Seminari del PHC - Riccardo Murri - 21 febbraio 2000 - Pisa 

Vigilare una workstation Linux: registrare gli accessi (LUCIDO 18) 


PRECEDENTE INDICE PHC HOME SUCCESSIVO

Attacco al programma portmap di poisson.dm.unipi.it (estratto dal file syslog)

Feb 19 15:08:49 poisson kernel: TCP connection accepted:
   ip=212.171.107.216 port=80 uid=33 process=apache[433]
Feb 19 15:09:56 poisson kernel: TCP connection rejected from
   133.41.16.192, port 23
Feb 19 15:09:56 poisson kernel: TCP connection accepted:
   ip=133.41.16.192 port=111 uid=1 process=portmap[161]
Feb 19 15:09:56 poisson kernel: TCP connection rejected from
   133.41.16.192, port 23
Feb 19 15:09:57 poisson kernel: TCP connection accepted:
   ip=133.41.16.192 port=111 uid=1 process=portmap[161]
Feb 19 15:10:03 poisson kernel: TCP connection rejected from
   133.41.16.192, port 1
Feb 19 16:10:03 poisson portmap[4844]: connect from 133.41.16.192 to
   dump(): request from unauthorized host