全球主机交流论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

CeraNetworks网络延迟测速工具IP归属甄别
查看: 19066|回复: 9

softlayer 被投诉,ip已经被停用,怎么办?

[复制链接]
发表于 2010-8-18 19:49:56 | 显示全部楼层 |阅读模式
真是搞不懂,怎么说我的服务器在攻击别人的站呢?被投诉了,还列举了一大堆的证据!怎么回事啊?要怎么解决啊?找softlayer技术,他说他们没法解决!晕死了




大家帮忙看看,这只是其中一点点东西:

Ticket Contents:

   Employee Response - 2010-Aug-09 10:23 (GMT-0600) [Update 1]
  SoftLayer Security has received the following HACKING / MALICIOUS ACTIVITY complaint in reference to an IP hosted on your server. A copy of the complaint is listed below or attached to this ticket for your review. Please disable or remove this activity immediately as it is direct abuse of the network services and a violation of your TOS and AUP. Failure to resolve this issue in an expeditious manner could lead to service interruption for this server. Please update this ticket with resolution to this issue. We thank you in advance for your quick action and cooperation.

Regards,
SoftLayer Security Team


Please rate this response
  
Worst             Best
  1 2 3 4 5   

  

Employee Response - 2010-Aug-09 10:23 (GMT-0600) [Update 2]
  Looks like your customer with IP 67.228.94.234 is doing ssh attacks to my server.
Please take care about
Best Regards

here some logfile output Date
Mon Aug 9 11:45:02 CEST 2010
Aug 9 00:43:44 81-89-97-101 sshd[11971]: Invalid user alyssa from 67.228.94.234 Aug 9 00:43:44 81-89-97-101 sshd[11971]: error: PAM: User not known to the underlying authentication module for illegal user alyssa from 67.228.94.234-static.reverse.softlayer.com
Aug 9 00:43:44 81-89-97-101 sshd[11971]: Failed keyboard-interactive/pam for invalid user alyssa from 67.228.94.234 port 39379 ssh2 Aug 9 02:39:00 81-89-97-101 sshd[13874]: Invalid user ann from 67.228.94.234 Aug 9 02:39:00 81-89-97-101 sshd[13874]: error: PAM: User not known to the underlying authentication module for illegal user ann from 67.228.94.234-static.reverse.softlayer.com
Aug 9 02:39:00 81-89-97-101 sshd[13874]: Failed keyboard-interactive/pam for invalid user ann from 67.228.94.234 port 52336 ssh2 Aug 9 04:11:39 81-89-97-101 sshd[11433]: Invalid user assh from 67.228.94.234 Aug 9 04:11:40 81-89-97-101 sshd[11433]: error: PAM: User not known to the underlying authentication module for illegal user assh from 67.228.94.234-static.reverse.softlayer.com
Aug 9 04:11:40 81-89-97-101 sshd[11433]: Failed keyboard-interactive/pam for invalid user assh from 67.228.94.234 port 57007 ssh2 Aug 9 11:13:36 81-89-97-101 sshd[9613]: Invalid user clark from 67.228.94.234 Aug 9 11:13:36 81-89-97-101 sshd[9613]: error: PAM: User not known to the underlying authentication module for illegal user clark from 67.228.94.234-static.reverse.softlayer.com
Aug 9 11:13:36 81-89-97-101 sshd[9613]: Failed keyboard-interactive/pam for invalid user clark from 67.228.94.234 port 53369 ssh2 Aug 9 11:31:39 81-89-97-101 sshd[15476]: Invalid user clint from 67.228.94.234 Aug 9 11:31:39 81-89-97-101 sshd[15476]: error: PAM: User not known to the underlying authentication module for illegal user clint from 67.228.94.234-static.reverse.softlayer.com
Aug 9 11:31:39 81-89-97-101 sshd[15476]: Failed keyboard-interactive/pam for invalid user clint from 67.228.94.234 port 41680 ssh2



Dear Sir/Madam,

We have detected abuse from the IP address 67.228.94.234, which according to a whois lookup is on your network. We would appreciate if you would investigate and take action as appropriate.

Log lines are given below, but please ask if you require any further information.

(If you are not the correct person to contact about this please accept our apologies - your e-mail address was extracted from the whois record by an automated process. This mail was generated by Fail2Ban.)

Note: Local timezone is +0300 (EEST)
Aug 9 04:27:30 cybershells sshd[12111]: Invalid user arias from 67.228.94.234 Aug 9 04:27:31 cybershells sshd[12111]: error: PAM: User not known to the underlying authentication module for illegal user arias from 67.228.94.234-static.reverse.softlayer.com
Aug 9 04:27:31 cybershells sshd[12111]: Failed keyboard-interactive/pam for invalid user arias from 67.228.94.234 port 36389 ssh2 Aug 9 05:59:31 cybershells sshd[5611]: Invalid user barbara from 67.228.94.234 Aug 9 05:59:31 cybershells sshd[5611]: error: PAM: User not known to the underlying authentication module for illegal user barbara from 67.228.94.234-static.reverse.softlayer.com
Aug 9 05:59:31 cybershells sshd[5611]: Failed keyboard-interactive/pam for invalid user barbara from 67.228.94.234 port 35412 ssh2 Aug 9 13:57:03 cybershells sshd[22612]: Invalid user craig from 67.228.94.234 Aug 9 13:57:04 cybershells sshd[22612]: error: PAM: User not known to the underlying authentication module for illegal user craig from 67.228.94.234-static.reverse.softlayer.com
Aug 9 13:57:04 cybershells sshd[22612]: Failed keyboard-interactive/pam for invalid user craig from 67.228.94.234 port 56894 ssh2

--
This message has bee


Please rate this response
  
Worst             Best
  1 2 3 4 5
发表于 2010-8-18 20:03:34 | 显示全部楼层
pam?是大家说的那个漏洞嘛,难道你被黑啦。
发表于 2010-8-18 20:10:33 | 显示全部楼层

回复 2# 的帖子

那个是pma
发表于 2010-8-18 22:41:30 | 显示全部楼层
ipmi登陆进去看看/tmp下面是不是有个dd_ssh?
发表于 2010-8-23 00:45:07 | 显示全部楼层
你直接回复他,我的服务器被黑了,我全部格式话了重装就完了。
发表于 2010-8-23 15:11:47 | 显示全部楼层
原帖由 杯具 于 2010-8-23 00:45 发表
你直接回复他,我的服务器被黑了,我全部格式话了重装就完了。

那得真正有重装才行,他们可以看到记录的。

跟softlayer好好沟通后都很容易解决的。
 楼主| 发表于 2010-8-25 00:00:50 | 显示全部楼层

回复 4# 的帖子

怎么登录啊?
 楼主| 发表于 2010-8-25 00:04:10 | 显示全部楼层

回复 5# 的帖子

重装后 就可以恢复使用了?
发表于 2010-10-2 16:34:58 | 显示全部楼层
- -"独立IP?
发表于 2010-10-10 12:05:59 | 显示全部楼层
被肉鸡了。。
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|小黑屋|全球主机交流论坛

GMT+8, 2024-4-24 16:40 , Processed in 0.062886 second(s), 9 queries , Gzip On, MemCache On.

Powered by Discuz! X3.4

© 2001-2023 Discuz! Team.

快速回复 返回顶部 返回列表