Whois scanning my machine???
- on 03.05.07
- Linux
- Digg
- Del.icio.us
wadaw!!!
mesin ku kena scan!!!!
:(( huwaaaaaaaaaaaaaaaa
Mar 5 21:12:01 serv-slack01 sshd[954]: Did not receive identification string from 222.90.73.206 Mar 5 21:16:00 serv-slack01 sshd[956]: Invalid user 64studio from 222.90.73.206 Mar 5 21:16:00 serv-slack01 sshd[956]: Failed password for invalid user 64studio from 222.90.73.206 port 54991 ssh2 Mar 5 21:16:01 serv-slack01 sshd[959]: Invalid user 64studio from 222.90.73.206 Mar 5 21:16:02 serv-slack01 sshd[959]: Failed password for invalid user 64studio from 222.90.73.206 port 55307 ssh2 Mar 5 21:16:03 serv-slack01 sshd[962]: Invalid user aaliyah from 222.90.73.206 Mar 5 21:16:03 serv-slack01 sshd[962]: Failed password for invalid user aaliyah from 222.90.73.206 port 55511 ssh2 Mar 5 21:16:04 serv-slack01 sshd[965]: Invalid user aaliyah from 222.90.73.206 Mar 5 21:16:04 serv-slack01 sshd[965]: Failed password for invalid user aaliyah from 222.90.73.206 port 55664 ssh2 Mar 5 21:16:06 serv-slack01 sshd[968]: Invalid user aaliyah from 222.90.73.206 Mar 5 21:16:06 serv-slack01 sshd[968]: Failed password for invalid user aaliyah from 222.90.73.206 port 55824 ssh2 Mar 5 21:16:07 serv-slack01 sshd[971]: Invalid user aaliyah from 222.90.73.206 … … … Mar 5 21:21:45 serv-slack01 sshd[1692]: Failed password for invalid user sales from 61.78.36.229 port 38280 ssh2 Mar 5 21:21:46 serv-slack01 sshd[1695]: Invalid user admin from 222.90.73.206 Mar 5 21:21:46 serv-slack01 sshd[1695]: Failed password for invalid user admin from 222.90.73.206 port 57210 ssh2 Mar 5 21:21:47 serv-slack01 sshd[1698]: Invalid user admin from 61.78.36.229 Mar 5 21:21:47 serv-slack01 sshd[1698]: Failed password for invalid user admin from 61.78.36.229 port 38412 ssh2 Mar 5 21:21:48 serv-slack01 sshd[1701]: Invalid user admin from 222.90.73.206 Mar 5 21:21:48 serv-slack01 sshd[1701]: Failed password for invalid user admin from 222.90.73.206 port 57697 ssh2 Mar 5 21:21:49 serv-slack01 sshd[1704]: Invalid user andrea from 61.78.36.229 Mar 5 21:21:49 serv-slack01 sshd[1704]: Failed password for invalid user andrea from 61.78.36.229 port 38493 ssh2 Mar 5 21:21:51 serv-slack01 sshd[1708]: Invalid user admin from 222.90.73.206 Mar 5 21:21:51 serv-slack01 sshd[1708]: Failed password for invalid user admin from 222.90.73.206 port 57999 ssh2 Mar 5 21:21:51 serv-slack01 sshd[1710]: Invalid user backup from 61.78.36.229 Mar 5 21:21:51 serv-slack01 sshd[1710]: Failed password for invalid user backup from 61.78.36.229 port 38608 ssh2 Mar 5 21:21:53 serv-slack01 sshd[1714]: Invalid user admin from 222.90.73.206 Mar 5 21:21:53 serv-slack01 sshd[1714]: Failed password for invalid user admin from 222.90.73.206 port 58562 ssh2 Mar 5 21:21:53 serv-slack01 sshd[1715]: Invalid user guest from 61.78.36.229 Mar 5 21:21:53 serv-slack01 sshd[1715]: Failed password for invalid user guest from 61.78.36.229 port 38713 ssh2 Mar 5 21:21:55 serv-slack01 sshd[1723]: Invalid user guest1 from 61.78.36.229 Mar 5 21:21:55 serv-slack01 sshd[1721]: Invalid user admin from 222.90.73.206 … … …
ada 2 IP yang scanning, 222.90.73.206 + 61.78.36.229
root@serv-slack01:~# whois 222.90.73.206 % [whois.apnic.net node-1] % Whois data copyright terms http://www.apnic.net/db/dbcopyright.html inetnum: 222.90.0.0 - 222.91.255.255 netname: CHINANET-SN descr: CHINANET shanxi(SN) province network descr: China Telecom descr: A12,Xin-Jie-Kou-Wai Street descr: Beijing 100088 country: CN admin-c: CH93-AP tech-c: XC10-AP mnt-by: APNIC-HM mnt-lower: MAINT-CHINANET-SHAANXI mnt-routes: MAINT-CHINANET-SHAANXI remarks: This object can only modify by APNIC hostmaster remarks: If you wish to modify this object details please remarks: send email to hostmaster@apnic.net with your remarks: organisation account name in the subject line. changed: hm-changed@apnic.net 20040224 status: ALLOCATED PORTABLE source: APNIC person: Chinanet Hostmaster nic-hdl: CH93-AP e-mail: anti-spam@ns.chinanet.cn.net address: No.31 ,jingrong street,beijing address: 100032 phone: +86-10-58501724 fax-no: +86-10-58501724 country: CN changed: lqing@chinatelecom.com.cn 20051212 mnt-by: MAINT-CHINANET source: APNIC person: Xianghong Cao address: Shaanxi province data communication Bureau address: 8# guangde Road west development zone address: Xi’an city, Shanxi province 710075 address: CN phone: +8629-837-1049 fax-no: +8629-837-1049 e-mail: IPADM@PUBLIC.XA.SN.CN nic-hdl: XC10-AP mnt-by: MAINT-CHINANET-SHAANXI changed: IPADM@PUBLIC.XA.SN.CN 20011203 source: APNIC root@serv-slack01:~# whois 61.78.36.229 Çѱ¹ÀÎÅóÃÃøÈï¿ø(NIDA)ÀÇ ÀÎÅóÃ亸¼¾ÅÃ(KRNIC)°¡ æ°øÇô Whois ¼Âºñ½º ÀԴôÙ. query: 61.78.36.229 # KOREAN öȸ°á°ú´Â ¾Æ·¡¿à °°À¸¸ç, ½Çæ 亸¿à »óÀÌÇÒ ¼ö ÀÖ½À´Ã´Ù. IPv4 ÃÖ¼Ò : 61.78.36.0-61.78.36.255 ³×Æ®¿öÅ© À̸§ : KORNET-INFRA000001 ¿¬°á ISP¸à : KORNET ÇÒ´ç³»¿ª µî·ÃÀà : 20060405 ÇÒ´ç亸°ø°³¿©ºÎ : N [ IPv4 »ç¿ë ±â°ü 亸 ] ±â°ü°ÃÀ¯¹øÈ£ : ORG1600 ±â°ü¸à : (ÃÖ)ÄÉÀÌÆ¼ ÃÖ¼Ò : ¼º³²½Ã ºÃ´ç±¸ äÀÚµ¿ ¿ìÆà ¹øÈ£ : 463-711 [ ³×Æ®¿öÅ© ´ã´çÀÚ Àι° Ã¤º¸ ] ±â°ü¸à : KORNET ÃÖ¼Ò : ¼º³²½Ã ºÃ´ç±¸ äÀÚµ¿ ¿ìÆà ¹øÈ£ : 463-711 ÀüÀÚ ¿ìÆà : ip@krnic.kornet.net ——————————————————————————– ¸¸¾à À§ÀÇ IPv4ÃÖ¼Ò »ç¿ë±â°ü 亸°¡ ¿Ã¹Ù¸£Ãö ¾ÊÀ» °æ¿ì ¾Æ·¡ÀÇ ÇØ´ç ¿¬°á ISP ´ç´çÀÚ¿¡°Ô ¹®ÀÇÇýñ⠹ٶø´Ã´Ù. [ ¿¬°áISPÀÇ IPv4ÃÖ¼Ò Ã¥ÀÓÀÚ Ã¤º¸ ] À̸§ : IPÃÖ¼Ò°ü¸®ÀÚ ÀüÈ ¹øÈ£ : +82-2-3674-5708 ÀüÀÚ ¿ìÆà : ip@krnic.kornet.net [ ¿¬°áISPÀÇ IPv4ÃÖ¼Ò °ü¸®ÀÚ Ã¤º¸ ] À̸§ : IPÃÖ¼Ò´ã´çÀÚ ÀüÈ ¹øÈ£ : +82-2-3674-5708 ÀüÀÚ ¿ìÆà : ip@krnic.kornet.net [ ¿¬°áISPÀÇ Network Abuse ´ã´çÀÚ Ã¤º¸ ] À̸§ : ½ºÆÔ/ÇØÅ·´ã´ç ÀüÈ ¹øÈ£ : +82-2-100-0000 ÀüÀÚ ¿ìÆà : abuse@kornet.net # ENGLISH KRNIC is not an ISP but a National Internet Registry similar to APNIC. The followings is organization information that is using the IPv4 address. IPv4 Address : 61.78.36.0-61.78.36.255 Network Name : KORNET-INFRA000001 Connect ISP Name : KORNET Registration Date : 20060405 Publishes : N [ Organization Information ] Organization ID : ORG1600 Org Name : Korea Telecom Address : Jungja-dong, Bundang-gu, Sungnam-ci Zip Code : 463-711 [ Technical Contact Information ] Org Name : Korea Telecom Address : Jungja-dong, Bundang-gu, Sungnam-ci Zip Code : 463-711 E-Mail : ip@krnic.kornet.net ——————————————————————————– If the above contacts are not reachable, please contact following ISP for further information. [ ISP IPv4 Admin Contact Information ] Name : IP Administrator Phone : +82-2-3674-5708 E-Mail : ip@krnic.kornet.net [ ISP IPv4 Tech Contact Information ] Name : IP Manager Phone : +82-2-3674-5708 E-Mail : ip@krnic.kornet.net [ ISP Network Abuse Contact Information ] Name : Network Abuse Phone : +82-2-100-0000 E-Mail : abuse@kornet.net
Asem asem asem!!!
Kopeds!!!
Asuw!!!
Anjeeeeng!!!
Leave a Reply