Deux choses m’interpellent ce matin :
le résultat quotidien de logwatch :
[quote]--------------------- SSHD Begin ------------------------
Users logging in through sshd:
ricardo:
192.168.1.9: 1 time
Received disconnect:
11: disconnected by user : 1 Time(s)
---------------------- SSHD End ---------
[/quote]
Alors que je n’ai pas d’IP…“9”
et ensuite, en me connectant sur le serveur en ssh, je vois un dernière connexion hier à 15:05, avec cette IP.
[quote]ricardo@sid-sda8:~$ ssh -p XXXXXX 192.168.1.2
ricardo@192.168.1.2’s password:
Linux serveur 2.6.32-5-amd64 #1 SMP Wed Jan 12 03:40:32 UTC 2011 x86_64
The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
You have mail.
Last login: Thu Mar 3 15:05:45 2011 from 192.168.1.9
[/quote]
OÙ DOIS-JE ALLER POUR VÉRIFIER SI INTRUSION ET COMMENT PARER À UN RENOUVELLEMENT ?
