[범탱이]님이 남기신 글:
>/var/log/secure
>Jun 22 11:01:26 acekbs xinetd[634]: START: ftp pid=18932
from=61.155.214.29
>Jun 22 11:01:28 acekbs xinetd[634]: EXIT: ftp pid=18932 duration=2(sec)
>Jun 22 14:17:14 acekbs xinetd[634]: START: ftp pid=18947
from=211.42.186.5
>Jun 22 14:17:14 acekbs xinetd[634]: EXIT: ftp pid=18947 duration=0(sec)
>Jun 22 23:58:41 acekbs xinetd[634]: START: ftp pid=18984
from=211.244.216.104
>Jun 22 23:58:41 acekbs xinetd[634]: EXIT: ftp pid=18984 duration=0(sec)
>Jun 23 02:45:01 acekbs xinetd[634]: START: ftp pid=18997
from=219.232.49.15
>Jun 23 02:45:02 acekbs xinetd[634]: START: ftp pid=18998
from=219.232.49.15
>Jun 23 02:45:02 acekbs xinetd[634]: EXIT: ftp pid=18998 duration=0(sec)
>Jun 23 02:45:02 acekbs xinetd[634]: EXIT: ftp pid=18997 duration=1(sec)
>
>/var/log/messages
>Jun 22 23:28:05 acekbs named[8197]: USAGE 1056292085 1055842085
CPU=0.05664u/0.042968s CHILDCPU=0u/0s
>Jun 22 23:28:05 acekbs named[8197]: NSTATS 1056292085 1055842085 A=192 MX=18
AAAA=23 A6=22 ANY=1
>Jun 22 23:28:05 acekbs named[8197]: XSTATS 1056292085 1055842085 RR=58 RNXD=0
RFwdR=0 RDupR=0 RFail=0 RFErr=0 RErr=1 RAXFR=0 RLame=0 ROpts=0 SSysQ=58 SAns=255
SFwdQ=0 SDupQ=0 SErr=0 RQ=256 RIQ=0 RFwdQ=0 RDupQ=0 RTCP=1 SFwdR=0 SFail=0 SFErr=0
SNaAns=0 SNXD=1 RUQ=0 RURQ=0 RUXFR=0 RUUpd=0
>Jun 22 23:58:41 acekbs ftpd[18984]: wu-ftpd - TLS settings: control allow,
client_cert allow, data allow
>Jun 22 23:58:41 acekbs ftpd[18984]: FTP LOGIN FAILED (cannot set guest privileges)
for 211.244.216.104 [211.244.216.104], ftp
>Jun 22 23:58:41 acekbs ftpd[18984]: FTP session closed
>Jun 23 00:28:05 acekbs named[8197]: Cleaned cache of 0 RRsets
>Jun 23 00:28:05 acekbs named[8197]: USAGE 1056295685 1055842085
CPU=0.05664u/0.042968s CHILDCPU=0u/0s
>Jun 23 00:28:05 acekbs named[8197]: NSTATS 1056295685 1055842085 A=192 MX=18
AAAA=23 A6=22 ANY=1
>Jun 23 00:28:05 acekbs named[8197]: XSTATS 1056295685 1055842085 RR=58 RNXD=0
RFwdR=0 RDupR=0 RFail=0 RFErr=0 RErr=1 RAXFR=0 RLame=0 ROpts=0 SSysQ=58 SAns=255
SFwdQ=0 SDupQ=0 SErr=0 RQ=256 RIQ=0 RFwdQ=0 RDupQ=0 RTCP=1 SFwdR=0 SFail=0 SFErr=0
SNaAns=0 SNXD=1 RUQ=0 RURQ=0 RUXFR=0 RUUpd=0
>Jun 23 01:28:05 acekbs named[8197]: Cleaned cache of 0 RRsets
>Jun 23 02:45:01 acekbs ftpd[18997]: wu-ftpd - TLS settings: control allow,
client_cert allow, data allow
>Jun 23 02:45:02 acekbs ftpd[18998]: wu-ftpd - TLS settings: control allow,
client_cert allow, data allow
>Jun 23 02:45:02 acekbs ftpd[18998]: FTP LOGIN FAILED (cannot set guest privileges)
for 219.232.49.15 [219.232.49.15], ftp
>Jun 23 02:45:02 acekbs ftpd[18998]: FTP session closed
>Jun 23 02:45:02 acekbs ftpd[18997]: FTP session closed
>Jun 23 03:28:05 acekbs named[8197]: Cleaned cache of 0 RRsets
>Jun 23 03:28:05 acekbs named[8197]: USAGE 1056306485 1055842085
CPU=0.05664u/0.042968s CHILDCPU=0u/0s
>Jun 23 03:28:05 acekbs named[8197]: NSTATS 1056306485 1055842085 A=194 MX=19
AAAA=23 A6=22 ANY=1
>Jun 23 03:28:05 acekbs named[8197]: XSTATS 1056306485 1055842085 RR=59 RNXD=0
RFwdR=0 RDupR=0 RFail=0 RFErr=0 RErr=1 RAXFR=0 RLame=0 ROpts=0 SSysQ=59 SAns=258
SFwdQ=0 SDupQ=0 SErr=0 RQ=259 RIQ=0 RFwdQ=0 RDupQ=0 RTCP=1 SFwdR=0 SFail=0 SFErr=0
SNaAns=0 SNXD=1 RUQ=0 RURQ=0 RUXFR=0 RUUpd=0
>Jun 22 23:28:05 acekbs named[8197]: Cleaned cache of 0 RRsets
>Jun 22 23:28:05 acekbs named[8197]: USAGE 1056292085 1055842085
CPU=0.05664u/0.042968s CHILDCPU=0u/0s
>Jun 22 23:28:05 acekbs named[8197]: NSTATS 1056292085 1055842085 A=192 MX=18
AAAA=23 A6=22 ANY=1
>Jun 22 23:28:05 acekbs named[8197]: XSTATS 1056292085 1055842085 RR=58 RNXD=0
RFwdR=0 RDupR=0 RFail=0 RFErr=0 RErr=1 RAXFR=0 RLame=0 ROpts=0 SSysQ=58 SAns=255
SFwdQ=0 SDupQ=0 SErr=0 RQ=256 RIQ=0 RFwdQ=0 RDupQ=0 RTCP=1 SFwdR=0 SFail=0 SFErr=0
SNaAns=0 SNXD=1 RUQ=0 RURQ=0 RUXFR=0 RUUpd=0
>Jun 22 23:58:41 acekbs ftpd[18984]: wu-ftpd - TLS settings: control allow,
client_cert allow, data allow
>Jun 22 23:58:41 acekbs ftpd[18984]: FTP LOGIN FAILED (cannot set guest privileges)
for 211.244.216.104 [211.244.216.104], ftp
>Jun 22 23:58:41 acekbs ftpd[18984]: FTP session closed
>Jun 23 00:28:05 acekbs named[8197]: Cleaned cache of 0 RRsets
>Jun 23 00:28:05 acekbs named[8197]: USAGE 1056295685 1055842085
CPU=0.05664u/0.042968s CHILDCPU=0u/0s
>Jun 23 00:28:05 acekbs named[8197]: NSTATS 1056295685 1055842085 A=192 MX=18
AAAA=23 A6=22 ANY=1
>Jun 23 00:28:05 acekbs named[8197]: XSTATS 1056295685 1055842085 RR=58 RNXD=0
RFwdR=0 RDupR=0 RFail=0 RFErr=0 RErr=1 RAXFR=0 RLame=0 ROpts=0 SSysQ=58 SAns=255
SFwdQ=0 SDupQ=0 SErr=0 RQ=256 RIQ=0 RFwdQ=0 RDupQ=0 RTCP=1 SFwdR=0 SFail=0 SFErr=0
SNaAns=0 SNXD=1 RUQ=0 RURQ=0 RUXFR=0 RUUpd=0
>Jun 23 01:28:05 acekbs named[8197]: Cleaned cache of 0 RRsets
>Jun 23 01:28:05 acekbs named[8197]: USAGE 1056299285 1055842085
CPU=0.05664u/0.042968s CHILDCPU=0u/0s
>Jun 23 01:28:05 acekbs named[8197]: NSTATS 1056299285 1055842085 A=193 MX=19
AAAA=23 A6=22 ANY=1
>Jun 23 01:28:05 acekbs named[8197]: XSTATS 1056299285 1055842085 RR=59 RNXD=0
RFwdR=0 RDupR=0 RFail=0 RFErr=0 RErr=1 RAXFR=0 RLame=0 ROpts=0 SSysQ=59 SAns=257
SFwdQ=0 SDupQ=0 SErr=0 RQ=258 RIQ=0 RFwdQ=0 RDupQ=0 RTCP=1 SFwdR=0 SFail=0 SFErr=0
SNaAns=0 SNXD=1 RUQ=0 RURQ=0 RUXFR=0 RUUpd=0
>Jun 23 02:28:05 acekbs named[8197]: Cleaned cache of 0 RRsets
>Jun 23 02:28:05 acekbs named[8197]: USAGE 1056302885 1055842085
CPU=0.05664u/0.042968s CHILDCPU=0u/0s
>Jun 23 02:28:05 acekbs named[8197]: NSTATS 1056302885 1055842085 A=194 MX=19
AAAA=23 A6=22 ANY=1
>Jun 23 02:28:05 acekbs named[8197]: XSTATS 1056302885 1055842085 RR=59 RNXD=0
RFwdR=0 RDupR=0 RFail=0 RFErr=0 RErr=1 RAXFR=0 RLame=0 ROpts=0 SSysQ=59 SAns=258
SFwdQ=0 SDupQ=0 SErr=0 RQ=259 RIQ=0 RFwdQ=0 RDupQ=0 RTCP=1 SFwdR=0 SFail=0 SFErr=0
SNaAns=0 SNXD=1 RUQ=0 RURQ=0 RUXFR=0 RUUpd=0
>Jun 23 02:45:01 acekbs ftpd[18997]: wu-ftpd - TLS settings: control allow,
client_cert allow, data allow
>Jun 23 02:45:02 acekbs ftpd[18998]: wu-ftpd - TLS settings: control allow,
client_cert allow, data allow
>Jun 23 02:45:02 acekbs ftpd[18998]: FTP LOGIN FAILED (cannot set guest privileges)
for 219.232.49.15 [219.232.49.15], ftp
>Jun 23 02:45:02 acekbs ftpd[18998]: FTP session closed
>Jun 23 02:45:02 acekbs ftpd[18997]: FTP session closed
>
>
>/var/log/xferlog
>xferlog.1에는 제가 접근했던거만 있고요 xferlog에는 깨끗하게
아무것도 기록이 없네요.
>
>/etc/shadow 파일에는 암호설정이 *로 되어 있는걸 봐서는 따로
설정이 안된듯 싶습니다.
>
>
>last명령으로 보면
>ftp ftpd18947 211.42.186.5 Sun Jun 22 14:17 - 14:17 (00:00)
>ftp ftpd18932 61.155.214.29 Sun Jun 22 11:01 - 11:01 (00:00)
>ftp ftpd10370 p508BC713.dip0.t Sat Jun 21 06:29 - 06:29
(00:00)
>ftp ftpd9569 211.147.128.5 Fri Jun 20 03:35 - 03:35 (00:00)
>ftp ftpd9549 b105244.adsl.han Thu Jun 19 23:01 - 23:01 (00:00)
>ftp ftpd8963 218.98.87.128 Wed Jun 18 22:39 - 22:39 (00:00)
>ftp ftpd8418 pD9E1C8CB.dip.t- Wed Jun 18 03:59 - 03:59 (00:00)
이런것들이 있네요.
>문제 없는거겠죠?
>
>다시 한번 답변 부탁드립니다.
========================================
....
아 제가 그만 착각을 했네요.... T.T
(착각하도록 질문했네요..)
ftp ftpd2174 211.147.128.5 금 6월 20 03:45:26 +0900 2003
제일 처음 질문한 위의 내용은 lastlog 의 결과가 아니라
last 결과입니다.
# lastlog
....
ftp **Never logged in**
....
이와 같이 나와야 정상입니다.
그러나
# lastlog
...
ftp pts/0 192.168.0.152 월 6월 23 16:39:39 +0900 2003
...
이와같이 ftp 계정이 pts/0 는 tty/0 와 같이 원격로그인이
되었다면 문제가 됩니다.
앞의 로그 기록에서 ftp 는 Anonymous 의 로그 기록입니다.
|