找回密码
 立即注册
CeraNetworksBGVM服务器主机交流会员请立即修改密码Sharktech防护
查看: 579|回复: 9

softlayer 被投诉,ip已经被停用,怎么办?

[复制链接]

3

主题

5

回帖

21

积分

新手上路

积分
21
发表于 2010-8-18 19:49:56 | 显示全部楼层 |阅读模式
真是搞不懂,怎么说我的服务器在攻击别人的站呢?被投诉了,还列举了一大堆的证据!怎么回事啊?要怎么解决啊?找softlayer技术,他说他们没法解决!晕死了




大家帮忙看看,这只是其中一点点东西:

Ticket Contents:

   Employee Response - 2010-Aug-09 10:23 (GMT-0600) [Update 1]
  SoftLayer Security has received the following HACKING / MALICIOUS ACTIVITY complaint in reference to an IP hosted on your server. A copy of the complaint is listed below or attached to this ticket for your review. Please disable or remove this activity immediately as it is direct abuse of the network services and a violation of your TOS and AUP. Failure to resolve this issue in an expeditious manner could lead to service interruption for this server. Please update this ticket with resolution to this issue. We thank you in advance for your quick action and cooperation.

Regards,
SoftLayer Security Team


Please rate this response
  
Worst             Best
  1 2 3 4 5   

  

Employee Response - 2010-Aug-09 10:23 (GMT-0600) [Update 2]
  Looks like your customer with IP 67.228.94.234 is doing ssh attacks to my server.
Please take care about
Best Regards

here some logfile output Date
Mon Aug 9 11:45:02 CEST 2010
Aug 9 00:43:44 81-89-97-101 sshd[11971]: Invalid user alyssa from 67.228.94.234 Aug 9 00:43:44 81-89-97-101 sshd[11971]: error: PAM: User not known to the underlying authentication module for illegal user alyssa from 67.228.94.234-static.reverse.softlayer.com
Aug 9 00:43:44 81-89-97-101 sshd[11971]: Failed keyboard-interactive/pam for invalid user alyssa from 67.228.94.234 port 39379 ssh2 Aug 9 02:39:00 81-89-97-101 sshd[13874]: Invalid user ann from 67.228.94.234 Aug 9 02:39:00 81-89-97-101 sshd[13874]: error: PAM: User not known to the underlying authentication module for illegal user ann from 67.228.94.234-static.reverse.softlayer.com
Aug 9 02:39:00 81-89-97-101 sshd[13874]: Failed keyboard-interactive/pam for invalid user ann from 67.228.94.234 port 52336 ssh2 Aug 9 04:11:39 81-89-97-101 sshd[11433]: Invalid user assh from 67.228.94.234 Aug 9 04:11:40 81-89-97-101 sshd[11433]: error: PAM: User not known to the underlying authentication module for illegal user assh from 67.228.94.234-static.reverse.softlayer.com
Aug 9 04:11:40 81-89-97-101 sshd[11433]: Failed keyboard-interactive/pam for invalid user assh from 67.228.94.234 port 57007 ssh2 Aug 9 11:13:36 81-89-97-101 sshd[9613]: Invalid user clark from 67.228.94.234 Aug 9 11:13:36 81-89-97-101 sshd[9613]: error: PAM: User not known to the underlying authentication module for illegal user clark from 67.228.94.234-static.reverse.softlayer.com
Aug 9 11:13:36 81-89-97-101 sshd[9613]: Failed keyboard-interactive/pam for invalid user clark from 67.228.94.234 port 53369 ssh2 Aug 9 11:31:39 81-89-97-101 sshd[15476]: Invalid user clint from 67.228.94.234 Aug 9 11:31:39 81-89-97-101 sshd[15476]: error: PAM: User not known to the underlying authentication module for illegal user clint from 67.228.94.234-static.reverse.softlayer.com
Aug 9 11:31:39 81-89-97-101 sshd[15476]: Failed keyboard-interactive/pam for invalid user clint from 67.228.94.234 port 41680 ssh2



Dear Sir/Madam,

We have detected abuse from the IP address 67.228.94.234, which according to a whois lookup is on your network. We would appreciate if you would investigate and take action as appropriate.

Log lines are given below, but please ask if you require any further information.

(If you are not the correct person to contact about this please accept our apologies - your e-mail address was extracted from the whois record by an automated process. This mail was generated by Fail2Ban.)

Note: Local timezone is +0300 (EEST)
Aug 9 04:27:30 cybershells sshd[12111]: Invalid user arias from 67.228.94.234 Aug 9 04:27:31 cybershells sshd[12111]: error: PAM: User not known to the underlying authentication module for illegal user arias from 67.228.94.234-static.reverse.softlayer.com
Aug 9 04:27:31 cybershells sshd[12111]: Failed keyboard-interactive/pam for invalid user arias from 67.228.94.234 port 36389 ssh2 Aug 9 05:59:31 cybershells sshd[5611]: Invalid user barbara from 67.228.94.234 Aug 9 05:59:31 cybershells sshd[5611]: error: PAM: User not known to the underlying authentication module for illegal user barbara from 67.228.94.234-static.reverse.softlayer.com
Aug 9 05:59:31 cybershells sshd[5611]: Failed keyboard-interactive/pam for invalid user barbara from 67.228.94.234 port 35412 ssh2 Aug 9 13:57:03 cybershells sshd[22612]: Invalid user craig from 67.228.94.234 Aug 9 13:57:04 cybershells sshd[22612]: error: PAM: User not known to the underlying authentication module for illegal user craig from 67.228.94.234-static.reverse.softlayer.com
Aug 9 13:57:04 cybershells sshd[22612]: Failed keyboard-interactive/pam for invalid user craig from 67.228.94.234 port 56894 ssh2

--
This message has bee


Please rate this response
  
Worst             Best
  1 2 3 4 5
回复

使用道具 举报

20

主题

374

回帖

1366

积分

金牌会员

积分
1366
发表于 2010-8-18 20:03:34 | 显示全部楼层
pam?是大家说的那个漏洞嘛,难道你被黑啦。
回复

使用道具 举报

2

主题

48

回帖

482

积分

中级会员

积分
482
发表于 2010-8-18 20:10:33 | 显示全部楼层
那个是pma
回复

使用道具 举报

49

主题

929

回帖

3181

积分

论坛元老

积分
3181
发表于 2010-8-18 22:41:30 | 显示全部楼层
ipmi登陆进去看看/tmp下面是不是有个dd_ssh?
回复

使用道具 举报

19

主题

288

回帖

1023

积分

金牌会员

积分
1023
发表于 2010-8-23 00:45:07 | 显示全部楼层
你直接回复他,我的服务器被黑了,我全部格式话了重装就完了。
回复

使用道具 举报

966

主题

5383

回帖

2万

积分

论坛元老

积分
21401
发表于 2010-8-23 15:11:47 | 显示全部楼层
原帖由 杯具 于 2010-8-23 00:45 发表


你直接回复他,我的服务器被黑了,我全部格式话了重装就完了。

那得真正有重装才行,他们可以看到记录的。

跟softlayer好好沟通后都很容易解决的。
回复

使用道具 举报

3

主题

5

回帖

21

积分

新手上路

积分
21
 楼主| 发表于 2010-8-25 00:00:50 | 显示全部楼层
怎么登录啊?
回复

使用道具 举报

3

主题

5

回帖

21

积分

新手上路

积分
21
 楼主| 发表于 2010-8-25 00:04:10 | 显示全部楼层
重装后 就可以恢复使用了?
回复

使用道具 举报

2

主题

9

回帖

146

积分

注册会员

积分
146
发表于 2010-10-2 16:34:58 | 显示全部楼层
- -"独立IP?
回复

使用道具 举报

182

主题

1375

回帖

5234

积分

论坛元老

积分
5234
发表于 2010-10-10 12:05:59 | 显示全部楼层
被肉鸡了。。
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

Archiver|手机版|小黑屋|HS2V主机综合交流论坛

GMT+8, 2024-11-16 10:49 , Processed in 0.068771 second(s), 3 queries , Gzip On, Redis On.

Powered by Discuz! X3.5

© 2001-2024 Discuz! Team.

快速回复 返回顶部 返回列表