Úkol č.1
Přihlaste se pomocí Bitvise ssh klienta na vzdálený počítač s IP adresou 10.1.1.197. Vaše uživatelské jméno a heslo dostanete na papírku. Papírek s heslem nevyhazujte, ale bezpečně ho uschovejte, bude se hodit. Vygenerujte si pár klíčů, veřejný klíč nakopírujte ho na vzdálený počítač a přidejte ho do ~/.ssh/authorized_keys. Klíč můžete generovat buď typu RSA nebo lépe Ed25519. Export veřejného klíče musíte udělat v OpenSSH formátu.


cat muj_verejny_klic.pub >> ~/.ssh/authorized_keys (1)
| 1 | Znak vlnovka ~ znamená váš domovský adresář. |
Poté se přihlaste klíčem.
| Úkoly budou průběžně známkovány. |
Úkol č.2
Na vzdáleném stroji si vytvořte adresář (složku) pomocí příkazu mkdir
cd (1)
mkdir klice (2)
chmod 700 klice (3)
| 1 | Přepnutí do domovského adresáře. |
| 2 | Vytvoření adresáře klice ve vašem domovském adresáři. |
| 3 | Změna přístupových práv k adresáři klice, od teď může číst a měnit adresář jenom vlastník, tj. vy a nikdo jiný. |
Nakopírujte si oba klíče, na vzdálený stroj do tohoto adresáře.
Úkol č.3
Pokud jste si nezabezpečili privátní klíč heslem, tak si ho zabezpečte. Jinak ho smažte. Ne však tak, že ho vyhodíte do koše, ale otevřte ho pomocí Notepadu a přepište ho nesmysly, uložte a potom smažte. Nezapomeňte ve Windows vysypat koš, jinak jste soubor nesmazali.
Výsledky
Aby mohl správce vzdáleného stroje vidět kdo a jakým způsobem používá ssh, či případně řešit řešit problémy, k tomu slouží log soubor. Na našem stroji je to /var/log/authlog
Podíváme se na výpis logu, který pořídíme příkazem cat /var/log/authlog.
mujbsd# cat /var/log/authlog
2023-05-02T06:00:01.697Z mujbsd newsyslog[66992]: logfile turned over
May 2 08:11:26 mujbsd sshd[79717]: Received disconnect from 10.1.1.170 port 65385:11: FlowSshClientSession: host key rejected [preauth]
May 2 08:11:26 mujbsd sshd[79717]: Disconnected from 10.1.1.170 port 65385 [preauth]
May 2 08:12:28 mujbsd sshd[83365]: Received disconnect from 10.1.1.237 port 58682:11: FlowSshClientSession: host key rejected [preauth]
May 2 08:12:28 mujbsd sshd[83365]: Disconnected from 10.1.1.237 port 58682 [preauth]
May 2 08:12:41 mujbsd sshd[87382]: Accepted password for broulikova.jana from 10.1.1.143 port 53225 ssh2
May 2 08:12:42 mujbsd sshd[11217]: Accepted password for uzdil.jakub from 10.1.1.154 port 49956 ssh2
May 2 08:12:42 mujbsd sshd[78342]: Accepted password for krska.dominik from 10.1.1.145 port 51469 ssh2
May 2 08:12:43 mujbsd sshd[88981]: Accepted password for homolkova.adela from 10.1.1.237 port 58683 ssh2
May 2 08:12:44 mujbsd sshd[64279]: Accepted password for hofman.vojtech from 10.1.1.189 port 60480 ssh2
May 2 08:12:56 mujbsd sshd[74178]: Invalid user shaposhnikova.milana from 10.1.1.177 port 53130
May 2 08:12:56 mujbsd sshd[74178]: Failed password for invalid user shaposhnikova.milana from 10.1.1.177 port 53130 ssh2
May 2 08:13:13 mujbsd sshd[74178]: Failed password for invalid user shaposhnikova.milana from 10.1.1.177 port 53130 ssh2
May 2 08:13:15 mujbsd sshd[74178]: error: Received disconnect from 10.1.1.177 port 53130:13: User request [preauth]
May 2 08:13:15 mujbsd sshd[74178]: Disconnected from invalid user shaposhnikova.milana 10.1.1.177 port 53130 [preauth]
May 2 08:13:20 mujbsd sshd[79146]: Invalid user shaposhnikova.milana from 10.1.1.177 port 53132
May 2 08:13:20 mujbsd sshd[79146]: Failed password for invalid user shaposhnikova.milana from 10.1.1.177 port 53132 ssh2
May 2 08:13:21 mujbsd sshd[79146]: error: Received disconnect from 10.1.1.177 port 53132:13: User request [preauth]
May 2 08:13:21 mujbsd sshd[79146]: Disconnected from invalid user shaposhnikova.milana 10.1.1.177 port 53132 [preauth]
May 2 08:13:23 mujbsd sshd[59278]: Accepted password for melnychuk.viktoria from 10.1.1.186 port 51781 ssh2
May 2 08:13:25 mujbsd sshd[12164]: Invalid user shaposhnikova.milana from 10.1.1.177 port 53133
May 2 08:13:25 mujbsd sshd[12164]: Failed password for invalid user shaposhnikova.milana from 10.1.1.177 port 53133 ssh2
May 2 08:13:25 mujbsd sshd[44589]: Invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55902
May 2 08:13:25 mujbsd sshd[44589]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55902 ssh2
May 2 08:13:30 mujbsd sshd[49011]: Accepted password for sobotka.jan from 10.1.1.181 port 62073 ssh2
May 2 08:13:42 mujbsd sshd[44589]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55902 ssh2
May 2 08:13:42 mujbsd sshd[44589]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55902 ssh2
May 2 08:13:56 mujbsd sshd[74776]: Accepted publickey for jirka.chraska from 10.5.0.168 port 57865 ssh2: RSA SHA256:8wiSt6ofDrmmeZl6N+AdiQuXCQuLDbhum0+FCD1LF8M
May 2 08:14:09 mujbsd sshd[5548]: subsystem request for publickey by user sobotka.jan failed, subsystem not found
May 2 08:14:11 mujbsd sshd[12164]: Failed password for invalid user shaposhnikova.milana from 10.1.1.177 port 53133 ssh2
May 2 08:14:12 mujbsd sshd[44589]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55902 ssh2
May 2 08:14:13 mujbsd sshd[44589]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55902 ssh2
May 2 08:14:18 mujbsd sshd[44589]: error: Received disconnect from 10.1.1.243 port 55902:13: User request [preauth]
May 2 08:14:18 mujbsd sshd[44589]: Disconnected from invalid user shaposhnikova.yelizaeta 10.1.1.243 port 55902 [preauth]
May 2 08:14:19 mujbsd sshd[21449]: Invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55912
May 2 08:14:19 mujbsd sshd[21449]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55912 ssh2
May 2 08:14:21 mujbsd sshd[27511]: Accepted password for hornof.adam from 10.1.1.170 port 65438 ssh2
May 2 08:14:21 mujbsd sshd[21449]: error: Received disconnect from 10.1.1.243 port 55912:13: User request [preauth]
May 2 08:14:21 mujbsd sshd[21449]: Disconnected from invalid user shaposhnikova.yelizaeta 10.1.1.243 port 55912 [preauth]
May 2 08:14:23 mujbsd sshd[70147]: Invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55913
May 2 08:14:23 mujbsd sshd[70147]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55913 ssh2
May 2 08:14:26 mujbsd sshd[3783]: Accepted password for vajgl.michal from 10.1.1.178 port 61491 ssh2
May 2 08:14:30 mujbsd sshd[80393]: Accepted password for padevet.radek from 10.1.1.185 port 49981 ssh2
May 2 08:14:31 mujbsd sshd[41582]: subsystem request for publickey by user padevet.radek failed, subsystem not found
May 2 08:14:39 mujbsd sshd[12725]: subsystem request for publickey by user vajgl.michal failed, subsystem not found
May 2 08:14:40 mujbsd sshd[70147]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55913 ssh2
May 2 08:14:41 mujbsd sshd[70147]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55913 ssh2
May 2 08:14:46 mujbsd sshd[12164]: Failed password for invalid user shaposhnikova.milana from 10.1.1.177 port 53133 ssh2
May 2 08:14:47 mujbsd sshd[12725]: subsystem request for publickey by user vajgl.michal failed, subsystem not found
May 2 08:14:55 mujbsd sshd[41582]: subsystem request for publickey by user padevet.radek failed, subsystem not found
May 2 08:15:17 mujbsd sshd[70147]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55913 ssh2
May 2 08:15:25 mujbsd sshd[12164]: fatal: Timeout before authentication for 10.1.1.177 port 53133
May 2 08:15:25 mujbsd sshd[6959]: Received disconnect from 10.1.1.146 port 62727:11: FlowSshClientSession: host key rejected [preauth]
May 2 08:15:25 mujbsd sshd[6959]: Disconnected from 10.1.1.146 port 62727 [preauth]
May 2 08:15:31 mujbsd sshd[70147]: error: Received disconnect from 10.1.1.243 port 55913:13: User request [preauth]
May 2 08:15:31 mujbsd sshd[70147]: Disconnected from invalid user shaposhnikova.yelizaeta 10.1.1.243 port 55913 [preauth]
May 2 08:15:34 mujbsd sshd[96112]: Invalid user shaposhnikova.milana from 10.1.1.177 port 53149
May 2 08:15:34 mujbsd sshd[96112]: Failed password for invalid user shaposhnikova.milana from 10.1.1.177 port 53149 ssh2
May 2 08:15:34 mujbsd sshd[25]: Invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55919
May 2 08:15:34 mujbsd sshd[25]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55919 ssh2
May 2 08:15:35 mujbsd sshd[45368]: Failed password for skvrna.oldrich from 10.1.1.179 port 57922 ssh2
May 2 08:15:52 mujbsd sshd[97295]: Accepted password for galic.djordje from 10.1.1.161 port 52709 ssh2
May 2 08:15:55 mujbsd sshd[56272]: Accepted password for nosal.milos from 10.1.1.240 port 50259 ssh2
May 2 08:15:56 mujbsd sshd[92442]: Accepted password for krulich.filip from 10.1.1.163 port 60338 ssh2
May 2 08:15:57 mujbsd sshd[25]: error: Received disconnect from 10.1.1.243 port 55919:13: User request [preauth]
May 2 08:15:57 mujbsd sshd[25]: Disconnected from invalid user shaposhnikova.yelizaeta 10.1.1.243 port 55919 [preauth]
May 2 08:15:58 mujbsd sshd[45368]: Accepted password for skvrna.oldrich from 10.1.1.179 port 57922 ssh2
May 2 08:15:58 mujbsd sshd[56357]: Invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55922
May 2 08:15:58 mujbsd sshd[56357]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55922 ssh2
May 2 08:16:14 mujbsd sshd[56357]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55922 ssh2
May 2 08:16:14 mujbsd sshd[96112]: Failed password for invalid user shaposhnikova.milana from 10.1.1.177 port 53149 ssh2
May 2 08:16:21 mujbsd sshd[99894]: Accepted password for smola.daniel from 10.1.1.146 port 62729 ssh2
May 2 08:16:22 mujbsd sshd[84954]: error: connect_to 127.0.0.1 port 3389: failed.
May 2 08:16:25 mujbsd sshd[56357]: error: Received disconnect from 10.1.1.243 port 55922:13: User request [preauth]
May 2 08:16:25 mujbsd sshd[56357]: Disconnected from invalid user shaposhnikova.yelizaeta 10.1.1.243 port 55922 [preauth]
May 2 08:16:26 mujbsd sshd[21843]: subsystem request for publickey by user smola.daniel failed, subsystem not found
May 2 08:16:32 mujbsd sshd[96112]: Failed password for invalid user shaposhnikova.milana from 10.1.1.177 port 53149 ssh2
May 2 08:16:38 mujbsd sshd[96112]: error: Received disconnect from 10.1.1.177 port 53149:13: User request [preauth]
May 2 08:16:38 mujbsd sshd[96112]: Disconnected from invalid user shaposhnikova.milana 10.1.1.177 port 53149 [preauth]
May 2 08:16:43 mujbsd sshd[1772]: Invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55929
May 2 08:16:43 mujbsd sshd[1772]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55929 ssh2
May 2 08:16:54 mujbsd sshd[3183]: Invalid user shaposhnikova.milana from 10.1.1.177 port 53158
May 2 08:16:54 mujbsd sshd[3183]: Failed password for invalid user shaposhnikova.milana from 10.1.1.177 port 53158 ssh2
May 2 08:16:56 mujbsd sshd[1772]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55929 ssh2
May 2 08:16:57 mujbsd sshd[1772]: Failed password for invalid user shaposhnikova.yelizaeta from 10.1.1.243 port 55929 ssh2
May 2 08:17:19 mujbsd sshd[3183]: Failed password for invalid user shaposhnikova.milana from 10.1.1.177 port 53158 ssh2
May 2 08:17:53 mujbsd sshd[3183]: Failed password for invalid user shaposhnikova.milana from 10.1.1.177 port 53158 ssh2
May 2 08:17:58 mujbsd sshd[42794]: subsystem request for publickey by user hornof.adam failed, subsystem not found
May 2 08:18:10 mujbsd sshd[3183]: error: Received disconnect from 10.1.1.177 port 53158:13: User request [preauth]
May 2 08:18:10 mujbsd sshd[3183]: Disconnected from invalid user shaposhnikova.milana 10.1.1.177 port 53158 [preauth]
May 2 08:18:17 mujbsd sshd[21929]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53168 ssh2
May 2 08:18:19 mujbsd sshd[66379]: Received disconnect from 10.1.1.177 port 53168:11: FlowSshClientSession: disconnected on user's request
May 2 08:18:19 mujbsd sshd[66379]: Disconnected from user shaposnikova.milana 10.1.1.177 port 53168
May 2 08:18:20 mujbsd sshd[54022]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53169 ssh2
May 2 08:18:22 mujbsd sshd[86296]: Received disconnect from 10.1.1.177 port 53169:11: FlowSshClientSession: disconnected on user's request
May 2 08:18:22 mujbsd sshd[86296]: Disconnected from user shaposnikova.milana 10.1.1.177 port 53169
May 2 08:18:23 mujbsd sshd[31563]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53170 ssh2
May 2 08:18:25 mujbsd sshd[29746]: subsystem request for publickey by user shaposnikova.milana failed, subsystem not found
May 2 08:18:26 mujbsd sshd[1772]: error: Received disconnect from 10.1.1.243 port 55929:13: User request [preauth]
May 2 08:18:26 mujbsd sshd[1772]: Disconnected from invalid user shaposhnikova.yelizaeta 10.1.1.243 port 55929 [preauth]
May 2 08:18:28 mujbsd sshd[29746]: Received disconnect from 10.1.1.177 port 53170:11: FlowSshClientSession: disconnected on user's request
May 2 08:18:28 mujbsd sshd[29746]: Disconnected from user shaposnikova.milana 10.1.1.177 port 53170
May 2 08:18:36 mujbsd sshd[10027]: Invalid user shaposhnikova.yelizaveta from 10.1.1.243 port 55939
May 2 08:18:36 mujbsd sshd[10027]: Failed password for invalid user shaposhnikova.yelizaveta from 10.1.1.243 port 55939 ssh2
May 2 08:18:38 mujbsd sshd[5688]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53171 ssh2
May 2 08:18:39 mujbsd sshd[57341]: Accepted password for valenta.petr from 10.1.1.229 port 51945 ssh2
May 2 08:18:47 mujbsd sshd[10027]: Failed password for invalid user shaposhnikova.yelizaveta from 10.1.1.243 port 55939 ssh2
May 2 08:18:55 mujbsd sshd[54001]: subsystem request for publickey by user broulikova.jana failed, subsystem not found
May 2 08:18:56 mujbsd sshd[93554]: Received disconnect from 10.1.1.177 port 53171:11: FlowSshClientSession: disconnected on user's request
May 2 08:18:56 mujbsd sshd[93554]: Disconnected from user shaposnikova.milana 10.1.1.177 port 53171
May 2 08:18:57 mujbsd sshd[18821]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53174 ssh2
May 2 08:18:57 mujbsd sshd[81963]: Received disconnect from 10.1.1.177 port 53174:11: FlowSshClientSession: disconnected on user's request
May 2 08:18:57 mujbsd sshd[81963]: Disconnected from user shaposnikova.milana 10.1.1.177 port 53174
May 2 08:18:57 mujbsd sshd[62776]: subsystem request for publickey by user krska.dominik failed, subsystem not found
May 2 08:18:59 mujbsd sshd[34296]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53175 ssh2
May 2 08:19:00 mujbsd sshd[90389]: Received disconnect from 10.1.1.177 port 53175:11: FlowSshClientSession: disconnected on user's request
May 2 08:19:00 mujbsd sshd[90389]: Disconnected from user shaposnikova.milana 10.1.1.177 port 53175
May 2 08:19:01 mujbsd sshd[28654]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53176 ssh2
May 2 08:19:01 mujbsd sshd[41032]: Received disconnect from 10.1.1.177 port 53176:11: FlowSshClientSession: disconnected on user's request
May 2 08:19:01 mujbsd sshd[41032]: Disconnected from user shaposnikova.milana 10.1.1.177 port 53176
May 2 08:19:06 mujbsd sshd[83305]: subsystem request for publickey by user hofman.vojtech failed, subsystem not found
May 2 08:19:08 mujbsd sshd[98985]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53177 ssh2
May 2 08:19:09 mujbsd sshd[46685]: Received disconnect from 10.1.1.177 port 53177:11: FlowSshClientSession: disconnected on user's request
May 2 08:19:09 mujbsd sshd[46685]: Disconnected from user shaposnikova.milana 10.1.1.177 port 53177
May 2 08:19:16 mujbsd sshd[62683]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53178 ssh2
May 2 08:19:16 mujbsd sshd[63930]: Received disconnect from 10.1.1.177 port 53178:11: FlowSshClientSession: disconnected on user's request
May 2 08:19:16 mujbsd sshd[63930]: Disconnected from user shaposnikova.milana 10.1.1.177 port 53178
May 2 08:19:17 mujbsd sshd[37538]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53179 ssh2
May 2 08:19:36 mujbsd sshd[10027]: Failed password for invalid user shaposhnikova.yelizaveta from 10.1.1.243 port 55939 ssh2
May 2 08:19:46 mujbsd sshd[10027]: error: Received disconnect from 10.1.1.243 port 55939:13: User request [preauth]
May 2 08:19:46 mujbsd sshd[10027]: Disconnected from invalid user shaposhnikova.yelizaveta 10.1.1.243 port 55939 [preauth]
May 2 08:20:15 mujbsd sshd[429]: subsystem request for publickey by user uzdil.jakub failed, subsystem not found
May 2 08:20:17 mujbsd sshd[63240]: Invalid user shaposhnikova.yelizaveta from 10.1.1.243 port 55961
May 2 08:20:17 mujbsd sshd[63240]: Failed password for invalid user shaposhnikova.yelizaveta from 10.1.1.243 port 55961 ssh2
May 2 08:20:31 mujbsd last message repeated 2 times
May 2 08:20:34 mujbsd sshd[13610]: subsystem request for publickey by user homolkova.adela failed, subsystem not found
May 2 08:21:02 mujbsd sshd[63240]: error: Received disconnect from 10.1.1.243 port 55961:13: User request [preauth]
May 2 08:21:02 mujbsd sshd[63240]: Disconnected from invalid user shaposhnikova.yelizaveta 10.1.1.243 port 55961 [preauth]
May 2 08:21:06 mujbsd sshd[7306]: subsystem request for publickey by user shaposnikova.milana failed, subsystem not found
May 2 08:21:11 mujbsd sshd[39084]: Accepted password for shaposnikova.yelizaveta from 10.1.1.243 port 55970 ssh2
May 2 08:24:13 mujbsd sshd[8156]: subsystem request for publickey by user shaposnikova.yelizaveta failed, subsystem not found
May 2 08:24:20 mujbsd sshd[82545]: subsystem request for publickey by user melnychuk.viktoria failed, subsystem not found
May 2 08:25:53 mujbsd sshd[89093]: Received disconnect from 10.1.1.161 port 52709:11: FlowSshClientSession: disconnected on user's request
May 2 08:25:53 mujbsd sshd[89093]: Disconnected from user galic.djordje 10.1.1.161 port 52709
May 2 08:25:55 mujbsd sshd[84954]: Received disconnect from 10.1.1.163 port 60338:11: FlowSshClientSession: disconnected on user's request
May 2 08:25:55 mujbsd sshd[84954]: Disconnected from user krulich.filip 10.1.1.163 port 60338
May 2 08:26:07 mujbsd sshd[67810]: Accepted password for krulich.filip from 10.1.1.163 port 65185 ssh2
May 2 08:26:10 mujbsd sshd[30523]: Accepted password for galic.djordje from 10.1.1.161 port 53049 ssh2
May 2 08:26:12 mujbsd sshd[62864]: Received disconnect from 10.1.1.240 port 50259:11: FlowSshClientSession: disconnected on user's request
May 2 08:26:12 mujbsd sshd[62864]: Disconnected from user nosal.milos 10.1.1.240 port 50259
May 2 08:27:06 mujbsd sshd[42187]: Accepted password for nosal.milos from 10.1.1.240 port 50338 ssh2
May 2 08:31:04 mujbsd sshd[68693]: Received disconnect from 10.1.1.142 port 62793:11: FlowSshClientSession: host key rejected [preauth]
May 2 08:31:04 mujbsd sshd[68693]: Disconnected from 10.1.1.142 port 62793 [preauth]
May 2 08:31:25 mujbsd sshd[66126]: Accepted password for pataky.marcus from 10.1.1.142 port 62794 ssh2
May 2 08:43:56 mujbsd sshd[38488]: subsystem request for publickey by user jirka.chraska failed, subsystem not found
May 2 08:50:55 mujbsd sshd[59618]: subsystem request for publickey by user galic.djordje failed, subsystem not found
May 2 08:51:04 mujbsd sshd[34104]: subsystem request for publickey by user nosal.milos failed, subsystem not found
May 2 08:56:02 mujbsd sshd[21843]: Received disconnect from 10.1.1.146 port 62729:11: FlowSshClientSession: disconnected on user's request
May 2 08:56:02 mujbsd sshd[21843]: Disconnected from user smola.daniel 10.1.1.146 port 62729
May 2 08:56:24 mujbsd sshd[33978]: Failed password for smola.daniel from 10.1.1.146 port 63153 ssh2
May 2 08:56:53 mujbsd sshd[33978]: Accepted password for smola.daniel from 10.1.1.146 port 63153 ssh2
May 2 08:57:10 mujbsd sshd[56023]: error: connect_to 127.0.0.1 port 3389: failed.
May 2 08:57:16 mujbsd sshd[85112]: Received disconnect from 10.1.1.146 port 63153:11: FlowSshClientSession: disconnected on user's request
May 2 08:57:16 mujbsd sshd[85112]: Disconnected from user smola.daniel 10.1.1.146 port 63153
May 2 08:57:29 mujbsd sshd[3423]: Failed password for smola.daniel from 10.1.1.146 port 63164 ssh2
May 2 08:57:32 mujbsd sshd[3423]: error: Received disconnect from 10.1.1.146 port 63164:13: User request [preauth]
May 2 08:57:32 mujbsd sshd[3423]: Disconnected from authenticating user smola.daniel 10.1.1.146 port 63164 [preauth]
May 2 08:57:48 mujbsd sshd[56023]: subsystem request for publickey by user krulich.filip failed, subsystem not found
May 2 08:58:28 mujbsd sshd[91085]: Accepted password for smola.daniel from 10.1.1.146 port 63172 ssh2
May 2 08:58:35 mujbsd sshd[7306]: subsystem request for publickey by user shaposnikova.milana failed, subsystem not found
May 2 09:00:46 mujbsd sshd[56023]: error: connect_to 127.0.0.1 port 3389: failed.
May 2 09:02:29 mujbsd sshd[62776]: subsystem request for publickey by user krska.dominik failed, subsystem not found
May 2 09:06:28 mujbsd sshd[56023]: Received disconnect from 10.1.1.163 port 65185:11: FlowSshClientSession: disconnected on user's request
May 2 09:06:28 mujbsd sshd[56023]: Disconnected from user krulich.filip 10.1.1.163 port 65185
May 2 09:06:38 mujbsd sshd[33990]: Failed password for krulich.filip from 10.1.1.163 port 63374 ssh2
May 2 09:07:06 mujbsd sshd[33990]: Accepted password for krulich.filip from 10.1.1.163 port 63374 ssh2
May 2 09:07:10 mujbsd sshd[65643]: error: connect_to 127.0.0.1 port 3389: failed.
May 2 09:07:36 mujbsd sshd[96869]: Received disconnect from 10.1.1.146 port 63172:11: FlowSshClientSession: disconnected on user's request
May 2 09:07:36 mujbsd sshd[96869]: Disconnected from user smola.daniel 10.1.1.146 port 63172
May 2 09:09:42 mujbsd sshd[30460]: Received disconnect from 10.1.1.146 port 63968:11: FlowSshClientSession: host key rejected [preauth]
May 2 09:09:42 mujbsd sshd[30460]: Disconnected from 10.1.1.146 port 63968 [preauth]
May 2 09:10:06 mujbsd sshd[74707]: Received disconnect from 10.1.1.142 port 62794:11: FlowSshClientSession: disconnected on user's request
May 2 09:10:06 mujbsd sshd[74707]: Disconnected from user pataky.marcus 10.1.1.142 port 62794
May 2 09:10:14 mujbsd sshd[24406]: Accepted publickey for smola.daniel from 10.1.1.146 port 63971 ssh2: ED25519 SHA256:Zc4ycozl/YyZqHTJzkS+LG3u6g6P9hjeCvV0Iwn++FA
May 2 09:10:38 mujbsd sshd[82892]: Accepted publickey for pataky.marcus from 10.1.1.142 port 63021 ssh2: ED25519 SHA256:DPy2B40hhTQzVB7NROKeRLRkAJ3Gu3Q4P2XODw+tVuE
May 2 09:11:14 mujbsd sshd[85520]: Received disconnect from 10.1.1.142 port 63021:11: FlowSshClientSession: disconnected on user's request
May 2 09:11:14 mujbsd sshd[85520]: Disconnected from user pataky.marcus 10.1.1.142 port 63021
May 2 09:11:25 mujbsd sshd[39353]: Accepted publickey for pataky.marcus from 10.1.1.142 port 63038 ssh2: ED25519 SHA256:DPy2B40hhTQzVB7NROKeRLRkAJ3Gu3Q4P2XODw+tVuE
May 2 09:11:53 mujbsd sshd[42794]: subsystem request for publickey by user hornof.adam failed, subsystem not found
May 2 09:12:49 mujbsd sshd[42794]: Received disconnect from 10.1.1.170 port 65438:11: FlowSshClientSession: disconnected on user's request
May 2 09:12:49 mujbsd sshd[42794]: Disconnected from user hornof.adam 10.1.1.170 port 65438
May 2 09:13:02 mujbsd sshd[5548]: Received disconnect from 10.1.1.181 port 62073:11: FlowSshClientSession: disconnected on user's request
May 2 09:13:02 mujbsd sshd[5548]: Disconnected from user sobotka.jan 10.1.1.181 port 62073
May 2 09:13:35 mujbsd sshd[14216]: Accepted publickey for sobotka.jan from 10.1.1.181 port 62585 ssh2: RSA SHA256:6YUiaJRik0YuZk1dP3TjmTwpVfjHy7lO1tbHX9TBl7M
May 2 09:19:12 mujbsd sshd[65643]: Received disconnect from 10.1.1.163 port 63374:11: FlowSshClientSession: disconnected on user's request
May 2 09:19:12 mujbsd sshd[65643]: Disconnected from user krulich.filip 10.1.1.163 port 63374
May 2 09:19:35 mujbsd sshd[93264]: error: Received disconnect from 10.1.1.163 port 57477:13: User request [preauth]
May 2 09:19:35 mujbsd sshd[93264]: Disconnected from authenticating user krulich.filip 10.1.1.163 port 57477 [preauth]
May 2 09:21:02 mujbsd sshd[99557]: Received disconnect from 10.1.1.181 port 62585:11: FlowSshClientSession: disconnected on user's request
May 2 09:21:02 mujbsd sshd[99557]: Disconnected from user sobotka.jan 10.1.1.181 port 62585
May 2 09:21:08 mujbsd sshd[78422]: Received disconnect from 10.1.1.146 port 63971:11: FlowSshClientSession: disconnected on user's request
May 2 09:21:08 mujbsd sshd[78422]: Disconnected from user smola.daniel 10.1.1.146 port 63971
May 2 09:21:20 mujbsd sshd[98862]: Received disconnect from 10.1.1.142 port 63038:11: FlowSshClientSession: disconnected on user's request
May 2 09:21:20 mujbsd sshd[98862]: Disconnected from user pataky.marcus 10.1.1.142 port 63038
May 2 09:21:32 mujbsd sshd[82545]: Received disconnect from 10.1.1.186 port 51781:11: FlowSshClientSession: disconnected on user's request
May 2 09:21:32 mujbsd sshd[82545]: Disconnected from user melnychuk.viktoria 10.1.1.186 port 51781
May 2 09:22:26 mujbsd sshd[10978]: Received disconnect from 10.1.1.179 port 57922:11: FlowSshClientSession: disconnected on user's request
May 2 09:22:26 mujbsd sshd[10978]: Disconnected from user skvrna.oldrich 10.1.1.179 port 57922
May 2 09:22:41 mujbsd sshd[41582]: Received disconnect from 10.1.1.185 port 49981:11: FlowSshClientSession: disconnected on user's request
May 2 09:22:41 mujbsd sshd[41582]: Disconnected from user padevet.radek 10.1.1.185 port 49981
May 2 09:22:55 mujbsd sshd[71676]: Accepted publickey for melnychuk.viktoria from 10.1.1.186 port 51786 ssh2: RSA SHA256:G4noboNF7jnqhIesfN7Mfl+gqkURRYKLOQLCVcSTKXA
May 2 09:23:19 mujbsd sshd[12725]: Received disconnect from 10.1.1.178 port 61491:11: FlowSshClientSession: disconnected on user's request
May 2 09:23:19 mujbsd sshd[12725]: Disconnected from user vajgl.michal 10.1.1.178 port 61491
May 2 09:23:58 mujbsd sshd[56219]: error: Received disconnect from 10.1.1.186 port 51792:13: User request [preauth]
May 2 09:23:58 mujbsd sshd[56219]: Disconnected from authenticating user melnychuk.viktoria 10.1.1.186 port 51792 [preauth]
May 2 09:24:01 mujbsd sshd[7306]: subsystem request for publickey by user shaposnikova.milana failed, subsystem not found
May 2 09:24:08 mujbsd sshd[5441]: error: Received disconnect from 10.1.1.186 port 51793:13: User request [preauth]
May 2 09:24:08 mujbsd sshd[5441]: Disconnected from authenticating user melnychuk.viktoria 10.1.1.186 port 51793 [preauth]
May 2 09:24:21 mujbsd sshd[62776]: Received disconnect from 10.1.1.145 port 51469:11: FlowSshClientSession: disconnected on user's request
May 2 09:24:21 mujbsd sshd[62776]: Disconnected from user krska.dominik 10.1.1.145 port 51469
May 2 09:24:21 mujbsd sshd[34104]: Received disconnect from 10.1.1.240 port 50338:11: FlowSshClientSession: disconnected on user's request
May 2 09:24:21 mujbsd sshd[34104]: Disconnected from user nosal.milos 10.1.1.240 port 50338
May 2 09:24:22 mujbsd sshd[54001]: Received disconnect from 10.1.1.143 port 53225:11: FlowSshClientSession: disconnected on user's request
May 2 09:24:22 mujbsd sshd[54001]: Disconnected from user broulikova.jana 10.1.1.143 port 53225
May 2 09:24:29 mujbsd sshd[83305]: Received disconnect from 10.1.1.189 port 60480:11: FlowSshClientSession: disconnected on user's request
May 2 09:24:29 mujbsd sshd[83305]: Disconnected from user hofman.vojtech 10.1.1.189 port 60480
May 2 09:24:45 mujbsd sshd[13610]: subsystem request for publickey by user homolkova.adela failed, subsystem not found
May 2 09:25:34 mujbsd sshd[45562]: error: Received disconnect from 10.1.1.145 port 53076:13: User request [preauth]
May 2 09:25:34 mujbsd sshd[45562]: Disconnected from authenticating user krska.dominik 10.1.1.145 port 53076 [preauth]
May 2 09:25:40 mujbsd sshd[53359]: Failed password for broulikova.jana from 10.1.1.143 port 54051 ssh2
May 2 09:26:11 mujbsd sshd[7306]: Received disconnect from 10.1.1.177 port 53179:11: FlowSshClientSession: disconnected on user's request
May 2 09:26:11 mujbsd sshd[7306]: Disconnected from user shaposnikova.milana 10.1.1.177 port 53179
May 2 09:26:14 mujbsd sshd[35524]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53720 ssh2
May 2 09:26:37 mujbsd sshd[53359]: Failed password for broulikova.jana from 10.1.1.143 port 54051 ssh2
May 2 09:26:38 mujbsd sshd[8156]: subsystem request for publickey by user shaposnikova.yelizaveta failed, subsystem not found
May 2 09:26:41 mujbsd sshd[53359]: error: Received disconnect from 10.1.1.143 port 54051:13: User request [preauth]
May 2 09:26:41 mujbsd sshd[53359]: Disconnected from authenticating user broulikova.jana 10.1.1.143 port 54051 [preauth]
May 2 09:27:50 mujbsd sshd[429]: Received disconnect from 10.1.1.154 port 49956:11: FlowSshClientSession: disconnected on user's request
May 2 09:27:50 mujbsd sshd[429]: Disconnected from user uzdil.jakub 10.1.1.154 port 49956
May 2 09:29:15 mujbsd sshd[13610]: Received disconnect from 10.1.1.237 port 58683:11: FlowSshClientSession: disconnected on user's request
May 2 09:29:15 mujbsd sshd[13610]: Disconnected from user homolkova.adela 10.1.1.237 port 58683
May 2 09:29:31 mujbsd sshd[13429]: Accepted publickey for homolkova.adela from 10.1.1.237 port 62892 ssh2: RSA SHA256:JlCTYwCMq6+PHB4xclcH3k9HvS/2ESv/fGPP9jjKuqc
May 2 09:30:25 mujbsd sshd[80888]: Received disconnect from 10.1.1.237 port 62892:11: FlowSshClientSession: disconnected on user's request
May 2 09:30:25 mujbsd sshd[80888]: Disconnected from user homolkova.adela 10.1.1.237 port 62892
May 2 09:32:03 mujbsd sshd[38488]: Received disconnect from 10.5.0.168 port 57865:11: FlowSshClientSession: disconnected on user's request
May 2 09:32:03 mujbsd sshd[38488]: Disconnected from user jirka.chraska 10.5.0.168 port 57865
May 2 12:54:14 mujbsd sshd[12892]: Accepted publickey for jirka from 192.168.120.242 port 52148 ssh2: ED25519 SHA256:O16P7xQbiYKL4Bx0VEWVTgdFj+WB5NkiCpqLn2oM/jM
May 2 12:54:19 mujbsd sshd[88145]: Received disconnect from 192.168.120.242 port 52148:11: disconnected by user
May 2 12:54:19 mujbsd sshd[88145]: Disconnected from user jirka 192.168.120.242 port 52148
May 2 12:54:25 mujbsd sshd[10609]: Accepted publickey for root from 192.168.120.242 port 57802 ssh2: ED25519 SHA256:O16P7xQbiYKL4Bx0VEWVTgdFj+WB5NkiCpqLn2oM/jM
mujbsd#
Toto je dost nepřehledné, vylepšíme to. Zjistíme, kdo se úspěšně přihlásil heslem (tito mají trojku.):
mujbsd# cat /var/log/authlog | grep 'Accepted password' (1)
May 2 08:12:41 mujbsd sshd[87382]: Accepted password for broulikova.jana from 10.1.1.143 port 53225 ssh2
May 2 08:12:42 mujbsd sshd[11217]: Accepted password for uzdil.jakub from 10.1.1.154 port 49956 ssh2
May 2 08:12:42 mujbsd sshd[78342]: Accepted password for krska.dominik from 10.1.1.145 port 51469 ssh2
May 2 08:12:43 mujbsd sshd[88981]: Accepted password for homolkova.adela from 10.1.1.237 port 58683 ssh2
May 2 08:12:44 mujbsd sshd[64279]: Accepted password for hofman.vojtech from 10.1.1.189 port 60480 ssh2
May 2 08:13:23 mujbsd sshd[59278]: Accepted password for melnychuk.viktoria from 10.1.1.186 port 51781 ssh2
May 2 08:13:30 mujbsd sshd[49011]: Accepted password for sobotka.jan from 10.1.1.181 port 62073 ssh2
May 2 08:14:21 mujbsd sshd[27511]: Accepted password for hornof.adam from 10.1.1.170 port 65438 ssh2
May 2 08:14:26 mujbsd sshd[3783]: Accepted password for vajgl.michal from 10.1.1.178 port 61491 ssh2
May 2 08:14:30 mujbsd sshd[80393]: Accepted password for padevet.radek from 10.1.1.185 port 49981 ssh2
May 2 08:15:52 mujbsd sshd[97295]: Accepted password for galic.djordje from 10.1.1.161 port 52709 ssh2
May 2 08:15:55 mujbsd sshd[56272]: Accepted password for nosal.milos from 10.1.1.240 port 50259 ssh2
May 2 08:15:56 mujbsd sshd[92442]: Accepted password for krulich.filip from 10.1.1.163 port 60338 ssh2
May 2 08:15:58 mujbsd sshd[45368]: Accepted password for skvrna.oldrich from 10.1.1.179 port 57922 ssh2
May 2 08:16:21 mujbsd sshd[99894]: Accepted password for smola.daniel from 10.1.1.146 port 62729 ssh2
May 2 08:18:17 mujbsd sshd[21929]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53168 ssh2
May 2 08:18:20 mujbsd sshd[54022]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53169 ssh2
May 2 08:18:23 mujbsd sshd[31563]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53170 ssh2
May 2 08:18:38 mujbsd sshd[5688]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53171 ssh2
May 2 08:18:39 mujbsd sshd[57341]: Accepted password for valenta.petr from 10.1.1.229 port 51945 ssh2
May 2 08:18:57 mujbsd sshd[18821]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53174 ssh2
May 2 08:18:59 mujbsd sshd[34296]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53175 ssh2
May 2 08:19:01 mujbsd sshd[28654]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53176 ssh2
May 2 08:19:08 mujbsd sshd[98985]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53177 ssh2
May 2 08:19:16 mujbsd sshd[62683]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53178 ssh2
May 2 08:19:17 mujbsd sshd[37538]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53179 ssh2
May 2 08:21:11 mujbsd sshd[39084]: Accepted password for shaposnikova.yelizaveta from 10.1.1.243 port 55970 ssh2
May 2 08:26:07 mujbsd sshd[67810]: Accepted password for krulich.filip from 10.1.1.163 port 65185 ssh2
May 2 08:26:10 mujbsd sshd[30523]: Accepted password for galic.djordje from 10.1.1.161 port 53049 ssh2
May 2 08:27:06 mujbsd sshd[42187]: Accepted password for nosal.milos from 10.1.1.240 port 50338 ssh2
May 2 08:31:25 mujbsd sshd[66126]: Accepted password for pataky.marcus from 10.1.1.142 port 62794 ssh2
May 2 08:56:53 mujbsd sshd[33978]: Accepted password for smola.daniel from 10.1.1.146 port 63153 ssh2
May 2 08:58:28 mujbsd sshd[91085]: Accepted password for smola.daniel from 10.1.1.146 port 63172 ssh2
May 2 09:07:06 mujbsd sshd[33990]: Accepted password for krulich.filip from 10.1.1.163 port 63374 ssh2
May 2 09:26:14 mujbsd sshd[35524]: Accepted password for shaposnikova.milana from 10.1.1.177 port 53720 ssh2
mujbsd#
| 1 | Příkaz grep nám filtruje řádky logu, které obsahují slova 'Accepted password' |
A kdo se úspěšně přihlásil klíčem má jedničku:
mujbsd# cat /var/log/authlog | grep 'Accepted public' (1)
May 2 08:13:56 mujbsd sshd[74776]: Accepted publickey for jirka.chraska from 10.5.0.168 port 57865 ssh2: RSA SHA256:8wiSt6ofDrmmeZl6N+AdiQuXCQuLDbhum0+FCD1LF8M
May 2 09:10:14 mujbsd sshd[24406]: Accepted publickey for smola.daniel from 10.1.1.146 port 63971 ssh2: ED25519 SHA256:Zc4ycozl/YyZqHTJzkS+LG3u6g6P9hjeCvV0Iwn++FA
May 2 09:10:38 mujbsd sshd[82892]: Accepted publickey for pataky.marcus from 10.1.1.142 port 63021 ssh2: ED25519 SHA256:DPy2B40hhTQzVB7NROKeRLRkAJ3Gu3Q4P2XODw+tVuE
May 2 09:11:25 mujbsd sshd[39353]: Accepted publickey for pataky.marcus from 10.1.1.142 port 63038 ssh2: ED25519 SHA256:DPy2B40hhTQzVB7NROKeRLRkAJ3Gu3Q4P2XODw+tVuE
May 2 09:13:35 mujbsd sshd[14216]: Accepted publickey for sobotka.jan from 10.1.1.181 port 62585 ssh2: RSA SHA256:6YUiaJRik0YuZk1dP3TjmTwpVfjHy7lO1tbHX9TBl7M
May 2 09:22:55 mujbsd sshd[71676]: Accepted publickey for melnychuk.viktoria from 10.1.1.186 port 51786 ssh2: RSA SHA256:G4noboNF7jnqhIesfN7Mfl+gqkURRYKLOQLCVcSTKXA
May 2 09:29:31 mujbsd sshd[13429]: Accepted publickey for homolkova.adela from 10.1.1.237 port 62892 ssh2: RSA SHA256:JlCTYwCMq6+PHB4xclcH3k9HvS/2ESv/fGPP9jjKuqc
May 2 12:54:14 mujbsd sshd[12892]: Accepted publickey for jirka from 192.168.120.242 port 52148 ssh2: ED25519 SHA256:O16P7xQbiYKL4Bx0VEWVTgdFj+WB5NkiCpqLn2oM/jM
May 2 12:54:25 mujbsd sshd[10609]: Accepted publickey for root from 192.168.120.242 port 57802 ssh2: ED25519 SHA256:O16P7xQbiYKL4Bx0VEWVTgdFj+WB5NkiCpqLn2oM/jM
May 2 13:15:15 mujbsd sshd[621]: Accepted publickey for jirka from 192.168.120.242 port 56100 ssh2: ED25519 SHA256:O16P7xQbiYKL4Bx0VEWVTgdFj+WB5NkiCpqLn2oM/jM
May 2 13:15:29 mujbsd sshd[69040]: Accepted publickey for root from 192.168.120.242 port 44212 ssh2: ED25519 SHA256:O16P7xQbiYKL4Bx0VEWVTgdFj+WB5NkiCpqLn2oM/jM
mujbsd#
| 1 | Příkaz grep nám filtruje řádky logu, které obsahují slova 'Accepted publickey' |
Ostatní mají kuli.