取出/var/log/secure中一小时内登录失败超过三次的IP

取出/var/log/secure中一小时内登录失败超过三次的IP

前两个字段是日期,第三个字段是小时,第四个字段是IP

cat /var/log/secure | sort -i | awk -F ' :' '/Failed/{a$1" "$2" "$3" "$4" "$(NF-3)++}END{for(i in a)if(ai>3)print i}'

s="Jul 7 13:49:08"

sed -n "/s/, p" /var/log/secure | awk '/Failed/{a$(NF-3)++}END{for(b in a){if(ab>2){print b}}}'

统计/var/log/secure日志中出现"Failed"关键词的IP地址及次数。

···

awk 是三剑客中一把利刃。

cat /var/log/secure

Jul 18 10:28:59 sshd1377656: Accepted password for root from 172.16.100.66 port 59750 ssh2

Jul 18 10:28:59 sshd1377656: pam_unix(sshd:session): session opened for user root by (uid=0)

Jul 18 10:38:20 sshd1416681: Accepted password for root from 172.16.100.21 port 62366 ssh2

Jul 18 10:38:20 sshd1416681: pam_unix(sshd:session): session opened for user root by (uid=0)

Jul 18 10:58:57 sshd1502199: Accepted password for root from 172.16.100.66 port 61038 ssh2

可以看到正常的一个访问日志记录,新建一个连接 故意输错密码,让日志记录一下

Jul 18 10:59:13 sshd1503821: Failed password for root from 172.16.100.21 port 63802 ssh2

#可以看到错误登陆时的日志记录是这样的。

那么就可以开始使用awk来实现二级标题中的需要了。

先给出命令再来解析

awk '/Failed/ {++ip$(NF-3)} END {for (i in ip) print i"="ipi}'

一、登录ssh失败次数统计

1)错误的打开方式

awk '/Failed password/ {print $(NF-3)}' secure |sort -n |uniq -c|sort -n |tail /var/log/secure

2)拷贝文件,再查看失败

cp /var/log/secure .

awk '/Failed password/ {print $(NF-3)}' secure |sort -n |uniq -c|sort -n |tail

3)直接查看失败

awk '/Failed password/ {print (NF-3)}' /var/log/secure |sort -n |uniq -c|sort -n

4)查看最近失败的时间

less /var/log/secure

按G

二、对于防破解问题的处理

1)禁止密码登录方式

vi /etc/ssh/sshd_config

2)禁止失败的IP登录的方式

复制代码
#
# hosts.deny    This file contains access rules which are used to
#               deny connections to network services that either use
#               the tcp_wrappers library or that have been
#               started through a tcp_wrappers-enabled xinetd.
#
#               The rules in this file can also be set up in
#               /etc/hosts.allow with a 'deny' option instead.
#
#               See 'man 5 hosts_options' and 'man 5 hosts_access'
#               for information on rule syntax.
#               See 'man tcpd' for information on tcp_wrappers
#
sshd:192.168.2.41:deny

/etc/hosts.deny

在/etc/hosts.deny文件下面

添加 sshd:192.168.2.41:deny

重启sshd

Linux 系统SSH 登录失败的内容会记录到/var/log/secure文件,通过查找关键字 Failed,可以定位到这些异常的IP地址,比如:

root@www.cndba.cn \~# cat /var/log/secure|grep 36.250.229.118

Jan 10 16:54:25 iZbp15upsrdbnwnq3zksepZ sshd10813: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.152.101.235 user=root

Jan 10 16:54:25 iZbp15upsrdbnwnq3zksepZ sshd10813: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "root"

Jan 10 16:54:27 iZbp15upsrdbnwnq3zksepZ sshd10813: Failed password for root from 103.152.101.235 port 59352 ssh2

Jan 10 16:54:27 iZbp15upsrdbnwnq3zksepZ sshd10813: Connection closed by 103.152.101.235 port 59352 preauth

Jan 10 16:54:29 iZbp15upsrdbnwnq3zksepZ sshd10820: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.152.101.235 user=root

Jan 10 16:54:29 iZbp15upsrdbnwnq3zksepZ sshd10820: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "root"

Jan 10 16:54:31 iZbp15upsrdbnwnq3zksepZ sshd10820: Failed password for root from 103.152.101.235 port 60970 ssh2

Jan 10 16:54:31 iZbp15upsrdbnwnq3zksepZ sshd10820: Connection closed by 103.152.101.235 port 60970 preauth

Jan 10 16:54:33 iZbp15upsrdbnwnq3zksepZ sshd10825: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.152.101.235 user=root

Jan 10 16:54:33 iZbp15upsrdbnwnq3zksepZ sshd10825: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "root"

Jan 10 16:54:35 iZbp15upsrdbnwnq3zksepZ sshd10825: Failed password for root from 103.152.101.235 port 34445 ssh2

Jan 10 16:54:35 iZbp15upsrdbnwnq3zksepZ sshd10825: Connection closed by 103.152.101.235 port 34445 preauth

Jan 10 16:54:37 iZbp15upsrdbnwnq3zksepZ sshd10831: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.152.101.235 user=root

Jan 10 16:54:37 iZbp15upsrdbnwnq3zksepZ sshd10831: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "root"

Jan 10 16:54:39 iZbp15upsrdbnwnq3zksepZ sshd10831: Failed password for root from 103.152.101.235 port 36166 ssh2

Jan 10 16:54:39 iZbp15upsrdbnwnq3zksepZ sshd10831: Connection closed by 103.152.101.235 port 36166 preauth

Jan 10 16:54:41 iZbp15upsrdbnwnq3zksepZ sshd10836: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.152.101.235 user=root

Jan 10 16:54:41 iZbp15upsrdbnwnq3zksepZ sshd10836: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "root"

Jan 10 16:54:43 iZbp15upsrdbnwnq3zksepZ sshd10836: Failed password for root from 103.152.101.235 port 37866 ssh2

Jan 10 16:54:43 iZbp15upsrdbnwnq3zksepZ sshd10836: Connection closed by 103.152.101.235 port 37866 preauth

Jan 10 16:54:45 iZbp15upsrdbnwnq3zksepZ sshd10841: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.152.101.235 user=root

Jan 10 16:54:45 iZbp15upsrdbnwnq3zksepZ sshd10841: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "root"

Jan 10 16:54:47 iZbp15upsrdbnwnq3zksepZ sshd10841: Failed password for root from 103.152.101.235 port 39832 ssh2

Jan 10 16:54:47 iZbp15upsrdbnwnq3zksepZ sshd10841: Connection closed by 103.152.101.235 port 39832 preauth

Jan 10 16:54:49 iZbp15upsrdbnwnq3zksepZ sshd10847: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=103.152.101.235 user=root

Jan 10 16:54:49 iZbp15upsrdbnwnq3zksepZ sshd10847: pam_succeed_if(sshd:auth): requirement "uid >= 1000" not met by user "root"

Jan 10 16:54:51 iZbp15upsrdbnwnq3zksepZ sshd10847: Failed password for root from 103.152.101.235 port 41558 ssh2

Jan 10 16:54:52 iZbp15upsrdbnwnq3zksepZ sshd10847: Connection closed by 103.152.101.235 port 41558 preauth

比如这里,明显这个IP地址在进行SSH 扫描,不断的更换端口和用户进行暴力测试。

在Linux里面有两个相关的文件:

/etc/hosts.allow: 允许哪些IP访问主机

cat /etc/hosts.allow

sshd:19.16.18.1:allow

sshd:19.16.18.2:allow

/etc/hosts.deny 禁止哪些IP访问主机:

cat /etc/hosts.deny

sshd:13.7.3.6:deny

sshd:92.4.0.4:deny

sshd:94.10.4.2:deny

sshd:94.4.1.6:deny

sshd:11.64.11.5:deny

因此,我们只需要从/var/log/secure文件中提取IP地址,如果次数达到10次则将该IP写到 /etc/hosts.deny中,禁止这些IP访问主机。

脚本如下secure_ssh.sh:

#! /bin/bash

cat /var/log/secure|awk '/Failed/{print (NF-3)}'\|sort\|uniq -c\|awk '{print 2"="$1;}' > /boss/config/black.list

for i in `cat /boss/config/black.list`

do

IP=`echo i \|awk -F= '{print 1}'`

NUM=`echo i\|awk -F= '{print 2}'`

echo IP=NUM

if $NUM -gt 10 ; then

grep $IP /etc/hosts.deny > /dev/null

if $? -gt 0 ;then

echo "sshd:$IP:deny" >> /etc/hosts.deny

fi

fi

done

将secure_ssh.sh脚本放入cron计划任务,每1小时执行一次。

crontab -e

0 */1 * * * sh /usr/local/bin/secure_ssh.sh

1 CentOS7通过定时脚本阻断异常IP连接SSH(实测)_secure_ssh.sh-CSDN博客

相关推荐
linyanRPA5 分钟前
影刀RPA店群自动化实战:多店铺活动自动报名与促销管理架构设计
运维·自动化·办公自动化·rpa·python脚本·爬虫自动化·店群自动化
mounter62518 分钟前
现代 Linux 内存管理的演进与变革:从传统 LRU 到多代架构 MGLRU
linux·服务器·kernel
会Tk矩阵群控的小木19 分钟前
安卓群控系统对于游戏工作室实战教程
android·运维·游戏·adb·开源软件·个人开发
赵渝强老师42 分钟前
【赵渝强老师】Kubernetes(K8s)中的金丝雀升级
linux·docker·云原生·容器·kubernetes
佛山个人技术开发1 小时前
GitCode SSH连接配置教程
运维·ssh·gitcode
Qt程序员1 小时前
Linux RCU 原理与应用
linux·c++·内核·linux内核·rcu
The Sheep 20231 小时前
Vue复习
linux·服务器·数据库
兄台の请冷静1 小时前
Linux 安装es
linux·elasticsearch·jenkins
fengyehongWorld2 小时前
Linux rg命令
linux
pride.li2 小时前
海思视觉Hi3516CV610--开机自动设置ip
linux·网络·网络协议·tcp/ip