V2EX = way to explore
V2EX 是一个关于分享和探索的地方
Sign Up Now
For Existing Member  Sign In
saleacy
V2EX  ›  SSH

关于 ssh 日志/var/log/secure 的攻击日志

  •  
  •   saleacy · Apr 5, 2022 via Android · 2110 views
    This topic created in 1483 days ago, the information mentioned may be changed or developed.
    我服务器暴露公网的,今天看 secure 日志发现了以下错误

    sshd[15979]: Bad protocol version identification 'GET / HTTP/1.1' from 209.17.96.58 port 52775

    sshd[30025]: Bad protocol version identification '\026\003\001\002' from 39.103.146.185 port 60166

    sshd[30026]: Bad protocol version identification 'GET / HTTP/1.1' from 39.103.146.185 port 60168

    sshd[30027]: Bad protocol version identification 'GET / HTTP/2' from 39.103.146.185 port 60176

    sshd[30028]: Bad protocol version identification '\026\003\001\002' from 39.103.146.185 port 60178

    sshd[30029]: Bad protocol version identification 'GET / HTTP/1.1' from 39.103.146.185 port 60186

    sshd[30030]: Bad protocol version identification 'GET / HTTP/2' from 39.103.146.185 port 60190



    这是啥攻击方式,有大佬清楚吗?
    4 replies    2022-04-06 05:24:40 +08:00
    jim9606
        1
    jim9606  
       Apr 5, 2022   ❤️ 2
    各种自动端口扫描器,也可以说“互联网背景辐射”。
    一般来说连记日志的价值都没有。
    polaa
        2
    polaa  
       Apr 5, 2022   ❤️ 2
    不是攻击,网络空间资产测绘而已
    AlphaTauriHonda
        3
    AlphaTauriHonda  
       Apr 5, 2022
    39.103.146.185 不知道这个 Aliyun 北京的服务器在扫描什么,HTTP 和 HTTPS 吗?
    ferstar
        4
    ferstar  
       Apr 6, 2022 via Android
    换到 443 端口,世界安静了😏,用 nginx 回落
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   3456 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 37ms · UTC 00:36 · PVG 08:36 · LAX 17:36 · JFK 20:36
    ♥ Do have faith in what you're doing.