Öğlen saatlerinde sunucu firması HACKLENDİĞİMİ söyledi.
Tam olarak ne olduğunu sorduğumda:
Alıntı
Sunucu firması: "Abuse bildirimiyle gelen, brute force alan karşıdaki sunucunun sshd login logudur. Ayrıca sunucusuna openvz ana node üzerinden giriş yaptığımızda /tmp içinde ve ftpuser owneri ile birçok perl tool çalışmaktaydı."
Nov 24 07:16:20 h1887132 sshd[26867]: reverse mapping checking getaddrinfo for u7k3t9vx.[IP GIZLENDI].com [IP GIZLENDI] failed - POSSIBLE BREAK-IN ATTEMPT! Nov 24 07:16:20 h1887132 sshd[26867]: Invalid user jacques from [IP GIZLENDI] Nov 24 07:16:20 h1887132 sshd[26867]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=[IP GIZLENDI] Nov 24 07:16:23 h1887132 sshd[26867]: Failed password for invalid user jacques from [IP GIZLENDI] port 54596 ssh2 Nov 24 07:36:50 h1887132 sshd[29677]: reverse mapping checking getaddrinfo for u7k3t9vx.[IP GIZLENDI] [IP GIZLENDI] failed - POSSIBLE BREAK-IN ATTEMPT! Nov 24 07:36:50 h1887132 sshd[29677]: Invalid user michael from [IP GIZLENDI] Nov 24 07:36:50 h1887132 sshd[29677]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=[IP GIZLENDI]Kullandığım bilgisayarın işletim sistemi Ubuntu. Herhangi bir farklı program kullanmadım. Bu olayın nasıl olduğuna dair fikrim yok. Sizlerin düşüncelerini merak ediyorum...


