简单的方法就是查看日志:cat /var/log/auth.log
以下的日志是不是表示有坏人198.x.x.6 在频繁扫描我的vps ssh port?
Sep 22 21:41:01 cys CRON[11064]: pam_unix(cron:session): session closed for user smmsp
Sep 22 21:47:01 cys CRON[11088]: pam_unix(cron:session): session opened for user root by (uid=0)
Sep 22 21:47:01 cys CRON[11088]: pam_unix(cron:session): session closed for user root
Sep 22 22:00:01 cys CRON[11092]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Sep 22 22:01:02 cys CRON[11092]: pam_unix(cron:session): session closed for user smmsp
Sep 22 22:20:01 cys CRON[11113]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Sep 22 22:21:01 cys CRON[11113]: pam_unix(cron:session): session closed for user smmsp
Sep 22 22:40:01 cys CRON[11134]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Sep 22 22:40:49 cys sshd[11152]: Bad protocol version identification 'GET / HTTP/1.0' from 198.x.x.6
Sep 22 22:40:49 cys sshd[11153]: Did not receive identification string from 198.x.x.6
Sep 22 22:40:50 cys sshd[11154]: Bad protocol version identification 'GET / HTTP/1.0' from 198.x.x.6
Sep 22 22:40:50 cys sshd[11155]: Did not receive identification string from 198.x.x.6
Sep 22 22:41:01 cys CRON[11134]: pam_unix(cron:session): session closed for user smmsp
Sep 22 22:47:01 cys CRON[11158]: pam_unix(cron:session): session opened for user root by (uid=0)
Sep 22 22:47:01 cys CRON[11158]: pam_unix(cron:session): session closed for user root
Sep 22 23:00:01 cys CRON[11162]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Sep 22 23:01:02 cys CRON[11162]: pam_unix(cron:session): session closed for user smmsp
Sep 22 23:20:01 cys CRON[11183]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Sep 22 23:21:01 cys CRON[11183]: pam_unix(cron:session): session closed for user smmsp
Sep 22 23:40:01 cys CRON[11204]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Sep 22 23:40:49 cys sshd[11222]: Bad protocol version identification 'GET / HTTP/1.0' from 198.x.x.6
Sep 22 23:40:49 cys sshd[11223]: Did not receive identification string from 198.x.x.6
简单的方法就是查看日志:cat /var/log/auth.log
以下的日志是不是表示有坏人198.x.x.6 在频繁扫描我的vps ssh port?
Sep 22 21:41:01 cys CRON[11064]: pam_unix(cron:session): session closed for user smmsp
Sep 22 21:47:01 cys CRON[11088]: pam_unix(cron:session): session opened for user root by (uid=0)
Sep 22 21:47:01 cys CRON[11088]: pam_unix(cron:session): session closed for user root
Sep 22 22:00:01 cys CRON[11092]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Sep 22 22:01:02 cys CRON[11092]: pam_unix(cron:session): session closed for user smmsp
Sep 22 22:20:01 cys CRON[11113]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Sep 22 22:21:01 cys CRON[11113]: pam_unix(cron:session): session closed for user smmsp
Sep 22 22:40:01 cys CRON[11134]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Sep 22 22:40:49 cys sshd[11152]: Bad protocol version identification 'GET / HTTP/1.0' from 198.x.x.6
Sep 22 22:40:49 cys sshd[11153]: Did not receive identification string from 198.x.x.6
Sep 22 22:40:50 cys sshd[11154]: Bad protocol version identification 'GET / HTTP/1.0' from 198.x.x.6
Sep 22 22:40:50 cys sshd[11155]: Did not receive identification string from 198.x.x.6
Sep 22 22:41:01 cys CRON[11134]: pam_unix(cron:session): session closed for user smmsp
Sep 22 22:47:01 cys CRON[11158]: pam_unix(cron:session): session opened for user root by (uid=0)
Sep 22 22:47:01 cys CRON[11158]: pam_unix(cron:session): session closed for user root
Sep 22 23:00:01 cys CRON[11162]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Sep 22 23:01:02 cys CRON[11162]: pam_unix(cron:session): session closed for user smmsp
Sep 22 23:20:01 cys CRON[11183]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Sep 22 23:21:01 cys CRON[11183]: pam_unix(cron:session): session closed for user smmsp
Sep 22 23:40:01 cys CRON[11204]: pam_unix(cron:session): session opened for user smmsp by (uid=0)
Sep 22 23:40:49 cys sshd[11222]: Bad protocol version identification 'GET / HTTP/1.0' from 198.x.x.6
Sep 22 23:40:49 cys sshd[11223]: Did not receive identification string from 198.x.x.6