开启frpc进程后,ssh日志不断刷新尝试登录日志
Bug Description
开启frpc进程后,ssh日志不断刷新尝试登录日志
frpc Version
0.44.0
frps Version
0.39.1
System Architecture
linux/amd64
Configurations
[common] server_addr = xxxxx server_port = xxx token = [sftp] type = tcp local_ip = xxx local_port = xxx remote_port = xxx
Logs
Aug 15 18:28:54 sftpsvr sshd[17300]: Received disconnect from 127.0.0.1 port 60746:11: Normal Shutdown, Thank you for playing [preauth] Aug 15 18:28:54 sftpsvr sshd[17300]: Disconnected from 127.0.0.1 port 60746 [preauth] Aug 15 18:29:03 sftpsvr sshd[17302]: Invalid user licongcong from 127.0.0.1 port 60748 Aug 15 18:29:03 sftpsvr sshd[17302]: input_userauth_request: invalid user licongcong [preauth] Aug 15 18:29:03 sftpsvr sshd[17302]: Received disconnect from 127.0.0.1 port 60748:11: Normal Shutdown, Thank you for playing [preauth] Aug 15 18:29:03 sftpsvr sshd[17302]: Disconnected from 127.0.0.1 port 60748 [preauth] Aug 15 18:29:13 sftpsvr sshd[17304]: Invalid user licongcong from 127.0.0.1 port 60750 Aug 15 18:29:13 sftpsvr sshd[17304]: input_userauth_request: invalid user licongcong [preauth] Aug 15 18:29:14 sftpsvr sshd[17304]: Received disconnect from 127.0.0.1 port 60750:11: Normal Shutdown, Thank you for playing [preauth] Aug 15 18:29:14 sftpsvr sshd[17304]: Disconnected from 127.0.0.1 port 60750 [preauth]
Steps to reproduce
...
Affected area
- [ ] Docs
- [ ] Installation
- [ ] Performance and Scalability
- [X] Security
- [ ] User Experience
- [ ] Test and Release
- [ ] Developer Infrastructure
- [ ] Client Plugin
- [ ] Server Plugin
- [ ] Extensions
- [ ] Others
恶意爆破,尝试更换其他端口或换用stcp
这是基本常识,SSH 端口暴露出去会被扫 + 爆破。要么改用私钥登录,关闭密码登录;要么采取一些流量控制措施或 fail2ban 之类的应用抑制登录尝试次数;还可以尝试一些蜜罐应用。
Issues go stale after 30d of inactivity. Stale issues rot after an additional 7d of inactivity and eventually close.