Bonjour,
L'une des sociétés dont je m'occupe vient de recevoir un mail d'une personne se plaignant d'être sujette a des attaques provenant de l'adresse publique fixe de ladite entreprise.
Voila une copie du fichier log de sont firewall :
auth.log:Jun 5 15:36:35 ip-164 sshd[7819]: Failed password for invalid user root from xxx.xxx.xxx.xxx port 51597 ssh2
auth.log:Jun 5 15:36:39 ip-164 sshd[7821]: Failed password for invalid user admin from xxx.xxx.xxx.xxx port 51668 ssh2
auth.log:Jun 5 15:36:43 ip-164 sshd[7824]: Failed password for invalid user test from xxx.xxx.xxx.xxx port 51707 ssh2
auth.log:Jun 5 15:36:51 ip-164 sshd[7826]: Failed password for invalid user guest from xxx.xxx.xxx.xxx port 51799 ssh2
auth.log:Jun 5 15:36:52 ip-164 sshd[7828]: Failed password for invalid user webmaster from xxx.xxx.xxx.xxx port 51985 ssh2
auth.log:Jun 5 15:36:59 ip-164 sshd[7830]: Failed password for invalid user mysql from xxx.xxx.xxx.xxx port 52015 ssh2
auth.log:Jun 5 15:37:00 ip-164 sshd[7832]: Failed password for invalid user oracle from xxx.xxx.xxx.xxx port 52189 ssh2
auth.log:Jun 5 15:37:02 ip-164 sshd[7834]: Failed password for invalid user library from xxx.xxx.xxx.xxx port 52228 ssh2
auth.log:Jun 5 15:37:05 ip-164 sshd[7836]: Failed password for invalid user info from xxx.xxx.xxx.xxx port 52259 ssh2
auth.log:Jun 5 15:37:06 ip-164 sshd[7838]: Failed password for invalid user shell from xxx.xxx.xxx.xxx port 52360 ssh2
auth.log:Jun 5 15:37:07 ip-164 sshd[7840]: Failed password for invalid user linux from xxx.xxx.xxx.xxx port 52384 ssh2
auth.log:Jun 5 15:37:11 ip-164 sshd[7842]: Failed password for invalid user unix from xxx.xxx.xxx.xxx port 52399 ssh2
auth.log:Jun 5 15:37:13 ip-164 sshd[7844]: Failed password for invalid user webadmin from xxx.xxx.xxx.xxx port 52512 ssh2
auth.log:Jun 5 15:37:14 ip-164 sshd[7846]: Failed password for invalid user ftp from xxx.xxx.xxx.xxx port 52550 ssh2
auth.log:Jun 5 15:37:20 ip-164 sshd[7848]: Failed password for invalid user test from xxx.xxx.xxx.xxx port 52573 ssh2
auth.log:Jun 5 15:37:21 ip-164 sshd[7850]: Failed password for invalid user root from xxx.xxx.xxx.xxx port 52656 ssh2
auth.log:Jun 5 15:37:22 ip-164 sshd[7852]: Failed password for invalid user admin from xxx.xxx.xxx.xxx port 52696 ssh2
auth.log:Jun 5 15:37:24 ip-164 sshd[7855]: Failed password for invalid user guest from xxx.xxx.xxx.xxx port 52729 ssh2
auth.log:Jun 5 15:37:25 ip-164 sshd[7857]: Failed password for invalid user master from xxx.xxx.xxx.xxx port 52762 ssh2
auth.log:Jun 5 15:37:25 ip-164 sshd[7859]: Failed password for invalid user apache from xxx.xxx.xxx.xxx port 52789 ssh2
auth.log:Jun 5 15:37:33 ip-164 sshd[7861]: Failed password for invalid user root from xxx.xxx.xxx.xxx port 52806 ssh2
messages:Jun 5 15:36:35 ip-164 sshd[7819]: Failed password for invalid user root from xxx.xxx.xxx.xxx port 51597 ssh2
messages:Jun 5 15:36:39 ip-164 sshd[7821]: Failed password for invalid user admin from xxx.xxx.xxx.xxx port 51668 ssh2
messages:Jun 5 15:36:43 ip-164 sshd[7824]: Failed password for invalid user test from xxx.xxx.xxx.xxx port 51707 ssh2
messages:Jun 5 15:36:51 ip-164 sshd[7826]: Failed password for invalid user guest from xxx.xxx.xxx.xxx port 51799 ssh2
messages:Jun 5 15:36:52 ip-164 sshd[7828]: Failed password for invalid user webmaster from xxx.xxx.xxx.xxx port 51985 ssh2
messages:Jun 5 15:36:59 ip-164 sshd[7830]: Failed password for invalid user mysql from xxx.xxx.xxx.xxx port 52015 ssh2
messages:Jun 5 15:37:00 ip-164 sshd[7832]: Failed password for invalid user oracle from xxx.xxx.xxx.xxx port 52189 ssh2
messages:Jun 5 15:37:02 ip-164 sshd[7834]: Failed password for invalid user library from xxx.xxx.xxx.xxx port 52228 ssh2
messages:Jun 5 15:37:05 ip-164 sshd[7836]: Failed password for invalid user info from xxx.xxx.xxx.xxx port 52259 ssh2
messages:Jun 5 15:37:06 ip-164 sshd[7838]: Failed password for invalid user shell from xxx.xxx.xxx.xxx port 52360 ssh2
messages:Jun 5 15:37:07 ip-164 sshd[7840]: Failed password for invalid user linux from xxx.xxx.xxx.xxx port 52384 ssh2
messages:Jun 5 15:37:11 ip-164 sshd[7842]: Failed password for invalid user unix from xxx.xxx.xxx.xxx port 52399 ssh2
messages:Jun 5 15:37:13 ip-164 sshd[7844]: Failed password for invalid user webadmin from xxx.xxx.xxx.xxx port 52512 ssh2
messages:Jun 5 15:37:14 ip-164 sshd[7846]: Failed password for invalid user ftp from xxx.xxx.xxx.xxx port 52550 ssh2
messages:Jun 5 15:37:20 ip-164 sshd[7848]: Failed password for invalid user test from xxx.xxx.xxx.xxx port 52573 ssh2
messages:Jun 5 15:37:21 ip-164 sshd[7850]: Failed password for invalid user root from xxx.xxx.xxx.xxx port 52656 ssh2
messages:Jun 5 15:37:22 ip-164 sshd[7852]: Failed password for invalid user admin from xxx.xxx.xxx.xxx port 52696 ssh2
messages:Jun 5 15:37:24 ip-164 sshd[7855]: Failed password for invalid user guest from xxx.xxx.xxx.xxx port 52729 ssh2
messages:Jun 5 15:37:25 ip-164 sshd[7857]: Failed password for invalid user master from xxx.xxx.xxx.xxx port 52762 ssh2
messages:Jun 5 15:37:25 ip-164 sshd[7859]: Failed password for invalid user apache from xxx.xxx.xxx.xxx port 52789 ssh2
messages:Jun 5 15:37:33 ip-164 sshd[7861]: Failed password for invalid user root from xxx.xxx.xxx.xxx port 52806 ssh2
Que puis je faire pour régler le problème? Un virus serait il a l'origine des ces problèmes?
Merci d'avance.