Accessi ftp

Installazione, configurazione e uso di Ubuntu come server: web, ftp, mail, news, proxy, dns e altro.
viro
Prode Principiante
Messaggi: 137
Iscrizione: mercoledì 14 luglio 2010, 17:55
Sesso: Maschile

Accessi ftp

Messaggio da viro »

Salve a tutti, c'è un comando per capire chi si è loggato negli ultimi due giorni tramite ftp?
Chiedo questo perchè mi trovo delle cartelle nuove (malware) create sul server e non capisco da dove sono entrati. Tramite shell sicuro no, perchè ho visto il log e hanno tentato di accedere ma senza esito positivo.
Perchè altrimenti non so dove cercare.
Grazie è importante.
viro
Prode Principiante
Messaggi: 137
Iscrizione: mercoledì 14 luglio 2010, 17:55
Sesso: Maschile

Re: Accessi ftp

Messaggio da viro »

Ok, ho trovato il file di log era vsftpd.log e ho trovato che hanno eseguito l'accesso credo proprio da li, di seguito il contenuto, qualcuno può aiutarmi a capire il suo significato e capire come sono entrati sul mio server?
Grazie

////////////////////////////////////////


Sun Mar 25 10:11:33 2012 [pid 10068] CONNECT: Client "82.137.15.64"
Sun Mar 25 10:11:34 2012 [pid 10067] [cowl] OK LOGIN: Client "82.137.15.64"
Sun Mar 25 10:14:07 2012 [pid 10069] [cowl] OK MKDIR: Client "82.137.15.64", "/pow"
Sun Mar 25 10:14:49 2012 [pid 10069] [cowl] OK MKDIR: Client "82.137.15.64", "/pow/back"
Sun Mar 25 10:14:51 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/back/dc.pl", 972 bytes, 0.88Kbyte/sec
Sun Mar 25 10:14:55 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/back/nc.tgz", 9690 bytes, 14.50Kbyte/sec
Sun Mar 25 10:15:30 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/back/rk.tgz", 672336 bytes, 18.91Kbyte/sec
Sun Mar 25 10:18:31 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/back/sshmeu.tgz", 5078879 bytes, 27.39Kbyte/sec
Sun Mar 25 10:18:32 2012 [pid 10069] [cowl] OK MKDIR: Client "82.137.15.64", "/pow/expl"
Sun Mar 25 10:18:45 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/1exp.tgz", 78719 bytes, 6.85Kbyte/sec
Sun Mar 25 10:18:46 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/2.6.32.c", 12084 bytes, 16.87Kbyte/sec
Sun Mar 25 10:18:47 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/aroot.pl", 1987 bytes, 4.73Kbyte/sec
Sun Mar 25 10:18:47 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/aroot.sh", 4641 bytes, 7.95Kbyte/sec
Sun Mar 25 10:18:49 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/autorooter.txt", 29143 bytes, 24.75Kbyte/sec
Sun Mar 25 10:18:50 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/broot.pl", 16705 bytes, 19.89Kbyte/sec
Sun Mar 25 10:18:51 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/broot.sh", 4643 bytes, 7.69Kbyte/sec
Sun Mar 25 10:18:53 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/dev.tgz", 49857 bytes, 30.81Kbyte/sec
Sun Mar 25 10:18:54 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/ex2009.tgz", 6143 bytes, 10.00Kbyte/sec
Sun Mar 25 10:20:40 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/expl.tgz", 3598451 bytes, 34.48Kbyte/sec
Sun Mar 25 10:20:41 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/exx2009.tgz", 6376 bytes, 9.90Kbyte/sec
Sun Mar 25 10:20:42 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/ex_cron.sh", 1616 bytes, 4.05Kbyte/sec
Sun Mar 25 10:20:43 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/linux-sendpage.tgz", 6686 bytes, 7.25Kbyte/sec
Sun Mar 25 10:21:44 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/lroot.tgz", 1671561 bytes, 27.13Kbyte/sec
Sun Mar 25 10:21:45 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/ubu.c", 9193 bytes, 11.81Kbyte/sec
Sun Mar 25 10:23:16 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/xpl.tgz", 2140584 bytes, 23.07Kbyte/sec
Sun Mar 25 10:27:54 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/expl/zmeu.tar.gz", 5884588 bytes, 20.67Kbyte/sec
Sun Mar 25 10:27:55 2012 [pid 10069] [cowl] OK MKDIR: Client "82.137.15.64", "/pow/scan"
Sun Mar 25 10:32:29 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/scan/ehcp-scan.tgz", 4740574 bytes, 17.07Kbyte/sec
Sun Mar 25 10:32:31 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/scan/nt.tgz", 44126 bytes, 30.12Kbyte/sec
Sun Mar 25 10:32:33 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/scan/ntu.tgz", 50682 bytes, 31.31Kbyte/sec
Sun Mar 25 10:32:39 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/scan/pma2.tgz", 218317 bytes, 39.56Kbyte/sec
Sun Mar 25 10:32:43 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/scan/scanbunsmpt.zip", 164216 bytes, 38.74Kbyte/sec
Sun Mar 25 10:32:49 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/scan/smtp.tgz", 205227 bytes, 39.46Kbyte/sec
Sun Mar 25 10:33:12 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/scan/tomcat-scan.tgz", 989780 bytes, 41.03Kbyte/sec
Sun Mar 25 10:33:35 2012 [pid 10069] [cowl] OK UPLOAD: Client "82.137.15.64", "/pow/back/dc2.pl", 729 bytes, 0.74Kbyte/sec
Sun Mar 25 10:35:18 2012 [pid 10069] [cowl] FAIL RMDIR: Client "82.137.15.64", "/pow"
Sun Mar 25 10:35:19 2012 [pid 10069] [cowl] FAIL DELETE: Client "82.137.15.64", "/pow"
Sun Mar 25 10:35:23 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/back/dc.pl"
Sun Mar 25 10:35:23 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/back/dc2.pl"
Sun Mar 25 10:35:23 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/back/nc.tgz"
Sun Mar 25 10:35:23 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/back/rk.tgz"
Sun Mar 25 10:35:24 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/back/sshmeu.tgz"
Sun Mar 25 10:35:24 2012 [pid 10069] [cowl] OK RMDIR: Client "82.137.15.64", "/pow/back"
Sun Mar 25 10:35:25 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/1exp.tgz"
Sun Mar 25 10:35:25 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/2.6.32.c"
Sun Mar 25 10:35:25 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/aroot.pl"
Sun Mar 25 10:35:25 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/aroot.sh"
Sun Mar 25 10:35:26 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/autorooter.txt"
Sun Mar 25 10:35:26 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/broot.pl"
Sun Mar 25 10:35:26 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/broot.sh"
Sun Mar 25 10:35:26 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/dev.tgz"
Sun Mar 25 10:35:26 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/ex2009.tgz"
Sun Mar 25 10:35:27 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/ex_cron.sh"
Sun Mar 25 10:35:27 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/expl.tgz"
Sun Mar 25 10:35:27 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/exx2009.tgz"
Sun Mar 25 10:35:27 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/linux-sendpage.tgz"
Sun Mar 25 10:35:27 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/lroot.tgz"
Sun Mar 25 10:35:28 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/ubu.c"
Sun Mar 25 10:35:28 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/xpl.tgz"
Sun Mar 25 10:35:28 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/expl/zmeu.tar.gz"
Sun Mar 25 10:35:28 2012 [pid 10069] [cowl] OK RMDIR: Client "82.137.15.64", "/pow/expl"
Sun Mar 25 10:35:30 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/scan/ehcp-scan.tgz"
Sun Mar 25 10:35:30 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/scan/nt.tgz"
Sun Mar 25 10:35:30 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/scan/ntu.tgz"
Sun Mar 25 10:35:31 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/scan/pma2.tgz"
Sun Mar 25 10:35:31 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/scan/scanbunsmpt.zip"
Sun Mar 25 10:35:31 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/scan/smtp.tgz"
Sun Mar 25 10:35:31 2012 [pid 10069] [cowl] OK DELETE: Client "82.137.15.64", "/pow/scan/tomcat-scan.tgz"
Sun Mar 25 10:35:32 2012 [pid 10069] [cowl] OK RMDIR: Client "82.137.15.64", "/pow/scan"
Sun Mar 25 10:35:32 2012 [pid 10069] [cowl] OK RMDIR: Client "82.137.15.64", "/pow"
Sun Mar 25 10:38:08 2012 [pid 10230] CONNECT: Client "82.137.15.64"
Sun Mar 25 10:38:08 2012 [pid 10229] [cowl] OK LOGIN: Client "82.137.15.64"
Sun Mar 25 15:36:01 2012 [pid 12423] CONNECT: Client "178.162.154.218"
Mon Mar 26 16:07:51 2012 [pid 21314] CONNECT: Client "85.214.234.241"
Tue Mar 27 18:30:11 2012 [pid 31699] CONNECT: Client "89.123.112.78"
Tue Mar 27 18:30:11 2012 [pid 31698] [vhosts] FAIL LOGIN: Client "89.123.112.78"
Thu Mar 29 21:12:37 2012 [pid 22097] CONNECT: Client "178.79.143.178"
Thu Mar 29 21:12:47 2012 [pid 22096] [anonymous] FAIL LOGIN: Client "178.79.143.178"
inc0
Scoppiettante Seguace
Scoppiettante Seguace
Messaggi: 281
Iscrizione: giovedì 6 marzo 2008, 10:38
Contatti:

Re: Accessi ftp

Messaggio da inc0 »

Codice: Seleziona tutto

Sun Mar 25 10:11:34 2012 [pid 10067] [cowl] OK LOGIN: Client "82.137.15.64"
Utente "cowl", con ip 82.137.15.64, ha fatto login con successo: da li ha eseguito dei normali comadni ftp...
KNOWLEDGE IS POWER
http://www.inc0.net
shinpo
Prode Principiante
Messaggi: 11
Iscrizione: lunedì 3 ottobre 2011, 19:38

Re: Accessi ftp

Messaggio da shinpo »

Salve ragazzi avrei bisogno di una mano con dei permessi per un server FTP, non riesco a capire come risolvere. Ho un server FTP creato con Zentyal. Il server funziona ed è tutto ok però ho un piccolo problema
Quello che voglio fare è creare due una cartella per il server però nel momento in cui accede un tipo di account questo è abilitato solo a vedere ed inviare i file sull' FTP mentre se si collega un'altro account questi può vedere inviare e scaricare i file presenti.

Mi sapreste dire come risolvere, credo che devo giocare con il chmod e il chown ma non riesco a intendere come fare.

GRAZIE ragazzi 
Scrivi risposta

Ritorna a “Ubuntu su server”

Chi c’è in linea

Visualizzano questa sezione: 0 utenti iscritti e 4 ospiti