon.png[闲聊] 双极の女神1 木魔爵
icon.png[售车] 新竹 1997 march 1297cc 白色 四门
icon.png[讨论] 能从照片感受到摄影者心情吗
icon.png[狂贺] 贺贺贺贺 贺!岛村卯月!总选举NO.1
icon.png[难过] 羡慕白皮肤的女生
icon.png阅读文章
icon.png[黑特]
icon.png[问题] SBK S1安装於安全帽位置
icon.png[分享] 旧woo100绝版开箱!!
icon.pngRe: [无言] 关於小包卫生纸
icon.png[开箱] E5-2683V3 RX480Strix 快睿C1 简单测试
icon.png[心得] 苍の海贼龙 地狱 执行者16PT
icon.png[售车] 1999年Virage iO 1.8EXi
icon.png[心得] 挑战33 LV10 狮子座pt solo
icon.png[闲聊] 手把手教你不被桶之新手主购教学
icon.png[分享] Civic Type R 量产版官方照无预警流出
icon.png[售车] Golf 4 2.0 银色 自排
icon.png[出售] Graco提篮汽座(有底座)2000元诚可议
icon.png[问题] 请问补牙材质掉了还能再补吗?(台中半年内
icon.png[问题] 44th 单曲 生写竟然都给重复的啊啊!
icon.png[心得] 华南红卡/icash 核卡
icon.png[问题] 拔牙矫正这样正常吗
icon.png[赠送] 老莫高业 初业 102年版
icon.png[情报] 三大行动支付 本季掀战火
icon.png[宝宝] 博客来Amos水蜡笔5/1特价五折
icon.pngRe: [心得] 新鲜人一些面试分享
icon.png[心得] 苍の海贼龙 地狱 麒麟25PT
icon.pngRe: [闲聊] (君の名は。雷慎入) 君名二创漫画翻译
icon.pngRe: [闲聊] OGN中场影片:失踪人口局 (英文字幕)
icon.png[问题] 台湾大哥大4G讯号差
icon.png[出售] [全国]全新千寻侘草LED灯, 水草
伺服器连线错误,造成您的不便还请多多包涵!
「赞助商连结」






like.gif 您可能会有兴趣的文章
icon.png[问题/行为] 猫晚上进房间会不会有憋尿问题
icon.pngRe: [闲聊] 选了错误的女孩成为魔法少女 XDDDDDDDDDD
icon.png[正妹] 瑞典 一张
icon.png[心得] EMS高领长版毛衣.墨小楼MC1002
icon.png[分享] 丹龙隔热纸GE55+33+22
icon.png[问题] 清洗洗衣机
icon.png[寻物] 窗台下的空间
icon.png[闲聊] 双极の女神1 木魔爵
icon.png[售车] 新竹 1997 march 1297cc 白色 四门
icon.png[讨论] 能从照片感受到摄影者心情吗
icon.png[狂贺] 贺贺贺贺 贺!岛村卯月!总选举NO.1
icon.png[难过] 羡慕白皮肤的女生
icon.png阅读文章
icon.png[黑特]
icon.png[问题] SBK S1安装於安全帽位置
icon.png[分享] 旧woo100绝版开箱!!
icon.pngRe: [无言] 关於小包卫生纸
icon.png[开箱] E5-2683V3 RX480Strix 快睿C1 简单测试
icon.png[心得] 苍の海贼龙 地狱 执行者16PT
icon.png[售车] 1999年Virage iO 1.8EXi
icon.png[心得] 挑战33 LV10 狮子座pt solo
icon.png[闲聊] 手把手教你不被桶之新手主购教学
icon.png[分享] Civic Type R 量产版官方照无预警流出
icon.png[售车] Golf 4 2.0 银色 自排
icon.png[出售] Graco提篮汽座(有底座)2000元诚可议
icon.png[问题] 请问补牙材质掉了还能再补吗?(台中半年内
icon.png[问题] 44th 单曲 生写竟然都给重复的啊啊!
icon.png[心得] 华南红卡/icash 核卡
icon.png[问题] 拔牙矫正这样正常吗
icon.png[赠送] 老莫高业 初业 102年版
icon.png[情报] 三大行动支付 本季掀战火
icon.png[宝宝] 博客来Amos水蜡笔5/1特价五折
icon.pngRe: [心得] 新鲜人一些面试分享
icon.png[心得] 苍の海贼龙 地狱 麒麟25PT
icon.pngRe: [闲聊] (君の名は。雷慎入) 君名二创漫画翻译
icon.pngRe: [闲聊] OGN中场影片:失踪人口局 (英文字幕)
icon.png[问题] 台湾大哥大4G讯号差
icon.png[出售] [全国]全新千寻侘草LED灯, 水草

请输入看板名称,例如:Tech_Job站内搜寻

TOP