Сегодня был атакован сервер нашей компании :) Фак мой моск...дети :)
22:01
Сегодня наш сервер обмена данными компании был атакован с помощью брут форса. Вот последние минуты событий: Атака началась в Fri Jul 04 08:54:23 2008
Fri Jul 04 09:20:50 2008 28 Incoming connection request on interface 192.168.0.99 Fri Jul 04 09:20:50 2008 28 Connection request accepted from 58.252.70.99 Fri Jul 04 09:20:50 2008 28 USER mysql Fri Jul 04 09:20:51 2008 28 PASS *********** Fri Jul 04 09:20:51 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:20:55 2008 28 USER dan Fri Jul 04 09:20:56 2008 28 PASS *********** Fri Jul 04 09:20:56 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:21:00 2008 28 USER welcome Fri Jul 04 09:21:03 2008 28 PASS *********** Fri Jul 04 09:21:03 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:21:07 2008 28 USER admin Fri Jul 04 09:21:07 2008 28 PASS *********** Fri Jul 04 09:21:07 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:21:12 2008 28 USER ftp Fri Jul 04 09:21:12 2008 28 PASS *********** Fri Jul 04 09:21:12 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:21:17 2008 28 USER error Fri Jul 04 09:21:17 2008 28 PASS *********** Fri Jul 04 09:21:17 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:21:22 2008 28 USER connect Fri Jul 04 09:21:22 2008 28 PASS *********** Fri Jul 04 09:21:22 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:21:26 2008 28 USER god Fri Jul 04 09:21:27 2008 28 PASS *********** Fri Jul 04 09:21:27 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:21:31 2008 28 USER 123 Fri Jul 04 09:21:32 2008 28 PASS *********** Fri Jul 04 09:21:32 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:21:37 2008 28 USER administrator Fri Jul 04 09:21:37 2008 28 PASS *********** Fri Jul 04 09:21:37 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:21:41 2008 28 USER weldone Fri Jul 04 09:21:42 2008 28 PASS *********** Fri Jul 04 09:21:42 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:21:46 2008 28 USER kid Fri Jul 04 09:21:47 2008 28 PASS *********** Fri Jul 04 09:21:47 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:21:51 2008 28 USER alex Fri Jul 04 09:21:52 2008 28 PASS *********** Fri Jul 04 09:21:52 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:21:56 2008 28 USER help Fri Jul 04 09:21:56 2008 28 PASS *********** Fri Jul 04 09:21:56 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:22:01 2008 28 USER noone Fri Jul 04 09:22:02 2008 28 PASS *********** Fri Jul 04 09:22:02 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:22:06 2008 28 USER anonymous Fri Jul 04 09:22:07 2008 28 PASS *********** Fri Jul 04 09:22:07 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:22:11 2008 28 USER ftp Fri Jul 04 09:22:12 2008 28 PASS *********** Fri Jul 04 09:22:12 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:22:16 2008 28 USER ftpserver Fri Jul 04 09:22:17 2008 28 PASS *********** Fri Jul 04 09:22:17 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:22:22 2008 28 USER 2003server Fri Jul 04 09:22:22 2008 28 PASS *********** Fri Jul 04 09:22:22 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:22:27 2008 28 USER 12345 Fri Jul 04 09:22:27 2008 28 PASS *********** Fri Jul 04 09:22:27 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:22:32 2008 28 USER 54321 Fri Jul 04 09:22:32 2008 28 PASS *********** Fri Jul 04 09:22:32 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:22:36 2008 28 USER windows Fri Jul 04 09:22:37 2008 28 PASS *********** Fri Jul 04 09:22:37 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:22:41 2008 28 USER fackyou Fri Jul 04 09:22:42 2008 28 PASS *********** Fri Jul 04 09:22:42 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:22:46 2008 28 USER ver Fri Jul 04 09:22:47 2008 28 PASS *********** Fri Jul 04 09:22:47 2008 28 Logon failure: the user name did not belong to a valid NT user Fri Jul 04 09:22:51 2008 28 Connection terminated. - это мне надоело наблюдать за происходящим и я отрубил псевдохакера. Интересно то, что функция "Dos protection" была отключена, как и список "белых IP адресов" - Инсайдеры? О_о После этого были так же сделаны некоторые настройки на ADSL модеме, и других сетевых устройствах. --------------- Максим Специалист по сетевой безопасности, администратор СУБД. Компания "Fuji film" Город Луганск