差别
两侧同时换到之前的修订记录前一修订版后一修订版 | 前一修订版 |
it:server:保护 [2022-08-27 20:56] – goldentianya | it:server:保护 [2022-08-29 19:03] (当前版本) – [保护VPS] goldentianya |
---|
<code> | <code> |
sudo grep "Failed password for invalid user" /var/log/auth.log | awk '{print $13}' | sort | uniq -c | sort -nr | more | sudo grep "Failed password for invalid user" /var/log/auth.log | awk '{print $13}' | sort | uniq -c | sort -nr | more |
| </code> |
| |
| 3. 统计以root或者其它用户登录的次数 |
| <code> |
| sudo grep "Failed password for root" /var/log/auth.log | wc -l |
| sudo grep "Failed password for invalid user" /var/log/auth.log | wc -l |
</code> | </code> |
| |
* <color #ff7f27>''%%sudo systemctl restart sshd%%''</color> | * <color #ff7f27>''%%sudo systemctl restart sshd%%''</color> |
* <color #ff7f27>''%%sudo service ssh restart%%''</color> | * <color #ff7f27>''%%sudo service ssh restart%%''</color> |
| |
| <code> |
| // 统计以 root 用户尝试登录到数量 |
| sudo grep "Failed password for root" /var/log/auth.log | wc -l |
| // 统计以其它用户试登录到数量 |
| sudo grep "Failed password for invalid user" /var/log/auth.log | wc -l |
| </code> |
| |
<code> | <code> |
回到顶部