Neus писал(а):Какие-то изменения предшествовали чудесам?
Количество юзеров увеличилось?
Кто-то с локалки бомбит пакетами (торренты?)
Сетевуха глючит, старая стала, устаёт …
•••
В логах есть чего?
1. Кол-во юзеров не увеличивалось
2. Канал стабильный, когда начинаются чудеса, канал свободный, не нагружен
3. По локалке все чисто
4. Сетевухи профессиональные PCI-E Intel, работают верой и правдой уже много лет.
5. Логи выложу
Дисковое пространство
Код: Выделить всё
[root@arnezami ~]# df -h
Filesystem Size Used Avail Capacity Mounted on
/dev/ad4s2a 224G 19G 186G 9% /
devfs 1.0K 1.0K 0B 100% /dev
devfs 1.0K 1.0K 0B 100% /var/named/dev
Интересные вещи нашел в логах: Кто то с Индии пытается прорваться, не очень настойчиво
/var/log/auth.log
Код: Выделить всё
Oct 26 11:10:11 arnezami sshd[902]: Server listening on :: port 22.
Oct 26 11:10:11 arnezami sshd[902]: Server listening on 0.0.0.0 port 22.
Oct 26 11:12:46 arnezami sshd[1004]: error: PAM: authentication error for root from 192.168.0.2
Oct 26 11:12:54 arnezami sshd[1004]: Accepted keyboard-interactive/pam for root from 192.168.0.2 port 1043 ssh2
Oct 26 11:19:11 arnezami sshd[1337]: Accepted keyboard-interactive/pam for root from 192.168.0.2 port 1104 ssh2
Oct 26 13:01:34 arnezami sshd[2372]: Accepted keyboard-interactive/pam for root from 192.168.0.2 port 4389 ssh2
[b]Oct 27 04:16:16 arnezami ftpd[10244]: FTP LOGIN FAILED FROM 61.5.206.130, www-data
Oct 27 09:23:51 arnezami ftpd[12926]: FTP LOGIN FAILED FROM 117.239.186.154, test[/b]
Oct 27 23:58:32 arnezami sshd[21033]: Accepted keyboard-interactive/pam for root from 192.168.0.216 port 50141 ssh2
Oct 28 16:57:22 arnezami sshd[33899]: Accepted keyboard-interactive/pam for root from 192.168.0.2 port 10162 ssh2
[b]Oct 28 18:14:09 arnezami ftpd[35365]: FTP LOGIN FAILED FROM 169.149.165.85, admin[/b]
Oct 28 18:40:56 arnezami sshd[35671]: Accepted keyboard-interactive/pam for root from 192.168.0.216 port 1591 ssh2
Oct 28 23:06:09 arnezami sshd[42092]: Accepted keyboard-interactive/pam for root from 192.168.0.216 port 15732 ssh2
Oct 28 23:16:18 arnezami webmin[42238]: Non-existent login as root from 192.168.0.216
Oct 28 23:16:22 arnezami webmin[42236]: Non-existent login as root from 192.168.0.216
Oct 28 23:16:27 arnezami webmin[42237]: Non-existent login as arnezami from 192.168.0.216
Oct 28 23:16:47 arnezami webmin[42276]: Invalid login as admin from 192.168.0.216
Oct 28 23:16:49 arnezami webmin[858]: Security alert: Host 192.168.0.216 blocked after 5 failed logins for user admin
Oct 28 23:16:50 arnezami webmin[42281]: Invalid login as admin from 192.168.0.216
Oct 28 23:19:15 arnezami webmin[42328]: Invalid login as admin from 192.168.0.216
Oct 28 23:20:25 arnezami webmin[42332]: Invalid login as admin from 192.168.0.216
Oct 28 23:20:35 arnezami webmin[42365]: Successful login as admin from 192.168.0.216
Вот еще очень интересный список коннектов к Webmin, вероятно здесь зарыто "чудо": Кто то очень настойчиво пытается прорваться
Код: Выделить всё
Failed to initialize SSL connection
[27/Oct/2016:15:24:07 +0000] [173.224.126.219] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[27/Oct/2016:15:24:07 +0000] [173.224.126.219] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[27/Oct/2016:15:51:53 +0000] [204.93.154.217] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[27/Oct/2016:17:19:00 +0000] [104.152.52.71] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[27/Oct/2016:18:02:36 +0000] [104.152.52.58] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[27/Oct/2016:20:22:19 +0000] [204.93.154.208] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[27/Oct/2016:20:47:11 +0000] [62.168.227.162] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[27/Oct/2016:20:47:11 +0000] [62.168.227.162] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[27/Oct/2016:20:47:11 +0000] [62.168.227.162] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[27/Oct/2016:20:56:16 +0000] [104.152.52.55] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[27/Oct/2016:22:09:52 +0000] [104.152.52.55] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[27/Oct/2016:23:17:27 +0000] [104.152.52.60] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:00:02:17 +0000] [104.152.52.73] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:01:06:35 +0000] [104.152.52.56] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:01:53:48 +0000] [104.152.52.67] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:03:11:47 +0000] [104.152.52.62] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:04:13:49 +0000] [204.93.154.208] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:04:49:07 +0000] [104.152.52.74] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:05:44:39 +0000] [104.152.52.55] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:06:53:49 +0000] [104.152.52.75] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:07:58:38 +0000] [104.152.52.68] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:09:07:07 +0000] [204.93.154.208] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:10:14:39 +0000] [104.152.52.70] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:10:59:39 +0000] [104.152.52.55] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:12:08:52 +0000] [104.152.52.70] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:13:07:01 +0000] [104.152.52.59] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:13:57:56 +0000] [104.152.52.62] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:15:32:45 +0000] [204.93.154.217] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:15:48:48 +0000] [104.152.52.70] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:16:57:55 +0000] [104.152.52.55] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:19:15:55 +0000] [104.152.52.56] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:20:04:10 +0000] [104.152.52.71] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
[28/Oct/2016:20:57:52 +0000] [104.152.52.65] Bad Request : This web server is running in SSL mode. Try the URL <a href='https://202.54.87.109.triolan.net:10000/'>https://202.54.87.109.triolan.net:10000/</a> instead.<br>
Отправлено спустя 50 секунд:
snorlov писал(а):Arnezami,
Если считаете, что все в локалки чисто, то попробуйте перейти на ядерный нат... А так ..., обновитесь хотя до 9.3.
Согласен, уже давно пора обновиться, сервер так стабильно трудился, что уже 11 релиз вышел, а я и не заметил)
Отправлено спустя 16 минут 40 секунд:
Еще заметил сообщения в дополнение, их очень много, почти 1GB накопилось, с такого рода содержанием
Видимо кто то из Индии настойчиво пытается ломануть.
Видимо надо просто индусские сети все в бан.
Код: Выделить всё
Checking setuid files and devices:
Checking for uids of 0:
root 0
toor 0
Checking for passwordless accounts:
Checking login.conf permissions:
arnezami.com ipfw denied packets:
+++ /tmp/security.uRzh2cYQ 2016-10-22 03:02:31.000000000 +0000
+00078 213 11380 deny tcp from any to me dst-port 22 via em0
arnezami.com login failures:
Oct 21 16:03:35 arnezami ftpd[73231]: FTP LOGIN FAILED FROM 77.81.224.70, admin
Oct 21 21:56:12 arnezami ftpd[76762]: FTP LOGIN FAILED FROM 109.172.78.171, test
arnezami.com refused connections:
-- End of security output --