找回密码
 立即注册
搜索
热搜: 活动 交友 discuz
查看: 51|回复: 9

softlayer 被投诉,ip已经被停用,怎么办?

[复制链接]

3

主题

6

回帖

27

积分

新手上路

积分
27
发表于 2010-8-18 19:49:56 | 显示全部楼层 |阅读模式
真是搞不懂,怎么说我的服务器在攻击别人的站呢?被投诉了,还列举了一大堆的证据!怎么回事啊?要怎么解决啊?找softlayer技术,他说他们没法解决!晕死了




大家帮忙看看,这只是其中一点点东西:

Ticket Contents:

   Employee Response - 2010-Aug-09 10:23 (GMT-0600) [Update 1]
  SoftLayer Security has received the following HACKING / MALICIOUS ACTIVITY complaint in reference to an IP hosted on your server. A copy of the complaint is listed below or attached to this ticket for your review. Please disable or remove this activity immediately as it is direct abuse of the network services and a violation of your TOS and AUP. Failure to resolve this issue in an expeditious manner could lead to service interruption for this server. Please update this ticket with resolution to this issue. We thank you in advance for your quick action and cooperation.

Regards,
SoftLayer Security Team


Please rate this response
  
Worst             Best
  1 2 3 4 5   

  

Employee Response - 2010-Aug-09 10:23 (GMT-0600) [Update 2]
  Looks like your customer with IP 67.228.94.234 is doing ssh attacks to my server.
Please take care about
Best Regards

here some logfile output Date
Mon Aug 9 11:45:02 CEST 2010
Aug 9 00:43:44 81-89-97-101 sshd[11971]: Invalid user alyssa from 67.228.94.234 Aug 9 00:43:44 81-89-97-101 sshd[11971]: error: PAM: User not known to the underlying authentication module for illegal user alyssa from 67.228.94.234-static.reverse.softlayer.com
Aug 9 00:43:44 81-89-97-101 sshd[11971]: Failed keyboard-interactive/pam for invalid user alyssa from 67.228.94.234 port 39379 ssh2 Aug 9 02:39:00 81-89-97-101 sshd[13874]: Invalid user ann from 67.228.94.234 Aug 9 02:39:00 81-89-97-101 sshd[13874]: error: PAM: User not known to the underlying authentication module for illegal user ann from 67.228.94.234-static.reverse.softlayer.com
Aug 9 02:39:00 81-89-97-101 sshd[13874]: Failed keyboard-interactive/pam for invalid user ann from 67.228.94.234 port 52336 ssh2 Aug 9 04:11:39 81-89-97-101 sshd[11433]: Invalid user assh from 67.228.94.234 Aug 9 04:11:40 81-89-97-101 sshd[11433]: error: PAM: User not known to the underlying authentication module for illegal user assh from 67.228.94.234-static.reverse.softlayer.com
Aug 9 04:11:40 81-89-97-101 sshd[11433]: Failed keyboard-interactive/pam for invalid user assh from 67.228.94.234 port 57007 ssh2 Aug 9 11:13:36 81-89-97-101 sshd[9613]: Invalid user clark from 67.228.94.234 Aug 9 11:13:36 81-89-97-101 sshd[9613]: error: PAM: User not known to the underlying authentication module for illegal user clark from 67.228.94.234-static.reverse.softlayer.com
Aug 9 11:13:36 81-89-97-101 sshd[9613]: Failed keyboard-interactive/pam for invalid user clark from 67.228.94.234 port 53369 ssh2 Aug 9 11:31:39 81-89-97-101 sshd[15476]: Invalid user clint from 67.228.94.234 Aug 9 11:31:39 81-89-97-101 sshd[15476]: error: PAM: User not known to the underlying authentication module for illegal user clint from 67.228.94.234-static.reverse.softlayer.com
Aug 9 11:31:39 81-89-97-101 sshd[15476]: Failed keyboard-interactive/pam for invalid user clint from 67.228.94.234 port 41680 ssh2



Dear Sir/Madam,

We have detected abuse from the IP address 67.228.94.234, which according to a whois lookup is on your network. We would appreciate if you would investigate and take action as appropriate.

Log lines are given below, but please ask if you require any further information.

(If you are not the correct person to contact about this please accept our apologies - your e-mail address was extracted from the whois record by an automated process. This mail was generated by Fail2Ban.)

Note: Local timezone is +0300 (EEST)
Aug 9 04:27:30 cybershells sshd[12111]: Invalid user arias from 67.228.94.234 Aug 9 04:27:31 cybershells sshd[12111]: error: PAM: User not known to the underlying authentication module for illegal user arias from 67.228.94.234-static.reverse.softlayer.com
Aug 9 04:27:31 cybershells sshd[12111]: Failed keyboard-interactive/pam for invalid user arias from 67.228.94.234 port 36389 ssh2 Aug 9 05:59:31 cybershells sshd[5611]: Invalid user barbara from 67.228.94.234 Aug 9 05:59:31 cybershells sshd[5611]: error: PAM: User not known to the underlying authentication module for illegal user barbara from 67.228.94.234-static.reverse.softlayer.com
Aug 9 05:59:31 cybershells sshd[5611]: Failed keyboard-interactive/pam for invalid user barbara from 67.228.94.234 port 35412 ssh2 Aug 9 13:57:03 cybershells sshd[22612]: Invalid user craig from 67.228.94.234 Aug 9 13:57:04 cybershells sshd[22612]: error: PAM: User not known to the underlying authentication module for illegal user craig from 67.228.94.234-static.reverse.softlayer.com
Aug 9 13:57:04 cybershells sshd[22612]: Failed keyboard-interactive/pam for invalid user craig from 67.228.94.234 port 56894 ssh2

--
This message has bee


Please rate this response
  
Worst             Best
  1 2 3 4 5
回复

使用道具 举报

59

主题

2463

回帖

5129

积分

论坛元老

积分
5129
发表于 2010-8-18 20:03:34 | 显示全部楼层
pam?是大家说的那个漏洞嘛,难道你被黑啦。
回复

使用道具 举报

3

主题

310

回帖

649

积分

高级会员

积分
649
发表于 2010-8-18 20:10:33 | 显示全部楼层
那个是pma
回复

使用道具 举报

71

主题

3918

回帖

8109

积分

论坛元老

积分
8109
发表于 2010-8-18 22:41:30 | 显示全部楼层
ipmi登陆进去看看/tmp下面是不是有个dd_ssh?
回复

使用道具 举报

90

主题

2058

回帖

4446

积分

论坛元老

积分
4446
发表于 2010-8-23 00:45:07 | 显示全部楼层
你直接回复他,我的服务器被黑了,我全部格式话了重装就完了。
回复

使用道具 举报

1524

主题

3万

回帖

8万

积分

管理员

积分
81550
发表于 2010-8-23 15:11:47 | 显示全部楼层
原帖由 杯具 于 2010-8-23 00:45 发表


你直接回复他,我的服务器被黑了,我全部格式话了重装就完了。

那得真正有重装才行,他们可以看到记录的。

跟softlayer好好沟通后都很容易解决的。
回复

使用道具 举报

3

主题

6

回帖

27

积分

新手上路

积分
27
 楼主| 发表于 2010-8-25 00:00:50 | 显示全部楼层
怎么登录啊?
回复

使用道具 举报

3

主题

6

回帖

27

积分

新手上路

积分
27
 楼主| 发表于 2010-8-25 00:04:10 | 显示全部楼层
重装后 就可以恢复使用了?
回复

使用道具 举报

2

主题

33

回帖

82

积分

注册会员

积分
82
发表于 2010-10-2 16:34:58 | 显示全部楼层
- -"独立IP?
回复

使用道具 举报

113

主题

1338

回帖

3077

积分

论坛元老

积分
3077
发表于 2010-10-10 12:05:59 | 显示全部楼层
被肉鸡了。。
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

Archiver|手机版|小黑屋|Discuz! X

GMT+8, 2025-1-12 09:54 , Processed in 0.025050 second(s), 5 queries , Gzip On, Redis On.

Powered by Discuz! X3.5

© 2001-2024 Discuz! Team.

快速回复 返回顶部 返回列表