CSGO
V2EX  ›  问与答

服务器每时每刻 /var/log/secure 有大量登录日志,会有什么问题吗?

  •  
  •   CSGO · Mar 23, 2024 · 790 views
    This topic created in 779 days ago, the information mentioned may be changed or developed.
    类似这样:
    Mar 23 14:45:03 VM-4-16-opencloudos sshd[988302]: Received disconnect from 174.138.24.127 port 35340:11: Bye Bye [preauth]
    Mar 23 14:45:03 VM-4-16-opencloudos sshd[988302]: Disconnected from authenticating user root 174.138.24.127 port 35340 [preauth]

    腾讯云上防火墙,和服务器上防火墙都只有开发几个端口,而且确认了并没有日志中这些端口,比如这条的 35340 ,那么为啥它还会有记录?

    我 ssh 就是开发的默认端口,我也了解了下用上了 fail2ban ,但我也问了 ai 似乎 fail2ban 也能配置把 ssh 端口直接写 any ,那么到底是 any 直接封禁所有这样的尝试登录消耗性能,还是其实这样日志并没什么关系?
    julyclyde
        1
    julyclyde  
       Mar 24, 2024
    问题在于真正突破的日志可能会淹没在无效尝试的日志里
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   6245 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 37ms · UTC 06:15 · PVG 14:15 · LAX 23:15 · JFK 02:15
    ♥ Do have faith in what you're doing.