|
最近在server上执行last命令看到的结果大为吃惊。。
ftp ftpd6757 192.168.6.22 Mon Sep 8 13:46 - 13:46 (00:00)
ftp ftpd6756 192.168.6.22 Mon Sep 8 13:46 - 13:46 (00:00)
ftp ftpd6755 192.168.6.22 Mon Sep 8 13:46 - 13:46 (00:00)
ftp ftpd6754 192.168.6.22 Mon Sep 8 13:46 - 13:46 (00:00)
ftp ftpd6753 192.168.6.22 Mon Sep 8 13:46 - 13:46 (00:00)
ftp ftpd6752 192.168.6.22 Mon Sep 8 13:46 - 13:46 (00:00)
ftp ftpd6751 192.168.6.22 Mon Sep 8 13:46 - 13:46 (00:00)
ftp ftpd6750 192.168.6.22 Mon Sep 8 13:46 - 13:46 (00:00)
ftp ftpd6749 192.168.6.22 Mon Sep 8 13:46 - 13:46 (00:00)
ftp ftpd6748 192.168.6.22 Mon Sep 8 13:45 - 13:45 (00:00)
de pts/1 192.168.6.56 Sun Aug 3 11:20 - 11:22 (00:02)
kde pts/1 192.168.6.56 Fri Aug 1 17:52 - 17:53 (00:00)
kde pts/1 192.168.6.56 Fri Aug 1 14:29 - 14:33 (00:04)
kde pts/1 192.168.6.56 Fri Aug 1 14:28 - 14:28 (00:00)
kde pts/1 192.168.6.56 Fri Aug 1 14:25 - 14:25 (00:00)
kde pts/1 192.168.6.88 Wed Jun 11 20:46 - 20:47 (00:01)
kde pts/1 192.168.6.88 Tue Jun 10 19:27 - 19:28 (00:01)
kde pts/1 192.168.6.88 Tue Jun 10 19:18 - 19:19 (00:01)
kde pts/1 192.168.6.88 Tue Jun 10 19:13 - 19:17 (00:04)
kde pts/1 192.168.6.88 Tue Jun 10 17:01 - 17:07 (00:05)
kde pts/1 192.168.6.88 Tue Jun 10 16:50 - 16:51 (00:01)
kde pts/1 192.168.6.88 Tue Jun 10 16:31 - 16:31 (00:00)
kde pts/1 192.168.6.88 Tue Jun 10 16:06 - 16:07 (00:01)
kde pts/1 192.168.6.88 Sun Jun 8 21:45 - 21:45 (00:00)
kde pts/1 192.168.6.88 Sun Jun 8 16:06 - 16:07 (00:00)
kde pts/1 192.168.6.88 Fri Jun 6 21:20 - 21:20 (00:00)
kde pts/1 192.168.6.88 Fri Jun 6 21:05 - 21:07 (00:01)
kde pts/1 192.168.6.88 Fri Jun 6 14:35 - 14:35 (00:00)
kde pts/1 192.168.6.88 Fri Jun 6 14:34 - 14:35 (00:00)
kde pts/1 192.168.6.88 Fri Jun 6 14:29 - 14:34 (00:05)
gnome pts/1 192.168.6.60 Fri Dec 12 15:40 - 15:43 (00:03)
vi /etc/passwd
kde :0:80:kde:/var/desktop:/bin/bash
是否表明ftp,kde,gnome用户远程登陆过系统???
如果是,他们能用什么方式登陆啊。因为我提供的ssh服务,只允许tom一个用户可以登陆。我是不是遇到敌人。而且192.168.6.88经证实是我们公司一个人的ip,他是软件组的。能不能就凭这个判断他确实登陆过我的机器?而且我看了别的linux机器好像没有kde,gnome用户。。是不是入侵者自己添加的?? |
|