Voici les éléments demandés :
- le fichier de config de ton SSH
Host *
# ForwardAgent no
# ForwardX11 no
# ForwardX11Trusted yes
# RhostsRSAAuthentication no
# RSAAuthentication yes
# PasswordAuthentication yes
# HostbasedAuthentication no
# GSSAPIAuthentication no
# GSSAPIDelegateCredentials no
# GSSAPIKeyExchange no
# GSSAPITrustDNS no
# BatchMode no
# CheckHostIP yes
# AddressFamily any
# ConnectTimeout 0
# StrictHostKeyChecking ask
# IdentityFile ~/.ssh/identity
# IdentityFile ~/.ssh/id_rsa
# IdentityFile ~/.ssh/id_dsa
# IdentityFile ~/.ssh/id_ecdsa
# IdentityFile ~/.ssh/id_ed25519
# Port 22
# Protocol 2
# Cipher 3des
# Ciphers aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-cbc,3des-cbc
# MACs hmac-md5,hmac-sha1,umac-64@openssh.com,hmac-ripemd160
# EscapeChar ~
# Tunnel no
# TunnelDevice any:any
# PermitLocalCommand no
# VisualHostKey no
# ProxyCommand ssh -q -W %h:%p gateway.example.com
# RekeyLimit 1G 1h
SendEnv LANG LC_*
HashKnownHosts yes
GSSAPIAuthentication yes
GSSAPIDelegateCredentials no
- le fichier de log SSH (de la période supposée de l'intrusion) :
Sep 29 10:05:08 gevara sshd[7035]: Disconnected from 221.194.47.229 port 33058 [preauth]
Sep 29 10:05:08 gevara sshd[7035]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.194.47.229 user=root
Sep 29 10:05:13 gevara sshd[7037]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.194.47.229 user=root
Sep 29 10:05:14 gevara sshd[7037]: Failed password for root from 221.194.47.229 port 35103 ssh2
Sep 29 10:05:17 gevara sshd[7037]: Failed password for root from 221.194.47.229 port 35103 ssh2
Sep 29 10:05:18 gevara sshd[7039]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.229.172.76 user=root
Sep 29 10:05:19 gevara sshd[7039]: Failed password for root from 221.229.172.76 port 30319 ssh2
Sep 29 10:05:19 gevara sshd[7037]: Failed password for root from 221.194.47.229 port 35103 ssh2
Sep 29 10:08:57 gevara dbus[525]: [system] Failed to activate service 'org.bluez': timed out
Sep 29 10:09:19 gevara sshd[7311]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=119.249.54.88 user=root
Sep 29 10:09:21 gevara sshd[7311]: Failed password for root from 119.249.54.88 port 49429 ssh2
Sep 29 10:09:26 gevara sshd[7311]: message repeated 2 times: [ Failed password for root from 119.249.54.88 port 49429 ssh2]
Sep 29 10:09:27 gevara sshd[7311]: Received disconnect from 119.249.54.88 port 49429:11: [preauth]
Sep 29 10:09:27 gevara sshd[7311]: Disconnected from 119.249.54.88 port 49429 [preauth]
Sep 29 10:09:27 gevara sshd[7311]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=119.249.54.88 user=root
Sep 29 10:09:29 gevara sshd[7335]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=119.249.54.88 user=root
Sep 29 10:09:31 gevara sshd[7335]: Failed password for root from 119.249.54.88 port 55541 ssh2
Sep 29 10:09:36 gevara sshd[7335]: message repeated 2 times: [ Failed password for root from 119.249.54.88 port 55541 ssh2]
Sep 29 10:09:37 gevara sshd[7335]: Received disconnect from 119.249.54.88 port 55541:11: [preauth]
Sep 29 10:09:37 gevara sshd[7335]: Disconnected from 119.249.54.88 port 55541 [preauth]
Sep 29 10:09:37 gevara sshd[7335]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=119.249.54.88 user=root
Sep 29 10:09:39 gevara sshd[7355]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=119.249.54.88 user=root
Sep 29 10:09:41 gevara sshd[7355]: Failed password for root from 119.249.54.88 port 34660 ssh2
Sep 29 10:15:44 gevara sshd[7474]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.229.172.76 user=root
Sep 29 10:15:45 gevara sshd[7474]: Failed password for root from 221.229.172.76 port 39707 ssh2
Sep 29 10:15:50 gevara sshd[7474]: message repeated 2 times: [ Failed password for root from 221.229.172.76 port 39707 ssh2]
Sep 29 10:15:50 gevara sshd[7474]: Received disconnect from 221.229.172.76 port 39707:11: [preauth]
Sep 29 10:15:50 gevara sshd[7474]: Disconnected from 221.229.172.76 port 39707 [preauth]
et visiblement les tests pour entrer son toujours en cours :
Sep 30 10:51:13 gevara sshd[9748]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.229.172.76 user=root
Sep 30 10:51:14 gevara sshd[9750]: Failed password for root from 121.18.238.109 port 42139 ssh2
Sep 30 10:51:17 gevara sshd[9750]: Failed password for root from 121.18.238.109 port 42139 ssh2
Sep 30 10:51:17 gevara sshd[9750]: Received disconnect from 121.18.238.109 port 42139:11: [preauth]
Sep 30 10:51:17 gevara sshd[9750]: Disconnected from 121.18.238.109 port 42139 [preauth]
Sep 30 10:51:17 gevara sshd[9750]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=121.18.238.109 user=root
Sep 30 10:51:21 gevara sshd[9754]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=121.18.238.109 user=root
Sep 30 10:51:23 gevara sshd[9754]: Failed password for root from 121.18.238.109 port 33234 ssh2
Sep 30 10:51:41 gevara sshd[9762]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.229.172.76 user=root
Sep 30 10:51:43 gevara sshd[9762]: Failed password for root from 221.229.172.76 port 41063 ssh2
(fort heureusement, mon root est inaccessible)
- le retour des commandes :
netstat -tanu
Connexions Internet actives (serveurs et établies)
Proto Recv-Q Send-Q Adresse locale Adresse distante Etat
tcp 0 0 0.0.0.0:9091 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:5900 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:5902 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:6002 0.0.0.0:* LISTEN
tcp 0 0 127.0.1.1:53 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:51413 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN
tcp 0 0 192.168.0.11:51413 208.59.172.218:63746 TIME_WAIT
tcp 0 0 192.168.0.11:51413 79.70.37.215:64353 TIME_WAIT
tcp 0 0 192.168.0.11:51413 112.206.104.223:56884 TIME_WAIT
tcp 0 0 192.168.0.11:51413 208.59.172.218:63742 TIME_WAIT
tcp 0 0 192.168.0.11:40786 207.66.141.182:443 CLOSE_WAIT
tcp 1 0 192.168.0.11:40802 207.66.141.182:443 CLOSE_WAIT
tcp 0 0 192.168.0.11:51413 5.13.167.119:2292 TIME_WAIT
tcp 0 0 192.168.0.11:57992 104.20.40.187:80 ESTABLISHED
tcp 0 1 192.168.0.11:51413 89.140.204.131:4485 FIN_WAIT1
tcp 0 256 192.168.0.11:22 192.168.0.254:53796 ESTABLISHED
tcp 0 0 192.168.0.11:51413 197.149.178.174:64423 TIME_WAIT
tcp6 0 0 :::5900 :::* LISTEN
tcp6 0 0 :::51413 :::* LISTEN
tcp6 0 0 :::22 :::* LISTEN
udp 0 0 0.0.0.0:5353 0.0.0.0:*
udp 0 0 0.0.0.0:47015 0.0.0.0:*
udp 0 0 127.0.1.1:53 0.0.0.0:*
udp 0 0 0.0.0.0:68 0.0.0.0:*
udp 0 0 192.168.0.11:123 0.0.0.0:*
udp 0 0 127.0.0.1:123 0.0.0.0:*
udp 0 0 0.0.0.0:123 0.0.0.0:*
udp 0 0 0.0.0.0:51413 0.0.0.0:*
udp6 0 0 fe80::d869:80da:6bc:123 :::*
udp6 0 0 ::1:123 :::*
udp6 0 0 :::123 :::*
top
top - 10:54:04 up 13:07, 2 users, load average: 0,03, 0,04, 0,00
Tâches: 156 total, 1 en cours, 155 en veille, 0 arrêté, 0 zombie
%Cpu(s): 2,8 ut, 0,3 sy, 0,1 ni, 96,8 id, 0,0 wa, 0,0 hi, 0,0 si, 0,0 st
KiB Mem : 4029024 total, 644600 libr, 979972 util, 2404452 tamp/cache
KiB Éch: 19530748 total, 19527960 libr, 2788 util. 2694648 dispo Mem
PID UTIL. PR NI VIRT RES SHR S %CPU %MEM TEMPS+ COM.
9857 fredsau+ 20 0 41992 3992 3312 R 11,8 0,1 0:00.02 top
1 root 20 0 119924 6080 4000 S 0,0 0,2 0:23.07 systemd
2 root 20 0 0 0 0 S 0,0 0,0 0:00.00 kthreadd
3 root 20 0 0 0 0 S 0,0 0,0 0:00.06 ksoftirqd/0
5 root 0 -20 0 0 0 S 0,0 0,0 0:00.00 kworker/0:0H
7 root 20 0 0 0 0 S 0,0 0,0 0:13.02 rcu_sched
8 root 20 0 0 0 0 S 0,0 0,0 0:00.00 rcu_bh
9 root rt 0 0 0 0 S 0,0 0,0 0:00.03 migration/0
10 root rt 0 0 0 0 S 0,0 0,0 0:00.16 watchdog/0
11 root rt 0 0 0 0 S 0,0 0,0 0:00.17 watchdog/1
12 root rt 0 0 0 0 S 0,0 0,0 0:00.04 migration/1
13 root 20 0 0 0 0 S 0,0 0,0 0:00.42 ksoftirqd/1
15 root 0 -20 0 0 0 S 0,0 0,0 0:00.00 kworker/1:0H
16 root rt 0 0 0 0 S 0,0 0,0 0:00.16 watchdog/2
17 root rt 0 0 0 0 S 0,0 0,0 0:00.03 migration/2
18 root 20 0 0 0 0 S 0,0 0,0 0:00.12 ksoftirqd/2
20 root 0 -20 0 0 0 S 0,0 0,0 0:00.00 kworker/2:0H
21 root rt 0 0 0 0 S 0,0 0,0 0:00.09 watchdog/3
22 root rt 0 0 0 0 S 0,0 0,0 0:00.03 migration/3
23 root 20 0 0 0 0 S 0,0 0,0 0:00.07 ksoftirqd/3
25 root 0 -20 0 0 0 S 0,0 0,0 0:00.00 kworker/3:0H
26 root 20 0 0 0 0 S 0,0 0,0 0:00.00 kdevtmpfs
27 root 0 -20 0 0 0 S 0,0 0,0 0:00.00 netns
28 root 0 -20 0 0 0 S 0,0 0,0 0:00.00 perf
29 root 20 0 0 0 0 S 0,0 0,0 0:00.04 khungtaskd
30 root 0 -20 0 0 0 S 0,0 0,0 0:00.00 writeback
31 root 25 5 0 0 0 S 0,0 0,0 0:00.00 ksmd
32 root 39 19 0 0 0 S 0,0 0,0 0:01.18 khugepaged
33 root 0 -20 0 0 0 S 0,0 0,0 0:00.00 crypto
34 root 0 -20 0 0 0 S 0,0 0,0 0:00.00 kintegrityd
35 root 0 -20 0 0 0 S 0,0 0,0 0:00.00 bioset
dpkg --get-selections |grep minergate*
La commande ne rend rien
Merci,
Fredsaule