Anmeldung zur Zusammenkunft aller Physik-Fachschaften in (u.A.) Göttingen
by zigzag
Hallo liebe Fachschaften, ZaPFika und ZaPF-Interessierte,
endlich ist es soweit: Die Anmeldung für die Zusammenkunft aller
deutschsprachigen Physik-Fachschaften(ZaPF) im Wintersemester 2021/22
ist geöffnet. Bis zum 31.10. könnt ihr euch unter
https://anmeldung.zapf.in/ <https://anmeldung.zapf.in/>anmelden und von
eurer Fachschaft bestätigen lassen. Achtung gleiches Datum für das Ende
der Anmeldung der Teilnehmenden und Ende der Möglichkeit zur Bestätigung
dieser durch die Fachschaft!
Vom 11.11.2021 bis zum 14.11.2021 können sich die Teilnehmenden bei der
ZaPF über ihre Erfahrungen in der Fachschaftsarbeit austauschen, neue
Ideen für ihre Fachschaft mitnehmen, Themen rund um das Physikstudium
diskutieren und gemeinsame Positionen zu diesen veröffentlichen.
Genauere Informationen zur ZaPF sind auf der Webseite des ZaPF e.V.
unter https://zapfev.de/ <https://zapfev.de/>und im ZaPF-Wiki unter
https://zapf.wiki/Hauptseite <https://zapf.wiki/Hauptseite>zu finden.
Antworten zu Fragen wie "Was bringt es meiner Fachschaft an der ZaPF
teilzunehmen?" und "Was erwartet mich bei auf der ZaPF?", sowie weitere
Informationen zur Winter-ZaPF 2021 könnt ihr auf unserer Webseite
https://zigzag.uni-goettingen.de/
<https://zigzag.uni-goettingen.de/>finden. Und natürlich sind wir auch
als Orga immer für Fragen offen. Schreibt uns einfach eine Mail unter
zigzag(a)uni-goettingen.de.
Trotz der aktuellen Situation kann diese ZaPF endlich wieder (zumindest
teilweise) in Präsenz stattfinden, wenn auch immernochnicht zentral an
einem Standort. Stattdessen ist die Teilnahme sowohl online, als auch in
Präsenz an einem von vier Standorten (Göttingen 1, München, Göttingen 2
und Köln) möglich. Standortpräferenzen werden in der Anmeldung mit
abgefragt. Dabei können wir leider niemanden einen Platz in Präsenz oder
an einem bestimmten Präsenzstandort versprechen, da Faktoren, wie
beispielsweise der Impfstatus für die Verteilung der Teilnehmenden auf
die Standorte ausschlaggebend sein kann(wer sich aus medizinischen
Gründen nicht impfen lassen darf, kann dies gerne unter den Hinweisen
angeben, sodass wir betreffende Person auch für 2G-Standorte/Programm
einplanen können). Die Priorisierung der Plätze durch die Fachschaften
bezieht sich dieses Mal nur auf die Präsenzplätze. Auch hier können wir
allerdings nicht versprechen, das diese genau eingehalten werden können,
wenn es andere auschlaggebende Faktoren gibt. Jegliche inhaltliche
Arbeit wird allerdings online stattfinden und es wird auch online
Freizeit- und Vernetzungsprogramm geben, sodass weiterhin alle
Fachschaftenund Gremienmitgliederdie Möglichkeit haben an der ZaPF
teilzunehmen.
Für die Teilnahme an der ZaPF in Präsenz fällt ein Teilnahmebeitrag
von25Euro für jede*n Teilnehmende*n an. Für die online-Teilnahme ist
hingegen kein Teilnahmebeitrag zu zahlen.Bis zwei Wochen vor
Anmeldeschluss kann eure Fachschaft für die entstehenden Kosten einen
Antrag auf Förderung finanzschwacher Fachschaften an
foerderung(a)zapfev.de stellen.
Die Token zur Bestätigung eurer Anmeldung sollten in den nächsten Tagen
per Post bei eurer Fachschaft ankommen.Solltet ihr momentan keinen
Zugriff auf eure Post haben oder das Token nicht pünktlich bei euch
ankommen schreibt uns bitte zurück, sodass wir euch es per E-Mail
zuschicken können.Bitte beachtet dabei, dass es dieses mal keine
zusätzliche Zeit nach dem Ablauf der Anmeldung gibt, um Teilnehmende zu
bestätigen. Die Bestätigung muss auch innerhalb des Anmeldezeitraumes
geschehen.
Wir freuen uns schon sehr euch hoffentlich bald bei der ZaPF begrüßen zu
dürfen
Eure Orga aus Göttingen
4 Jahre
Logwatch for h2361197.stratoserver.net (Linux)
by root@zapf.in
################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Wed Oct 13 04:42:05 2021
Date Range Processed: yesterday
( 2021-Oct-12 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host: h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [112:113]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
A total of 13 sites probed the server
115.51.121.192
161.35.236.158
161.35.238.241
162.62.117.51
185.183.98.162
188.166.57.57
198.98.56.220
199.195.251.213
209.141.56.41
34.86.35.26
45.141.84.35
61.219.11.151
91.134.146.186
Requests with error response codes
400 Bad Request
null: 14 Time(s)
/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh: 3 Time(s)
/: 2 Time(s)
/config/getuser?index=0: 2 Time(s)
/.env: 1 Time(s)
/ab2g: 1 Time(s)
/ab2h: 1 Time(s)
/sra_{BA195980-CD49-458b-9E23-C84EE0ADCD75}/: 1 Time(s)
mstshash=Administr: 1 Time(s)
404 Not Found
/berlin/team/apple-touch-icon.png: 1 Time(s)
500 Internal Server Error
/: 59 Time(s)
/.env: 13 Time(s)
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 4 Time(s)
/?XDEBUG_SESSION_START=phpstorm: 2 Time(s)
/Autodiscover/Autodiscover.xml: 2 Time(s)
/_ignition/execute-solution: 2 Time(s)
/api/jsonws/invoke: 2 Time(s)
/console/: 2 Time(s)
/ecp/Current/exporttool/microsoft.exchange ... ool.application: 2 Time(s)
/index.php?s=/Index/\x5Cthink\x5Capp/invok ... HelloThinkPHP21: 2 Time(s)
/mifs/.;/services/LogService: 2 Time(s)
/remote/fgt_lang?lang=/../../../..//////// ... lvpn_websession: 2 Time(s)
/robots.txt: 2 Time(s)
/wp-content/plugins/wp-file-manager/readme.txt: 2 Time(s)
/GponForm/diag_Form?style/: 1 Time(s)
/actuator/health: 1 Time(s)
/favicon.ico: 1 Time(s)
/owa/auth/logon.aspx: 1 Time(s)
/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f: 1 Time(s)
/owa/auth/x.js: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
root (223.197.175.91): 53 Time(s)
root (167.99.164.118): 45 Time(s)
root (181.48.60.50): 42 Time(s)
root (122.51.64.115): 40 Time(s)
root (49.234.214.215): 39 Time(s)
root (1.116.178.163): 38 Time(s)
root (109.195.10.65): 38 Time(s)
root (210.21.226.2): 38 Time(s)
root (223.220.251.232): 38 Time(s)
root (103.127.77.78): 37 Time(s)
root (2.236.48.32): 37 Time(s)
root (121.4.180.217): 35 Time(s)
root (87.251.122.178): 35 Time(s)
root (181.49.154.26): 34 Time(s)
root (188.166.22.79): 34 Time(s)
root (52.178.155.67): 34 Time(s)
root (81.70.161.94): 34 Time(s)
root (82.157.186.236): 34 Time(s)
root (p57bdf833.dip0.t-ipconnect.de): 34 Time(s)
root (106.54.149.118): 33 Time(s)
root (14.141.174.123): 33 Time(s)
root (159.65.32.126): 33 Time(s)
root (45.80.64.230): 33 Time(s)
root (69.49.228.198): 33 Time(s)
root (119.29.171.213): 32 Time(s)
root (42.192.79.87): 32 Time(s)
root (82.156.229.10): 32 Time(s)
root (111.161.116.24): 31 Time(s)
root (117.158.4.243): 31 Time(s)
root (121.4.189.2): 31 Time(s)
root (167.172.101.208): 31 Time(s)
root (217.147.174.182): 31 Time(s)
root (49.235.122.197): 31 Time(s)
root (49.248.77.234): 31 Time(s)
unknown (106.55.37.132): 31 Time(s)
root (121.5.162.8): 30 Time(s)
root (153.101.29.178): 30 Time(s)
root (47.254.215.122): 30 Time(s)
root (106.53.121.171): 29 Time(s)
root (51.15.229.198): 28 Time(s)
root (82.157.125.42): 27 Time(s)
root (200.195.169.59): 26 Time(s)
root (117.50.12.89): 25 Time(s)
root (201-26-23-107.dsl.telesp.net.br): 23 Time(s)
root (v160-251-13-98.7xu2.static.cnode.io): 23 Time(s)
root (147.139.30.243): 22 Time(s)
unknown (121.5.162.8): 22 Time(s)
unknown (51.15.229.198): 22 Time(s)
root (120.92.134.94): 21 Time(s)
root (61.28.116.83): 20 Time(s)
unknown (223.197.175.91): 20 Time(s)
root (054441a4.skybroadband.com): 19 Time(s)
root (106.55.37.132): 19 Time(s)
root (91.209.59.71): 19 Time(s)
unknown (121.4.189.2): 19 Time(s)
unknown (217.147.174.182): 19 Time(s)
unknown (49.248.77.234): 19 Time(s)
root (150.158.173.223): 18 Time(s)
root (218.25.140.72): 18 Time(s)
root (49.232.67.184): 18 Time(s)
root (62.234.134.181): 18 Time(s)
unknown (42.192.79.87): 18 Time(s)
unknown (82.156.229.10): 18 Time(s)
unknown (82.157.125.42): 18 Time(s)
root (49.234.99.246): 17 Time(s)
unknown (106.53.121.171): 17 Time(s)
unknown (112.216.93.141): 17 Time(s)
unknown (14.141.174.123): 17 Time(s)
unknown (159.65.32.126): 17 Time(s)
unknown (45.80.64.230): 17 Time(s)
unknown (52.178.155.67): 16 Time(s)
unknown (81.70.161.94): 16 Time(s)
unknown (82.157.186.236): 16 Time(s)
unknown (p57bdf833.dip0.t-ipconnect.de): 16 Time(s)
root (157.245.101.31): 15 Time(s)
root (212.64.90.41): 15 Time(s)
unknown (106.54.149.118): 15 Time(s)
unknown (117.158.4.243): 15 Time(s)
unknown (119.29.171.213): 15 Time(s)
unknown (121.4.180.217): 15 Time(s)
unknown (181.49.154.26): 15 Time(s)
unknown (200.195.169.59): 15 Time(s)
unknown (223.220.251.232): 15 Time(s)
unknown (49.235.122.197): 15 Time(s)
root (1.202.77.126): 13 Time(s)
root (211.144.221.226): 13 Time(s)
root (49.234.41.154): 13 Time(s)
unknown (117.50.12.89): 13 Time(s)
unknown (153.101.29.178): 13 Time(s)
unknown (2.236.48.32): 13 Time(s)
unknown (62.234.134.181): 13 Time(s)
unknown (69.49.228.198): 13 Time(s)
unknown (87.251.122.178): 13 Time(s)
root (1.15.142.88): 12 Time(s)
root (209.141.54.35): 12 Time(s)
unknown (1.116.178.163): 12 Time(s)
unknown (109.195.10.65): 12 Time(s)
unknown (157.245.101.31): 12 Time(s)
unknown (210.21.226.2): 12 Time(s)
root (187.74.245.219): 11 Time(s)
unknown (103.127.77.78): 11 Time(s)
unknown (111.161.116.24): 11 Time(s)
unknown (188.166.22.79): 11 Time(s)
unknown (v160-251-13-98.7xu2.static.cnode.io): 11 Time(s)
root (218.94.136.90): 10 Time(s)
unknown (122.51.64.115): 10 Time(s)
unknown (147.139.30.243): 10 Time(s)
unknown (167.172.101.208): 10 Time(s)
unknown (212.64.90.41): 10 Time(s)
unknown (054441a4.skybroadband.com): 9 Time(s)
unknown (49.234.214.215): 9 Time(s)
root (112.216.93.141): 8 Time(s)
unknown (181.48.60.50): 8 Time(s)
unknown (199.19.224.76): 8 Time(s)
unknown (218.25.140.72): 8 Time(s)
unknown (91.209.59.71): 8 Time(s)
unknown (150.158.173.223): 7 Time(s)
unknown (176.111.173.237): 7 Time(s)
unknown (187.74.245.219): 7 Time(s)
unknown (201-26-23-107.dsl.telesp.net.br): 7 Time(s)
unknown (218.94.136.90): 7 Time(s)
unknown (47.254.215.122): 7 Time(s)
unknown (49.232.139.137): 7 Time(s)
unknown (61.28.116.83): 7 Time(s)
root (123.59.120.107): 6 Time(s)
unknown (141.98.10.82): 6 Time(s)
unknown (146.185.79.101): 6 Time(s)
unknown (185.90.136.69): 6 Time(s)
unknown (209.141.55.232): 6 Time(s)
unknown (49.232.67.184): 6 Time(s)
unknown (49.234.99.246): 6 Time(s)
root (185.6.91.219): 5 Time(s)
root (49.232.139.137): 5 Time(s)
unknown (1.15.142.88): 5 Time(s)
root (121.5.243.95): 4 Time(s)
root (mail.salsaventura.nl): 4 Time(s)
unknown (120.92.134.94): 4 Time(s)
unknown (185.6.91.219): 4 Time(s)
unknown (205.185.121.149): 4 Time(s)
unknown (209.141.53.99): 4 Time(s)
unknown (49.234.41.154): 4 Time(s)
unknown (51.15.197.4): 4 Time(s)
root (144.135.85.184): 3 Time(s)
root (45.135.232.159): 3 Time(s)
unknown (1.202.77.126): 3 Time(s)
unknown (136.144.41.253): 3 Time(s)
unknown (141.98.10.60): 3 Time(s)
unknown (209.141.54.35): 3 Time(s)
unknown (211.144.221.226): 3 Time(s)
unknown (45.135.232.159): 3 Time(s)
root (058177171112.ctinets.com): 2 Time(s)
root (180.167.18.22): 2 Time(s)
unknown (058177171112.ctinets.com): 2 Time(s)
unknown (1.224.249.138): 2 Time(s)
unknown (121.5.243.95): 2 Time(s)
unknown (141.98.10.121): 2 Time(s)
unknown (141.98.10.81): 2 Time(s)
unknown (144.135.85.184): 2 Time(s)
unknown (46.10.180.39): 2 Time(s)
unknown (81.25.152.154): 2 Time(s)
unknown (82.66.59.170): 2 Time(s)
unknown (host-80-116-71-220.pool80116.interbusiness.it): 2 Time(s)
bin (69.49.228.198): 1 Time(s)
mysql (103.127.77.78): 1 Time(s)
mysql (121.5.162.8): 1 Time(s)
news (47.254.215.122): 1 Time(s)
postgres (119.29.171.213): 1 Time(s)
postgres (69.49.228.198): 1 Time(s)
root (152.136.18.77): 1 Time(s)
root (176.111.173.218): 1 Time(s)
root (193.169.254.234): 1 Time(s)
root (41.137.137.92): 1 Time(s)
root (51.15.197.4): 1 Time(s)
root (66.96.236.91): 1 Time(s)
temp (181.49.154.26): 1 Time(s)
unknown (116.52.1.214): 1 Time(s)
unknown (117.50.119.208): 1 Time(s)
unknown (123.59.120.107): 1 Time(s)
unknown (176.111.173.218): 1 Time(s)
unknown (185.31.175.235): 1 Time(s)
unknown (188.126.89.94): 1 Time(s)
unknown (193.169.254.234): 1 Time(s)
unknown (209.141.59.180): 1 Time(s)
unknown (66.96.236.91): 1 Time(s)
unknown (ip-72-167-47-69.ip.secureserver.net): 1 Time(s)
unknown (mail.salsaventura.nl): 1 Time(s)
unknown (tor-exit1-readme.dfri.se): 1 Time(s)
uucp (103.127.77.78): 1 Time(s)
Invalid Users:
Unknown Account: 906 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
2 Miscellaneous warnings
17.254K Bytes accepted 17,668
17.254K Bytes sent via SMTP 17,668
======== ==================================================
1 Accepted 100.00%
-------- --------------------------------------------------
1 Total 100.00%
======== ==================================================
5 4xx Reject relay denied 100.00%
-------- --------------------------------------------------
5 Total 4xx Rejects 100.00%
======== ==================================================
137 Connections
66 Connections lost (inbound)
137 Disconnections
1 Removed from queue
1 Sent via SMTP
2 Hostname verification errors (FCRDNS)
---------------------- Postfix End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin ------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End -------------------------
--------------------- SSHD Begin ------------------------
Failed logins from:
1.15.142.88: 12 times
1.116.178.163: 38 times
1.202.77.126 (126.77.202.1.static.bjtelecom.net): 13 times
2.236.48.32: 37 times
5.68.65.164 (054441a4.skybroadband.com): 19 times
14.141.174.123 (14.141.174.123.static-vsnl.net.in): 33 times
41.137.137.92: 1 time
42.192.79.87: 32 times
45.80.64.230: 33 times
45.135.232.159: 3 times
47.254.215.122: 31 times
49.232.67.184: 18 times
49.232.139.137: 5 times
49.234.41.154: 13 times
49.234.99.246: 17 times
49.234.214.215: 39 times
49.235.122.197: 31 times
49.248.77.234 (static-234.77.248.49-tataidc.co.in): 31 times
51.15.197.4 (4-197-15-51.instances.scw.cloud): 1 time
51.15.229.198 (198-229-15-51.instances.scw.cloud): 28 times
52.178.155.67: 34 times
58.177.171.112 (058177171112.ctinets.com): 2 times
61.28.116.83: 20 times
62.234.134.181: 18 times
66.96.236.91 (host-66-96-236-91.myrepublic.co.id): 1 time
69.49.228.198 (69-49-228-198.unifiedlayer.com): 35 times
81.70.161.94: 34 times
82.156.229.10: 32 times
82.157.125.42: 27 times
82.157.186.236: 34 times
87.189.248.51 (p57bdf833.dip0.t-ipconnect.de): 34 times
87.251.122.178 (h087251122178.mkr.dsl.sakhalin.ru): 35 times
91.209.59.71: 19 times
103.127.77.78: 39 times
106.53.121.171: 29 times
106.54.149.118: 33 times
106.55.37.132: 19 times
109.195.10.65 (109x195x10x65.static-business.lipetsk.ertelecom.ru): 38 times
111.161.116.24 (dns24.online.tj.cn): 31 times
112.216.93.141: 8 times
117.50.12.89 (sqamtin.cn): 25 times
117.158.4.243: 31 times
119.29.171.213: 33 times
120.92.134.94: 21 times
121.4.180.217: 35 times
121.4.189.2: 31 times
121.5.162.8: 31 times
121.5.243.95: 4 times
122.51.64.115: 40 times
123.59.120.107: 6 times
136.144.138.169 (mail.salsaventura.nl): 4 times
144.135.85.184 (144-135-85-184.tpips.telstra.com): 3 times
147.139.30.243: 22 times
150.158.173.223: 18 times
152.136.18.77: 1 time
153.101.29.178: 30 times
157.245.101.31: 15 times
159.65.32.126: 33 times
160.251.13.98 (v160-251-13-98.7xu2.static.cnode.io): 23 times
167.99.164.118: 45 times
167.172.101.208: 31 times
176.111.173.218: 1 time
180.167.18.22: 2 times
181.48.60.50: 42 times
181.49.154.26: 35 times
185.6.91.219: 5 times
187.74.245.219 (187-74-245-219.dsl.telesp.net.br): 11 times
188.166.22.79: 34 times
193.169.254.234: 1 time
200.195.169.59 (59.169.195.200.static.copel.net): 26 times
201.26.23.107 (201-26-23-107.dsl.telesp.net.br): 23 times
209.141.54.35 (sp2.sonicinternet.net): 12 times
210.21.226.2 (reverse.gdsz.cncnet.net): 38 times
211.144.221.226 (221.226.dsnet): 13 times
212.64.90.41: 15 times
217.147.174.182: 31 times
218.25.140.72: 18 times
218.94.136.90: 10 times
223.197.175.91 (223-197-175-91.static.imsbiz.com): 53 times
223.220.251.232: 38 times
Illegal users from:
undef: 596 times
1.15.142.88: 5 times
1.116.178.163: 12 times
1.202.77.126 (126.77.202.1.static.bjtelecom.net): 3 times
1.224.249.138: 2 times
2.236.48.32: 13 times
5.68.65.164 (054441a4.skybroadband.com): 9 times
14.141.174.123 (14.141.174.123.static-vsnl.net.in): 17 times
42.192.79.87: 18 times
45.80.64.230: 17 times
45.135.232.159: 3 times
46.10.180.39 (46-10-180-39.btc-net.bg): 2 times
47.254.215.122: 7 times
49.232.67.184: 6 times
49.232.139.137: 7 times
49.234.41.154: 4 times
49.234.99.246: 6 times
49.234.214.215: 9 times
49.235.122.197: 15 times
49.248.77.234 (static-234.77.248.49-tataidc.co.in): 19 times
51.15.197.4 (4-197-15-51.instances.scw.cloud): 4 times
51.15.229.198 (198-229-15-51.instances.scw.cloud): 22 times
52.178.155.67: 16 times
58.177.171.112 (058177171112.ctinets.com): 2 times
61.28.116.83: 7 times
62.234.134.181: 13 times
65.49.20.69 (scan-20.shadowserver.org): 1 time
66.96.236.91 (host-66-96-236-91.myrepublic.co.id): 1 time
69.49.228.198 (69-49-228-198.unifiedlayer.com): 13 times
72.167.47.69 (ip-72-167-47-69.ip.secureserver.net): 1 time
80.116.71.220 (host-80-116-71-220.pool80116.interbusiness.it): 2 times
81.25.152.154 (81-25-152-154.junet.se): 2 times
81.70.161.94: 16 times
82.66.59.170 (mar92-2_migr-82-66-59-170.fbx.proxad.net): 2 times
82.156.229.10: 18 times
82.157.125.42: 18 times
82.157.186.236: 16 times
87.189.248.51 (p57bdf833.dip0.t-ipconnect.de): 16 times
87.251.122.178 (h087251122178.mkr.dsl.sakhalin.ru): 13 times
91.209.59.71: 8 times
103.127.77.78: 11 times
106.53.121.171: 17 times
106.54.149.118: 15 times
106.55.37.132: 31 times
109.195.10.65 (109x195x10x65.static-business.lipetsk.ertelecom.ru): 12 times
111.161.116.24 (dns24.online.tj.cn): 11 times
112.216.93.141: 17 times
116.52.1.214: 1 time
117.50.12.89 (sqamtin.cn): 13 times
117.50.119.208: 1 time
117.158.4.243: 15 times
119.29.171.213: 15 times
120.92.134.94: 4 times
121.4.180.217: 15 times
121.4.189.2: 19 times
121.5.162.8: 22 times
121.5.243.95: 2 times
122.51.64.115: 10 times
123.59.120.107: 1 time
136.144.41.253: 3 times
136.144.138.169 (mail.salsaventura.nl): 1 time
141.98.10.60: 3 times
141.98.10.81: 2 times
141.98.10.82: 6 times
141.98.10.121: 2 times
144.135.85.184 (144-135-85-184.tpips.telstra.com): 2 times
146.185.79.101: 6 times
147.139.30.243: 10 times
150.158.173.223: 7 times
153.101.29.178: 13 times
157.245.101.31: 12 times
159.65.32.126: 17 times
160.251.13.98 (v160-251-13-98.7xu2.static.cnode.io): 11 times
167.172.101.208: 10 times
171.25.193.77 (tor-exit1-readme.dfri.se): 1 time
176.111.173.218: 1 time
176.111.173.237: 7 times
181.48.60.50: 8 times
181.49.154.26: 15 times
185.6.91.219: 4 times
185.31.175.235: 1 time
185.90.136.69 (ksort-fi41-sort.betmam.com): 6 times
187.74.245.219 (187-74-245-219.dsl.telesp.net.br): 7 times
188.126.89.94: 1 time
188.166.22.79: 11 times
193.169.254.234: 1 time
199.19.224.76 (kon.is.hentai): 8 times
200.195.169.59 (59.169.195.200.static.copel.net): 15 times
201.26.23.107 (201-26-23-107.dsl.telesp.net.br): 7 times
205.185.121.149: 4 times
209.141.53.99 (abbrinym.com): 4 times
209.141.54.35 (sp2.sonicinternet.net): 3 times
209.141.55.232: 6 times
209.141.59.180 (freedomisnotfree): 1 time
210.21.226.2 (reverse.gdsz.cncnet.net): 12 times
211.144.221.226 (221.226.dsnet): 3 times
212.64.90.41: 10 times
217.147.174.182: 19 times
218.25.140.72: 8 times
218.94.136.90: 7 times
223.197.175.91 (223-197-175-91.static.imsbiz.com): 20 times
223.220.251.232: 15 times
**Unmatched Entries**
fatal: no matching cipher found: client aes256-cbc,rijndael-cbc(a)lysator.liu.se,aes192-cbc,aes128-cbc,arcfour128,arcfour,3des-cbc,none server aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com,chacha20-poly1305@openssh.com [preauth] : 1 time(s)
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/ploop33257p1 394G 242G 132G 65% /
none 4.0G 0 4.0G 0% /dev
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################
4 Jahre
Logwatch for h2361197.stratoserver.net (Linux)
by root@zapf.in
################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Tue Oct 12 04:42:05 2021
Date Range Processed: yesterday
( 2021-Oct-11 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host: h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [ 83:81 ]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
A total of 9 sites probed the server
193.107.216.49
199.195.251.213
209.141.56.41
222.186.19.235
27.115.124.74
64.225.98.138
68.183.198.74
89.233.107.229
91.132.58.79
Requests with error response codes
400 Bad Request
null: 10 Time(s)
/: 4 Time(s)
/config/getuser?index=0: 3 Time(s)
/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh: 2 Time(s)
/66526102: 1 Time(s)
/ab2g: 1 Time(s)
/ab2h: 1 Time(s)
/bag2: 1 Time(s)
/manager/html: 1 Time(s)
/robots.txt: 1 Time(s)
\xD6tI\x19J~0\x88\xB13\xD4C\xCA\x07: 1 Time(s)
mstshash=Administr: 1 Time(s)
499 (undefined)
/_ignition/execute-solution: 1 Time(s)
500 Internal Server Error
/: 54 Time(s)
/.env: 34 Time(s)
/ecp/Current/exporttool/microsoft.exchange ... ool.application: 2 Time(s)
/favicon.ico: 2 Time(s)
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 2 Time(s)
///remote/fgt_lang?lang=/../../../..//////////dev/: 1 Time(s)
//remote/fgt_lang?lang=/../../../..//////////dev/: 1 Time(s)
/?XDEBUG_SESSION_START=phpstorm: 1 Time(s)
/Autodiscover/Autodiscover.xml: 1 Time(s)
/OA_HTML/RF.jsp: 1 Time(s)
/OWA/NSPI/: 1 Time(s)
/actuator/health: 1 Time(s)
/api/jsonws/invoke: 1 Time(s)
/console/: 1 Time(s)
/index.php?s=/Index/\x5Cthink\x5Capp/invok ... HelloThinkPHP21: 1 Time(s)
/owa/auth/logon.aspx: 1 Time(s)
/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f: 1 Time(s)
/owa/auth/x.js: 1 Time(s)
/remote/fgt_lang?lang=/../../../..//////// ... lvpn_websession: 1 Time(s)
/robots.txt: 1 Time(s)
/sitemap.xml: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
root (121.5.45.12): 43 Time(s)
root (178.254.138.66): 43 Time(s)
root (118.25.182.61): 42 Time(s)
root (121.5.154.247): 40 Time(s)
root (82.157.189.241): 40 Time(s)
root (200-148-108-181.dsl.telesp.net.br): 39 Time(s)
root (114.255.252.30): 38 Time(s)
root (121.5.171.213): 38 Time(s)
root (82.156.81.59): 38 Time(s)
root (177.8.172.94): 37 Time(s)
root (66.96.236.91): 37 Time(s)
root (1.117.77.29): 35 Time(s)
root (81.70.178.153): 35 Time(s)
root (123.59.211.63): 34 Time(s)
unknown (159.75.130.111): 34 Time(s)
root (121.4.142.38): 33 Time(s)
root (144.135.85.184): 33 Time(s)
root (49.234.111.57): 33 Time(s)
root (121.5.25.74): 32 Time(s)
root (159.75.126.127): 32 Time(s)
root (49.235.72.35): 32 Time(s)
root (115.159.102.251): 31 Time(s)
root (121.4.175.99): 31 Time(s)
root (121.4.175.37): 30 Time(s)
root (200.123.180.52): 30 Time(s)
root (1.116.211.139): 29 Time(s)
root (81.70.146.107): 29 Time(s)
root (193.112.99.178): 28 Time(s)
root (hsi-kbw-109-193-249-107.hsi7.kabel-badenwuerttemberg.de): 24 Time(s)
root (223.197.175.91): 22 Time(s)
unknown (193.112.99.178): 22 Time(s)
unknown (1.116.211.139): 21 Time(s)
root (1.116.140.147): 20 Time(s)
root (101.34.3.70): 20 Time(s)
root (211.140.196.90): 20 Time(s)
root (45.124.144.116): 20 Time(s)
unknown (121.4.175.37): 20 Time(s)
root (189-089-221-246.static.stratus.com.br): 19 Time(s)
unknown (81.70.146.107): 19 Time(s)
root (49.235.254.75): 18 Time(s)
unknown (121.4.175.99): 18 Time(s)
unknown (121.5.25.74): 18 Time(s)
unknown (49.235.72.35): 18 Time(s)
unknown (115.159.102.251): 17 Time(s)
unknown (159.75.126.127): 17 Time(s)
root (159.75.130.111): 16 Time(s)
unknown (1.117.77.29): 15 Time(s)
unknown (123.59.211.63): 15 Time(s)
unknown (179.60.132.10): 15 Time(s)
unknown (49.234.111.57): 15 Time(s)
root (39.129.9.180): 14 Time(s)
unknown (1.116.140.147): 14 Time(s)
root (185.6.91.219): 13 Time(s)
unknown (121.4.142.38): 13 Time(s)
unknown (177.8.172.94): 13 Time(s)
unknown (81.70.178.153): 13 Time(s)
root (120.92.134.94): 12 Time(s)
unknown (114.255.252.30): 12 Time(s)
unknown (121.5.171.213): 12 Time(s)
unknown (144.135.85.184): 12 Time(s)
unknown (82.156.81.59): 12 Time(s)
root (157.230.230.126): 11 Time(s)
root (v150-95-151-4.a090.g.tyo1.static.cnode.io): 11 Time(s)
unknown (200-148-108-181.dsl.telesp.net.br): 11 Time(s)
unknown (66.96.236.91): 11 Time(s)
root (47.254.215.122): 10 Time(s)
root (h2821125.stratoserver.net): 10 Time(s)
unknown (121.5.154.247): 10 Time(s)
unknown (180.167.18.22): 10 Time(s)
unknown (82.157.189.241): 10 Time(s)
root (89.40.53.35): 9 Time(s)
unknown (211.220.27.191): 9 Time(s)
unknown (hsi-kbw-109-193-249-107.hsi7.kabel-badenwuerttemberg.de): 9 Time(s)
root (61.183.194.150): 8 Time(s)
root (heribay.intertoons.net): 8 Time(s)
unknown (118.25.182.61): 8 Time(s)
unknown (120.92.134.94): 8 Time(s)
unknown (121.5.45.12): 8 Time(s)
unknown (176.111.173.237): 8 Time(s)
unknown (200.123.180.52): 8 Time(s)
unknown (49.235.254.75): 8 Time(s)
unknown (89.40.53.35): 8 Time(s)
root (180.167.18.22): 7 Time(s)
unknown (157.230.230.126): 7 Time(s)
unknown (178.254.138.66): 7 Time(s)
unknown (185.6.91.219): 7 Time(s)
unknown (211.140.196.90): 7 Time(s)
root (60.8.87.190): 6 Time(s)
unknown (141.98.10.82): 6 Time(s)
unknown (171.225.184.186): 6 Time(s)
unknown (176.111.173.238): 6 Time(s)
unknown (189-089-221-246.static.stratus.com.br): 6 Time(s)
unknown (199.19.224.76): 6 Time(s)
root (82.157.125.42): 5 Time(s)
unknown (101.34.3.70): 5 Time(s)
unknown (223.197.175.91): 5 Time(s)
unknown (39.129.9.180): 5 Time(s)
unknown (45.124.144.116): 5 Time(s)
unknown (v150-95-151-4.a090.g.tyo1.static.cnode.io): 5 Time(s)
root (205.185.127.160): 4 Time(s)
root (49.234.41.154): 4 Time(s)
root (76.224.200.35.bc.googleusercontent.com): 4 Time(s)
root (ritvexu-pi1.rit.edu): 4 Time(s)
root (static-186-30-112-151.static.etb.net.co): 4 Time(s)
unknown (205.185.127.160): 4 Time(s)
unknown (209.141.53.99): 4 Time(s)
unknown (49.234.41.154): 4 Time(s)
root (211.220.27.191): 3 Time(s)
unknown (31.184.198.71): 3 Time(s)
unknown (45.155.204.39): 3 Time(s)
unknown (49.232.67.184): 3 Time(s)
unknown (smtp7.calabarblog.com): 3 Time(s)
root (058177171112.ctinets.com): 2 Time(s)
root (49.232.67.184): 2 Time(s)
unknown (125.187.24.45): 2 Time(s)
unknown (141.98.10.121): 2 Time(s)
unknown (171.251.25.233): 2 Time(s)
unknown (205.185.121.149): 2 Time(s)
unknown (212.193.30.64): 2 Time(s)
unknown (222.103.167.174): 2 Time(s)
unknown (47.254.215.122): 2 Time(s)
unknown (58.225.55.143): 2 Time(s)
postfix (180.167.18.22): 1 Time(s)
root (116.110.124.53): 1 Time(s)
root (117.220.15.119): 1 Time(s)
root (fixed-187-188-132-86.totalplay.net): 1 Time(s)
root (v118-27-25-147.4l0s.static.cnode.io): 1 Time(s)
unknown (116.110.124.53): 1 Time(s)
unknown (116.110.74.200): 1 Time(s)
unknown (164.90.199.110): 1 Time(s)
unknown (171.235.81.27): 1 Time(s)
unknown (185.220.102.242): 1 Time(s)
unknown (185.31.175.220): 1 Time(s)
unknown (188.126.89.45): 1 Time(s)
unknown (188.126.89.90): 1 Time(s)
unknown (61.183.194.150): 1 Time(s)
unknown (76.224.200.35.bc.googleusercontent.com): 1 Time(s)
unknown (84.246.151.125): 1 Time(s)
unknown (h-37-123-163-58.a785.priv.bahnhof.se): 1 Time(s)
unknown (h2821125.stratoserver.net): 1 Time(s)
unknown (ritvexu-pi1.rit.edu): 1 Time(s)
unknown (static-186-30-112-151.static.etb.net.co): 1 Time(s)
unknown (torops.cccfr.de): 1 Time(s)
Invalid Users:
Unknown Account: 630 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
15.042K Bytes accepted 15,403
======== ==================================================
1 Accepted 100.00%
-------- --------------------------------------------------
1 Total 100.00%
======== ==================================================
3 4xx Reject relay denied 100.00%
-------- --------------------------------------------------
3 Total 4xx Rejects 100.00%
======== ==================================================
198 Connections
70 Connections lost (inbound)
198 Disconnections
1 Removed from queue
1 Sent via SMTP
1 SMTP dialog errors
---------------------- Postfix End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin ------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End -------------------------
--------------------- SSHD Begin ------------------------
Disconnecting after too many authentication failures for user:
root : 1 Time(s)
Failed logins from:
1.116.140.147: 20 times
1.116.211.139: 29 times
1.117.77.29: 35 times
35.200.224.76 (76.224.200.35.bc.googleusercontent.com): 4 times
39.129.9.180: 14 times
45.124.144.116: 20 times
47.254.215.122: 10 times
49.232.67.184: 2 times
49.234.41.154: 4 times
49.234.111.57: 33 times
49.235.72.35: 32 times
49.235.254.75: 18 times
58.177.171.112 (058177171112.ctinets.com): 2 times
60.8.87.190: 6 times
61.183.194.150: 8 times
66.96.236.91 (host-66-96-236-91.myrepublic.co.id): 37 times
81.70.146.107: 29 times
81.70.178.153: 35 times
81.169.200.132 (h2821125.stratoserver.net): 10 times
82.156.81.59: 38 times
82.157.125.42: 5 times
82.157.189.241: 40 times
89.40.53.35: 9 times
101.34.3.70: 20 times
109.193.249.107 (HSI-KBW-109-193-249-107.hsi7.kabel-badenwuerttemberg.de): 24 times
114.255.252.30: 38 times
115.159.102.251: 31 times
116.110.124.53: 1 time
117.220.15.119: 1 time
118.25.182.61: 42 times
118.27.25.147 (v118-27-25-147.4l0s.static.cnode.io): 1 time
120.92.134.94: 12 times
121.4.142.38: 33 times
121.4.175.37: 30 times
121.4.175.99: 31 times
121.5.25.74: 32 times
121.5.45.12: 43 times
121.5.154.247: 40 times
121.5.171.213: 38 times
123.59.211.63: 34 times
129.21.240.247 (ritvexu-pi1.rit.edu): 4 times
143.110.179.115 (heribay.intertoons.net): 8 times
144.135.85.184 (144-135-85-184.tpips.telstra.com): 33 times
150.95.151.4 (v150-95-151-4.a090.g.tyo1.static.cnode.io): 11 times
157.230.230.126: 11 times
159.75.126.127: 32 times
159.75.130.111: 16 times
177.8.172.94: 37 times
178.254.138.66 (free-138-66.mediaworksit.net): 43 times
180.167.18.22: 8 times
185.6.91.219: 13 times
186.30.112.151 (static-186-30-112-151.static.etb.net.co): 4 times
187.188.132.86 (fixed-187-188-132-86.totalplay.net): 1 time
189.89.221.246 (189-089-221-246.static.stratus.com.br): 19 times
193.112.99.178: 28 times
200.123.180.52 (mail.host4r.com.ar): 30 times
200.148.108.181 (200-148-108-181.dsl.telesp.net.br): 39 times
205.185.127.160: 4 times
211.140.196.90: 20 times
211.220.27.191: 3 times
223.197.175.91 (223-197-175-91.static.imsbiz.com): 22 times
Illegal users from:
undef: 412 times
1.116.140.147: 14 times
1.116.211.139: 21 times
1.117.77.29: 15 times
5.255.97.149 (torops.cccfr.de): 1 time
31.184.198.71: 3 times
35.200.224.76 (76.224.200.35.bc.googleusercontent.com): 1 time
37.123.163.58 (h-37-123-163-58.A785.priv.bahnhof.se): 1 time
39.129.9.180: 5 times
45.124.144.116: 5 times
45.155.204.39: 3 times
47.254.215.122: 2 times
49.232.67.184: 3 times
49.234.41.154: 4 times
49.234.111.57: 15 times
49.235.72.35: 18 times
49.235.254.75: 8 times
58.225.55.143: 2 times
61.183.194.150: 1 time
65.49.20.68 (scan-19.shadowserver.org): 1 time
66.96.236.91 (host-66-96-236-91.myrepublic.co.id): 11 times
81.70.146.107: 19 times
81.70.178.153: 13 times
81.169.200.132 (h2821125.stratoserver.net): 1 time
82.156.81.59: 12 times
82.157.189.241: 10 times
84.246.151.125 (84-246-151-125.static.mavianmax.it): 1 time
89.40.53.35: 8 times
101.34.3.70: 5 times
109.193.249.107 (HSI-KBW-109-193-249-107.hsi7.kabel-badenwuerttemberg.de): 9 times
114.255.252.30: 12 times
115.159.102.251: 17 times
116.110.74.200: 1 time
116.110.124.53: 1 time
118.25.182.61: 8 times
120.92.134.94: 8 times
121.4.142.38: 13 times
121.4.175.37: 20 times
121.4.175.99: 18 times
121.5.25.74: 18 times
121.5.45.12: 8 times
121.5.154.247: 10 times
121.5.171.213: 12 times
123.59.211.63: 15 times
125.187.24.45: 2 times
129.21.240.247 (ritvexu-pi1.rit.edu): 1 time
141.98.10.82: 6 times
141.98.10.121: 2 times
144.135.85.184 (144-135-85-184.tpips.telstra.com): 12 times
150.95.151.4 (v150-95-151-4.a090.g.tyo1.static.cnode.io): 5 times
157.230.230.126: 7 times
159.75.126.127: 17 times
159.75.130.111: 34 times
164.90.199.110: 1 time
171.225.184.186 (dynamic-adsl.viettel.vn): 6 times
171.235.81.27 (dynamic-ip-adsl.viettel.vn): 1 time
171.251.25.233 (dynamic-ip-adsl.viettel.vn): 2 times
176.111.173.237: 8 times
176.111.173.238: 6 times
177.8.172.94: 13 times
178.254.138.66 (free-138-66.mediaworksit.net): 7 times
179.60.132.10: 15 times
180.167.18.22: 10 times
185.6.91.219: 7 times
185.31.175.220: 1 time
185.220.102.242 (185-220-102-242.torservers.net): 1 time
186.30.112.151 (static-186-30-112-151.static.etb.net.co): 1 time
188.126.89.45: 1 time
188.126.89.90: 1 time
189.89.221.246 (189-089-221-246.static.stratus.com.br): 6 times
193.112.99.178: 22 times
199.19.224.76 (kon.is.hentai): 6 times
200.123.180.52 (mail.host4r.com.ar): 8 times
200.148.108.181 (200-148-108-181.dsl.telesp.net.br): 11 times
205.185.113.224 (smtp7.calabarblog.com): 3 times
205.185.121.149: 2 times
205.185.127.160: 4 times
209.141.53.99 (abbrinym.com): 4 times
211.140.196.90: 7 times
211.220.27.191: 9 times
212.193.30.64: 2 times
222.103.167.174: 2 times
223.197.175.91 (223-197-175-91.static.imsbiz.com): 5 times
**Unmatched Entries**
Disconnecting: Change of username or service not allowed: (0,ssh-connection) -> (!root,ssh-connection) [preauth] : 1 time(s)
Disconnecting: Change of username or service not allowed: (admin,ssh-connection) -> (0,ssh-connection) [preauth] : 1 time(s)
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/ploop33257p1 394G 242G 132G 65% /
none 4.0G 0 4.0G 0% /dev
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################
4 Jahre
Logwatch for h2361197.stratoserver.net (Linux)
by root@zapf.in
################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Mon Oct 11 04:42:04 2021
Date Range Processed: yesterday
( 2021-Oct-10 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host: h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [ 78:78 ]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
A total of 10 sites probed the server
110.253.40.87
137.184.73.78
161.35.236.158
172.104.131.24
199.195.253.71
209.141.56.41
3.85.234.49
49.143.32.6
64.227.97.195
66.240.205.34
Requests with error response codes
400 Bad Request
null: 16 Time(s)
/: 5 Time(s)
/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh: 3 Time(s)
mstshash=Administr: 2 Time(s)
/.env: 1 Time(s)
/.well-known/security.txt: 1 Time(s)
/c/version.js: 1 Time(s)
/favicon.ico: 1 Time(s)
/flu/403.html: 1 Time(s)
/gemini-iptv/get_prc.php: 1 Time(s)
/gemini-iptv/vod.json: 1 Time(s)
/robots.txt: 1 Time(s)
/sra_{BA195980-CD49-458b-9E23-C84EE0ADCD75}/: 1 Time(s)
/stalker_portal/c/version.js: 1 Time(s)
/stream/live.php: 1 Time(s)
/streaming/clients_live.php: 1 Time(s)
/system_api.php: 1 Time(s)
/w00tw00t.at.ISC.SANS.DFind:): 1 Time(s)
500 Internal Server Error
/: 48 Time(s)
/.env: 2 Time(s)
/.well-known/security.txt: 2 Time(s)
/ecp/Current/exporttool/microsoft.exchange ... ool.application: 2 Time(s)
/robots.txt: 2 Time(s)
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 2 Time(s)
//login_sid.lua: 1 Time(s)
/?XDEBUG_SESSION_START=phpstorm: 1 Time(s)
/Autodiscover/Autodiscover.xml: 1 Time(s)
/GponForm/diag_Form?style/: 1 Time(s)
/_ignition/execute-solution: 1 Time(s)
/actuator/health: 1 Time(s)
/api/jsonws/invoke: 1 Time(s)
/bag2: 1 Time(s)
/c/version.js: 1 Time(s)
/console/: 1 Time(s)
/favicon.ico: 1 Time(s)
/flu/403.html: 1 Time(s)
/gemini-iptv/get_prc.php: 1 Time(s)
/gemini-iptv/vod.json: 1 Time(s)
/index.php?s=/Index/\x5Cthink\x5Capp/invok ... HelloThinkPHP21: 1 Time(s)
/mifs/.;/services/LogService: 1 Time(s)
/owa/auth/logon.aspx: 1 Time(s)
/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f: 1 Time(s)
/owa/auth/x.js: 1 Time(s)
/stalker_portal/c/version.js: 1 Time(s)
/stream/live.php: 1 Time(s)
/streaming/clients_live.php: 1 Time(s)
/system_api.php: 1 Time(s)
/wp-content/plugins/wp-file-manager/readme.txt: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
root (heribay.intertoons.net): 188 Time(s)
root (206.81.30.137): 38 Time(s)
root (218.26.188.73): 38 Time(s)
root (172.81.254.82): 36 Time(s)
root (211.115.68.105): 36 Time(s)
root (1.116.229.124): 35 Time(s)
root (49.234.13.139): 35 Time(s)
root (ip-182-16-240-238.interlink.net.id): 35 Time(s)
root (106.53.86.25): 34 Time(s)
root (221.231.9.138): 34 Time(s)
root (conm200-116-110-25.epm.net.co): 34 Time(s)
root (bras-base-mtrlpq3704w-grc-22-174-91-192-200.dsl.bell.ca): 33 Time(s)
root (112.160.220.233): 32 Time(s)
root (42.192.133.140): 32 Time(s)
root (50-77-68-201-static.hfc.comcastbusiness.net): 32 Time(s)
root (115.159.216.236): 31 Time(s)
root (182.254.151.198): 31 Time(s)
root (42.192.179.14): 29 Time(s)
root (210.28.213.193.static.cust.telenor.com): 28 Time(s)
root (42.193.41.129): 28 Time(s)
root (40.125.214.159): 27 Time(s)
root (175.27.232.16): 26 Time(s)
root (49.233.24.233): 26 Time(s)
unknown (121.5.168.67): 23 Time(s)
root (177.22.35.126): 19 Time(s)
unknown (182.254.151.198): 19 Time(s)
root (103.127.67.194): 18 Time(s)
root (106.54.170.148): 18 Time(s)
root (23.105.222.242.16clouds.com): 18 Time(s)
unknown (112.160.220.233): 18 Time(s)
unknown (50-77-68-201-static.hfc.comcastbusiness.net): 18 Time(s)
root (1.85.217.134): 17 Time(s)
root (157.245.101.31): 17 Time(s)
root (206.189.206.212): 17 Time(s)
root (221.226.39.202): 17 Time(s)
unknown (40.125.214.159): 17 Time(s)
unknown (bras-base-mtrlpq3704w-grc-22-174-91-192-200.dsl.bell.ca): 17 Time(s)
root (121.131.164.62): 16 Time(s)
unknown (106.53.86.25): 16 Time(s)
unknown (115.159.216.236): 16 Time(s)
unknown (221.231.9.138): 16 Time(s)
unknown (1.116.229.124): 15 Time(s)
unknown (175.27.232.16): 15 Time(s)
unknown (49.234.13.139): 15 Time(s)
unknown (81.69.7.163): 15 Time(s)
root (121.5.168.67): 14 Time(s)
root (189.45.78.175): 14 Time(s)
root (81.69.7.163): 14 Time(s)
unknown (172.81.254.82): 14 Time(s)
unknown (177.22.35.126): 14 Time(s)
unknown (210.28.213.193.static.cust.telenor.com): 14 Time(s)
unknown (211.115.68.105): 14 Time(s)
unknown (42.192.133.140): 14 Time(s)
unknown (103.127.67.194): 13 Time(s)
unknown (141.98.10.81): 13 Time(s)
root (122.55.221.172): 12 Time(s)
unknown (1.85.217.134): 12 Time(s)
unknown (157.245.101.31): 12 Time(s)
unknown (206.81.30.137): 12 Time(s)
unknown (218.26.188.73): 12 Time(s)
unknown (221.226.39.202): 12 Time(s)
unknown (42.193.41.129): 12 Time(s)
unknown (61.35.57.29): 12 Time(s)
root (111.229.237.226): 11 Time(s)
unknown (42.192.179.14): 11 Time(s)
unknown (conm200-116-110-25.epm.net.co): 11 Time(s)
unknown (ip-182-16-240-238.interlink.net.id): 11 Time(s)
unknown (23.105.222.242.16clouds.com): 9 Time(s)
root (40.73.17.36): 8 Time(s)
unknown (179.43.141.99): 8 Time(s)
unknown (205.185.126.71): 8 Time(s)
unknown (206.189.206.212): 8 Time(s)
unknown (209.141.53.99): 8 Time(s)
unknown (49.233.24.233): 8 Time(s)
unknown (106.54.170.148): 7 Time(s)
unknown (141.98.10.121): 6 Time(s)
root (058177171112.ctinets.com): 5 Time(s)
root (188.74.54.101): 5 Time(s)
unknown (111.229.237.226): 5 Time(s)
unknown (176.111.173.238): 5 Time(s)
unknown (40.73.17.36): 4 Time(s)
unknown (141.98.10.60): 3 Time(s)
unknown (189.45.78.175): 3 Time(s)
unknown (45.135.232.159): 3 Time(s)
unknown (45.155.204.39): 3 Time(s)
root (179.43.141.99): 2 Time(s)
unknown (10.85.105.92.dynamic.wline.res.cust.swisscom.ch): 2 Time(s)
unknown (112.184.176.131): 2 Time(s)
unknown (121.131.164.62): 2 Time(s)
unknown (188.126.89.67): 2 Time(s)
unknown (190.29.103.99): 2 Time(s)
unknown (199.19.224.76): 2 Time(s)
unknown (205.185.121.149): 2 Time(s)
unknown (212.193.30.32): 2 Time(s)
unknown (212.193.30.64): 2 Time(s)
unknown (82-64-125-231.subs.proxad.net): 2 Time(s)
mailman (42.192.179.14): 1 Time(s)
postfix (176.111.173.237): 1 Time(s)
root (117.146.172.106): 1 Time(s)
root (176.111.173.237): 1 Time(s)
root (200.73.128.252): 1 Time(s)
root (200.73.130.213): 1 Time(s)
unknown (058177171112.ctinets.com): 1 Time(s)
unknown (159.75.126.127): 1 Time(s)
unknown (176.111.173.237): 1 Time(s)
unknown (185.247.225.61): 1 Time(s)
unknown (185.31.175.228): 1 Time(s)
unknown (185.81.51.132): 1 Time(s)
unknown (188.74.54.101): 1 Time(s)
unknown (59.72.122.148): 1 Time(s)
unknown (tor-exit-relay-5.anonymizing-proxy.digitalcourage.de): 1 Time(s)
unknown (tor-exit0-readme.dfri.se): 1 Time(s)
Invalid Users:
Unknown Account: 551 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
17.967K Bytes accepted 18,398
17.967K Bytes sent via SMTP 18,398
======== ==================================================
1 Accepted 100.00%
-------- --------------------------------------------------
1 Total 100.00%
======== ==================================================
2 4xx Reject relay denied 100.00%
-------- --------------------------------------------------
2 Total 4xx Rejects 100.00%
======== ==================================================
65 Connections
41 Connections lost (inbound)
65 Disconnections
1 Removed from queue
1 Sent via SMTP
5 Hostname verification errors (FCRDNS)
---------------------- Postfix End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin ------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End -------------------------
--------------------- SSHD Begin ------------------------
Failed logins from:
1.85.217.134: 17 times
1.116.229.124: 35 times
23.105.222.242 (23.105.222.242.16clouds.com): 18 times
40.73.17.36: 8 times
40.125.214.159: 27 times
42.192.133.140: 32 times
42.192.179.14: 30 times
42.193.41.129: 28 times
49.233.24.233: 26 times
49.234.13.139: 35 times
50.77.68.201 (50-77-68-201-static.hfc.comcastbusiness.net): 32 times
58.177.171.112 (058177171112.ctinets.com): 5 times
81.69.7.163: 14 times
103.127.67.194: 18 times
106.53.86.25: 34 times
106.54.170.148: 18 times
111.229.237.226: 11 times
112.160.220.233: 32 times
115.159.216.236: 31 times
117.146.172.106: 1 time
121.5.168.67: 14 times
121.131.164.62: 16 times
122.55.221.172 (122.55.221.172.static.pldt.net): 12 times
143.110.179.115 (heribay.intertoons.net): 188 times
157.245.101.31: 17 times
172.81.254.82: 36 times
174.91.192.200 (bras-base-mtrlpq3704w-grc-22-174-91-192-200.dsl.bell.ca): 33 times
175.27.232.16: 26 times
176.111.173.237: 2 times
177.22.35.126: 19 times
179.43.141.99: 2 times
182.16.240.238 (ip-182-16-240-238.interlink.net.id): 35 times
182.254.151.198: 31 times
188.74.54.101: 5 times
189.45.78.175: 14 times
193.213.28.210 (210.28.213.193.static.cust.telenor.com): 28 times
200.73.128.252 (252.128.73.200.cab.prima.net.ar): 1 time
200.73.130.213 (213.130.73.200.cab.prima.net.ar): 1 time
200.116.110.25 (conm200-116-110-25.epm.net.co): 34 times
206.81.30.137: 38 times
206.189.206.212: 17 times
211.115.68.105: 36 times
218.26.188.73 (73.188.26.218.internet.sx.cn): 38 times
221.226.39.202: 17 times
221.231.9.138: 34 times
Illegal users from:
undef: 349 times
1.85.217.134: 12 times
1.116.229.124: 15 times
23.105.222.242 (23.105.222.242.16clouds.com): 9 times
40.73.17.36: 4 times
40.125.214.159: 17 times
42.192.133.140: 14 times
42.192.179.14: 11 times
42.193.41.129: 12 times
45.135.232.159: 3 times
45.155.204.39: 3 times
49.233.24.233: 8 times
49.234.13.139: 15 times
50.77.68.201 (50-77-68-201-static.hfc.comcastbusiness.net): 18 times
58.177.171.112 (058177171112.ctinets.com): 1 time
59.72.122.148: 1 time
61.35.57.29: 12 times
65.49.20.68 (scan-19.shadowserver.org): 1 time
81.69.7.163: 15 times
82.64.125.231 (82-64-125-231.subs.proxad.net): 2 times
92.105.85.10 (10.85.105.92.dynamic.wline.res.cust.swisscom.ch): 2 times
103.127.67.194: 13 times
106.53.86.25: 16 times
106.54.170.148: 7 times
111.229.237.226: 5 times
112.160.220.233: 18 times
112.184.176.131: 2 times
115.159.216.236: 16 times
121.5.168.67: 23 times
121.131.164.62: 2 times
141.98.10.60: 3 times
141.98.10.81: 13 times
141.98.10.121: 6 times
157.245.101.31: 12 times
159.75.126.127: 1 time
171.25.193.20 (tor-exit0-readme.dfri.se): 1 time
172.81.254.82: 14 times
174.91.192.200 (bras-base-mtrlpq3704w-grc-22-174-91-192-200.dsl.bell.ca): 17 times
175.27.232.16: 15 times
176.111.173.237: 1 time
176.111.173.238: 5 times
177.22.35.126: 14 times
179.43.141.99: 8 times
182.16.240.238 (ip-182-16-240-238.interlink.net.id): 11 times
182.254.151.198: 19 times
185.31.175.228: 1 time
185.81.51.132: 1 time
185.220.102.251 (tor-exit-relay-5.anonymizing-proxy.digitalcourage.de): 1 time
185.247.225.61: 1 time
188.74.54.101: 1 time
188.126.89.67: 2 times
189.45.78.175: 3 times
190.29.103.99 (static-adsl190-29-103-99.une.net.co): 2 times
193.213.28.210 (210.28.213.193.static.cust.telenor.com): 14 times
199.19.224.76 (kon.is.hentai): 2 times
200.116.110.25 (conm200-116-110-25.epm.net.co): 11 times
205.185.121.149: 2 times
205.185.126.71 (beta.bigislandrp.org): 8 times
206.81.30.137: 12 times
206.189.206.212: 8 times
209.141.53.99 (abbrinym.com): 8 times
211.115.68.105: 14 times
212.193.30.32: 2 times
212.193.30.64: 2 times
218.26.188.73 (73.188.26.218.internet.sx.cn): 12 times
221.226.39.202: 12 times
221.231.9.138: 16 times
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/ploop33257p1 394G 242G 132G 65% /
none 4.0G 0 4.0G 0% /dev
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################
4 Jahre
DOMAIN zapf.wiki RENEWAL SUCCESSFUL
by no-reply@inwx.de
DOMAIN: zapf.wiki
PERIOD: 1
PERIODTIMEUNIT: Y
-----------------------------------------------------------------------------------
DOMAIN RENEWAL SUCCESSFUL
-----------------------------------------------------------------------------------
4 Jahre
Logwatch for h2361197.stratoserver.net (Linux)
by root@zapf.in
################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Sun Oct 10 04:42:05 2021
Date Range Processed: yesterday
( 2021-Oct-09 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host: h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [ 85:86 ]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
Connection attempts using mod_proxy:
106.45.9.144 -> zapf.wiki:443: 1 Time(s)
222.186.19.235 -> zapf.wiki:443: 2 Time(s)
A total of 8 sites probed the server
176.58.124.134
193.242.145.112
199.195.251.213
209.141.56.41
222.186.19.235
5.188.210.227
66.240.205.34
91.132.58.79
Requests with error response codes
400 Bad Request
null: 15 Time(s)
zapf.wiki:443: 3 Time(s)
/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh: 2 Time(s)
/config/getuser?index=0: 2 Time(s)
mstshash=Administr: 2 Time(s)
/: 1 Time(s)
/.env: 1 Time(s)
http://5.188.210.227/echo.php: 1 Time(s)
500 Internal Server Error
/: 56 Time(s)
/.env: 4 Time(s)
/ecp/Current/exporttool/microsoft.exchange ... ool.application: 2 Time(s)
/.git/config: 1 Time(s)
/.well-known/security.txt: 1 Time(s)
///remote/fgt_lang?lang=/../../../..//////////dev/: 1 Time(s)
//login_sid.lua: 1 Time(s)
/?XDEBUG_SESSION_START=phpstorm: 1 Time(s)
/Autodiscover/Autodiscover.xml: 1 Time(s)
/GponForm/diag_Form?style/: 1 Time(s)
/_ignition/execute-solution: 1 Time(s)
/actuator/health: 1 Time(s)
/blog/wp-login.php: 1 Time(s)
/console/: 1 Time(s)
/ecp/fa.js: 1 Time(s)
/home/wp-login.php: 1 Time(s)
/index.php?s=/Index/\x5Cthink\x5Capp/invok ... HelloThinkPHP21: 1 Time(s)
/mifs/.;/services/LogService: 1 Time(s)
/new/wp-login.php: 1 Time(s)
/owa/auth/logon.aspx: 1 Time(s)
/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f: 1 Time(s)
/owa/auth/x.js: 1 Time(s)
/remote/fgt_lang?lang=/../../../..//////// ... lvpn_websession: 1 Time(s)
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/wp-content/plugins/wp-file-manager/readme.txt: 1 Time(s)
/wp-login.php: 1 Time(s)
/wp/wp-login.php: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
unknown (193.105.7.52): 45 Time(s)
root (212.64.74.235): 40 Time(s)
root (115.159.25.205): 38 Time(s)
root (119.91.80.2): 38 Time(s)
root (159.148.84.159): 38 Time(s)
root (106.52.174.219): 37 Time(s)
root (175.24.101.37): 37 Time(s)
root (167.71.145.201): 36 Time(s)
root (1.15.142.88): 35 Time(s)
root (103.154.59.65): 34 Time(s)
root (106.54.78.101): 34 Time(s)
root (202.169.46.88): 34 Time(s)
root (42.192.151.83): 34 Time(s)
root (bras-base-mtrlpq3704w-grc-22-174-91-192-200.dsl.bell.ca): 34 Time(s)
root (101.228.82.55): 33 Time(s)
root (104.236.69.31): 32 Time(s)
root (49.234.63.131): 32 Time(s)
root (42.192.50.24): 30 Time(s)
root (82.156.87.90): 29 Time(s)
unknown (81.70.164.97): 29 Time(s)
root (1.117.143.185): 27 Time(s)
root (222.185.231.246): 25 Time(s)
root (81.70.164.97): 21 Time(s)
unknown (211.253.8.225): 21 Time(s)
root (r201-217-159-155.ir-static.anteldata.net.uy): 20 Time(s)
root (49.235.37.144): 19 Time(s)
root (106.13.212.203): 18 Time(s)
root (120.133.52.105): 18 Time(s)
root (211.253.8.225): 18 Time(s)
root (211.45.247.122): 18 Time(s)
root (41.222.0.16): 18 Time(s)
unknown (49.234.63.131): 18 Time(s)
root (106.12.128.72): 17 Time(s)
root (89.17.63.85): 17 Time(s)
unknown (104.236.69.31): 17 Time(s)
root (116.247.81.99): 16 Time(s)
unknown (202.169.46.88): 16 Time(s)
unknown (42.192.50.24): 16 Time(s)
unknown (bras-base-mtrlpq3704w-grc-22-174-91-192-200.dsl.bell.ca): 16 Time(s)
unknown (106.54.78.101): 15 Time(s)
unknown (101.228.82.55): 14 Time(s)
unknown (103.154.59.65): 14 Time(s)
unknown (167.71.145.201): 14 Time(s)
unknown (89.17.63.85): 14 Time(s)
root (119.45.37.230): 13 Time(s)
root (81.69.7.163): 13 Time(s)
unknown (1.15.142.88): 13 Time(s)
unknown (198.23.153.142): 13 Time(s)
root (117.107.163.240): 12 Time(s)
unknown (119.91.80.2): 12 Time(s)
unknown (175.24.101.37): 12 Time(s)
unknown (41.222.0.16): 12 Time(s)
root (115.159.114.30): 11 Time(s)
root (143.110.212.213): 11 Time(s)
root (r179-27-60-34.static.adinet.com.uy): 11 Time(s)
unknown (106.52.174.219): 11 Time(s)
unknown (115.159.25.205): 11 Time(s)
unknown (159.148.84.159): 11 Time(s)
unknown (42.192.151.83): 11 Time(s)
unknown (1.117.143.185): 10 Time(s)
unknown (116.247.81.99): 10 Time(s)
unknown (117.107.163.240): 10 Time(s)
unknown (212.64.74.235): 10 Time(s)
unknown (82.156.87.90): 10 Time(s)
unknown (49.234.42.234): 9 Time(s)
root (139.255.66.218): 8 Time(s)
unknown (176.111.173.226): 8 Time(s)
unknown (81.69.7.163): 8 Time(s)
root (49.234.42.234): 7 Time(s)
unknown (115.159.114.30): 7 Time(s)
unknown (211.45.247.122): 7 Time(s)
unknown (222.185.231.246): 7 Time(s)
unknown (r179-27-60-34.static.adinet.com.uy): 7 Time(s)
unknown (106.12.128.72): 6 Time(s)
unknown (106.13.212.203): 6 Time(s)
unknown (61.35.57.29): 6 Time(s)
root (193.105.7.52): 5 Time(s)
unknown (120.133.52.105): 5 Time(s)
unknown (45.135.232.159): 5 Time(s)
unknown (49.235.37.144): 5 Time(s)
unknown (r201-217-159-155.ir-static.anteldata.net.uy): 5 Time(s)
root (198.23.153.142): 4 Time(s)
root (210.28.213.193.static.cust.telenor.com): 4 Time(s)
root (81.68.212.201): 4 Time(s)
root (conm200-116-110-25.epm.net.co): 4 Time(s)
unknown (143.110.212.213): 4 Time(s)
unknown (210.28.213.193.static.cust.telenor.com): 4 Time(s)
root (113.102.207.69): 3 Time(s)
root (14.221.4.185): 3 Time(s)
root (ip-182-16-240-238.interlink.net.id): 3 Time(s)
unknown (107.ip-51-254-113.eu): 3 Time(s)
unknown (119.45.37.230): 3 Time(s)
unknown (146.185.79.101): 3 Time(s)
unknown (176.111.173.237): 3 Time(s)
unknown (176.111.173.238): 3 Time(s)
unknown (205.185.121.149): 3 Time(s)
unknown (209.141.55.232): 3 Time(s)
root (101.89.182.204): 2 Time(s)
root (113.102.205.224): 2 Time(s)
root (113.102.205.97): 2 Time(s)
root (113.102.206.144): 2 Time(s)
root (113.102.206.149): 2 Time(s)
root (113.102.207.182): 2 Time(s)
root (113.102.207.245): 2 Time(s)
root (14.221.5.228): 2 Time(s)
root (14.221.5.73): 2 Time(s)
root (42.192.133.140): 2 Time(s)
root (net-109-116-41-238.cust.vodafonedsl.it): 2 Time(s)
unknown (046124101250.public.t-mobile.at): 2 Time(s)
unknown (112.31.56.247): 2 Time(s)
unknown (113.102.205.224): 2 Time(s)
unknown (139.255.66.218): 2 Time(s)
unknown (141.98.10.81): 2 Time(s)
unknown (212.193.30.64): 2 Time(s)
unknown (42.192.133.140): 2 Time(s)
unknown (82.166.147.151): 2 Time(s)
unknown (net-109-116-41-238.cust.vodafonedsl.it): 2 Time(s)
backup (104.236.69.31): 1 Time(s)
backup (198.23.153.142): 1 Time(s)
mysql (42.192.50.24): 1 Time(s)
root (107.ip-51-254-113.eu): 1 Time(s)
root (113.102.204.55): 1 Time(s)
root (113.102.204.82): 1 Time(s)
root (113.102.205.112): 1 Time(s)
root (113.102.205.120): 1 Time(s)
root (113.102.206.156): 1 Time(s)
root (113.102.207.128): 1 Time(s)
root (113.102.207.199): 1 Time(s)
root (114.67.104.59): 1 Time(s)
root (14.221.4.11): 1 Time(s)
root (14.221.4.138): 1 Time(s)
root (14.221.4.182): 1 Time(s)
root (14.221.4.55): 1 Time(s)
root (14.221.5.150): 1 Time(s)
root (14.221.5.157): 1 Time(s)
root (14.221.5.176): 1 Time(s)
root (14.221.5.190): 1 Time(s)
root (146.185.79.101): 1 Time(s)
root (154.8.226.52): 1 Time(s)
root (36.133.170.229): 1 Time(s)
root (36.133.216.195): 1 Time(s)
sys (159.148.84.159): 1 Time(s)
unknown (113.102.205.112): 1 Time(s)
unknown (113.102.205.202): 1 Time(s)
unknown (113.102.205.242): 1 Time(s)
unknown (113.102.205.42): 1 Time(s)
unknown (113.102.206.144): 1 Time(s)
unknown (113.102.206.149): 1 Time(s)
unknown (113.102.206.230): 1 Time(s)
unknown (113.102.207.128): 1 Time(s)
unknown (113.102.207.199): 1 Time(s)
unknown (14.221.5.22): 1 Time(s)
unknown (14.221.5.252): 1 Time(s)
unknown (14.221.5.71): 1 Time(s)
unknown (188.126.89.138): 1 Time(s)
unknown (188.126.89.139): 1 Time(s)
unknown (36.133.216.195): 1 Time(s)
unknown (45.154.255.147): 1 Time(s)
unknown (conm200-116-110-25.epm.net.co): 1 Time(s)
unknown (ip-182-16-240-238.interlink.net.id): 1 Time(s)
unknown (tor-exit4-readme.dfri.se): 1 Time(s)
uucp (45.135.232.159): 1 Time(s)
Invalid Users:
Unknown Account: 562 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
3 Miscellaneous warnings
16.583K Bytes accepted 16,981
16.583K Bytes sent via SMTP 16,981
======== ==================================================
1 Accepted 100.00%
-------- --------------------------------------------------
1 Total 100.00%
======== ==================================================
3 4xx Reject relay denied 100.00%
-------- --------------------------------------------------
3 Total 4xx Rejects 100.00%
======== ==================================================
90 Connections
32 Connections lost (inbound)
90 Disconnections
1 Removed from queue
1 Sent via SMTP
40 Hostname verification errors (FCRDNS)
---------------------- Postfix End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin ------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End -------------------------
--------------------- SSHD Begin ------------------------
Failed logins from:
1.15.142.88: 35 times
1.117.143.185: 27 times
14.221.4.11: 1 time
14.221.4.55: 1 time
14.221.4.138: 1 time
14.221.4.182: 1 time
14.221.4.185: 3 times
14.221.5.73: 2 times
14.221.5.150: 1 time
14.221.5.157: 1 time
14.221.5.176: 1 time
14.221.5.190: 1 time
14.221.5.228: 2 times
36.133.170.229: 1 time
36.133.216.195: 1 time
41.222.0.16: 18 times
42.192.50.24: 31 times
42.192.133.140: 2 times
42.192.151.83: 34 times
45.135.232.159: 1 time
49.234.42.234: 7 times
49.234.63.131: 32 times
49.235.37.144: 19 times
51.254.113.107 (107.ip-51-254-113.eu): 1 time
81.68.212.201: 4 times
81.69.7.163: 13 times
81.70.164.97: 21 times
82.156.87.90: 29 times
89.17.63.85: 17 times
101.89.182.204: 2 times
101.228.82.55: 33 times
103.154.59.65: 34 times
104.236.69.31: 33 times
106.12.128.72: 17 times
106.13.212.203: 18 times
106.52.174.219: 37 times
106.54.78.101: 34 times
109.116.41.238 (net-109-116-41-238.cust.vodafonedsl.it): 2 times
113.102.204.55: 1 time
113.102.204.82: 1 time
113.102.205.97: 2 times
113.102.205.112: 1 time
113.102.205.120: 1 time
113.102.205.224: 2 times
113.102.206.144: 2 times
113.102.206.149: 2 times
113.102.206.156: 1 time
113.102.207.69: 3 times
113.102.207.128: 1 time
113.102.207.182: 2 times
113.102.207.199: 1 time
113.102.207.245: 2 times
114.67.104.59: 1 time
115.159.25.205: 38 times
115.159.114.30: 11 times
116.247.81.99: 16 times
117.107.163.240: 12 times
119.45.37.230: 13 times
119.91.80.2: 38 times
120.133.52.105: 18 times
139.255.66.218 (ln-static-139-255-66-218.link.net.id): 8 times
143.110.212.213: 11 times
146.185.79.101: 1 time
154.8.226.52: 1 time
159.148.84.159: 39 times
167.71.145.201: 36 times
174.91.192.200 (bras-base-mtrlpq3704w-grc-22-174-91-192-200.dsl.bell.ca): 34 times
175.24.101.37: 37 times
179.27.60.34 (r179-27-60-34.static.adinet.com.uy): 11 times
182.16.240.238 (ip-182-16-240-238.interlink.net.id): 3 times
193.105.7.52 (193-105-7-52.therecom.net): 5 times
193.213.28.210 (210.28.213.193.static.cust.telenor.com): 4 times
198.23.153.142 (198-23-153-142-host.colocrossing.com): 5 times
200.116.110.25 (conm200-116-110-25.epm.net.co): 4 times
201.217.159.155 (r201-217-159-155.ir-static.anteldata.net.uy): 20 times
202.169.46.88: 34 times
211.45.247.122: 18 times
211.253.8.225: 18 times
212.64.74.235: 40 times
222.185.231.246: 25 times
Illegal users from:
undef: 388 times
1.15.142.88: 13 times
1.117.143.185: 10 times
14.221.5.22: 1 time
14.221.5.71: 1 time
14.221.5.252: 1 time
36.133.216.195: 1 time
41.222.0.16: 12 times
42.192.50.24: 16 times
42.192.133.140: 2 times
42.192.151.83: 11 times
45.135.232.159: 5 times
45.154.255.147 (cust-147.keff.org): 1 time
46.124.101.250 (046124101250.public.t-mobile.at): 2 times
49.234.42.234: 9 times
49.234.63.131: 18 times
49.235.37.144: 5 times
51.254.113.107 (107.ip-51-254-113.eu): 3 times
61.35.57.29: 6 times
65.49.20.69 (scan-20.shadowserver.org): 1 time
81.69.7.163: 8 times
81.70.164.97: 29 times
82.156.87.90: 10 times
82.166.147.151 (82-166-147-151.barak-online.net): 2 times
89.17.63.85: 14 times
101.228.82.55: 14 times
103.154.59.65: 14 times
104.236.69.31: 17 times
106.12.128.72: 6 times
106.13.212.203: 6 times
106.52.174.219: 11 times
106.54.78.101: 15 times
109.116.41.238 (net-109-116-41-238.cust.vodafonedsl.it): 2 times
112.31.56.247: 2 times
113.102.205.42: 1 time
113.102.205.112: 1 time
113.102.205.202: 1 time
113.102.205.224: 2 times
113.102.205.242: 1 time
113.102.206.144: 1 time
113.102.206.149: 1 time
113.102.206.230: 1 time
113.102.207.128: 1 time
113.102.207.199: 1 time
115.159.25.205: 11 times
115.159.114.30: 7 times
116.247.81.99: 10 times
117.107.163.240: 10 times
119.45.37.230: 3 times
119.91.80.2: 12 times
120.133.52.105: 5 times
139.255.66.218 (ln-static-139-255-66-218.link.net.id): 2 times
141.98.10.81: 2 times
143.110.212.213: 4 times
146.185.79.101: 3 times
159.148.84.159: 11 times
167.71.145.201: 14 times
171.25.193.78 (tor-exit4-readme.dfri.se): 1 time
174.91.192.200 (bras-base-mtrlpq3704w-grc-22-174-91-192-200.dsl.bell.ca): 16 times
175.24.101.37: 12 times
176.111.173.226: 8 times
176.111.173.237: 3 times
176.111.173.238: 3 times
179.27.60.34 (r179-27-60-34.static.adinet.com.uy): 7 times
182.16.240.238 (ip-182-16-240-238.interlink.net.id): 1 time
188.126.89.138: 1 time
188.126.89.139: 1 time
193.105.7.52 (193-105-7-52.therecom.net): 45 times
193.213.28.210 (210.28.213.193.static.cust.telenor.com): 4 times
198.23.153.142 (198-23-153-142-host.colocrossing.com): 13 times
200.116.110.25 (conm200-116-110-25.epm.net.co): 1 time
201.217.159.155 (r201-217-159-155.ir-static.anteldata.net.uy): 5 times
202.169.46.88: 16 times
205.185.121.149: 3 times
209.141.55.232: 3 times
211.45.247.122: 7 times
211.253.8.225: 21 times
212.64.74.235: 10 times
212.193.30.64: 2 times
222.185.231.246: 7 times
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/ploop33257p1 394G 242G 132G 65% /
none 4.0G 0 4.0G 0% /dev
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################
4 Jahre
Logwatch for h2361197.stratoserver.net (Linux)
by root@zapf.in
################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Sat Oct 9 04:42:05 2021
Date Range Processed: yesterday
( 2021-Oct-08 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host: h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [ 79:78 ]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
A total of 10 sites probed the server
120.85.172.72
142.93.219.241
162.62.117.51
185.142.236.36
198.98.56.220
209.141.56.41
34.86.35.25
68.183.178.53
71.6.167.142
91.132.58.50
Requests with error response codes
400 Bad Request
null: 11 Time(s)
mstshash=Administr: 5 Time(s)
/: 4 Time(s)
/config/getuser?index=0: 2 Time(s)
/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh: 1 Time(s)
/socket.io/?noteId=uAPQnP-nRVmrMa1L4sp2jQ& ... WScbbRNnUseAABw: 1 Time(s)
/socket.io/?noteId=uAPQnP-nRVmrMa1L4sp2jQ& ... iQrXskvq0-0AABy: 1 Time(s)
/socket.io/?noteId=uAPQnP-nRVmrMa1L4sp2jQ& ... kN-zJc7JqYNAABx: 1 Time(s)
jz\x03\xC7\x80\xEA\xB9K\x1B\x1B\xEE\xC2\xD ... x09\xC0\x14\xC0: 1 Time(s)
499 (undefined)
/socket.io/?noteId=uAPQnP-nRVmrMa1L4sp2jQ& ... WScbbRNnUseAABw: 1 Time(s)
/socket.io/?noteId=uAPQnP-nRVmrMa1L4sp2jQ& ... iQrXskvq0-0AABy: 1 Time(s)
/socket.io/?noteId=uAPQnP-nRVmrMa1L4sp2jQ& ... kN-zJc7JqYNAABx: 1 Time(s)
500 Internal Server Error
/: 68 Time(s)
/.env: 6 Time(s)
/GponForm/diag_Form?style/: 2 Time(s)
/ecp/Current/exporttool/microsoft.exchange ... ool.application: 2 Time(s)
/favicon.ico: 2 Time(s)
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 2 Time(s)
/.well-known/security.txt: 1 Time(s)
///remote/fgt_lang?lang=/../../../..//////////dev/: 1 Time(s)
//login_sid.lua: 1 Time(s)
/?XDEBUG_SESSION_START=phpstorm: 1 Time(s)
/Autodiscover/Autodiscover.xml: 1 Time(s)
/_ignition/execute-solution: 1 Time(s)
/actuator/health: 1 Time(s)
/api/jsonws/invoke: 1 Time(s)
/cms/wp-login.php: 1 Time(s)
/console/: 1 Time(s)
/en/wp-login.php: 1 Time(s)
/index.php?s=/Index/\x5Cthink\x5Capp/invok ... HelloThinkPHP21: 1 Time(s)
/mifs/.;/services/LogService: 1 Time(s)
/news/wp-login.php: 1 Time(s)
/owa/auth/logon.aspx: 1 Time(s)
/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f: 1 Time(s)
/owa/auth/x.js: 1 Time(s)
/robots.txt: 1 Time(s)
/robots.txt/: 1 Time(s)
/site/wp-login.php: 1 Time(s)
/test/wp-login.php: 1 Time(s)
/web/wp-login.php: 1 Time(s)
/wordpress/wp-login.php: 1 Time(s)
/wp-content/plugins/wp-file-manager/readme.txt: 1 Time(s)
/wp-login.php: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
root (115.248.153.89): 46 Time(s)
root (121.18.88.186): 39 Time(s)
root (81.68.123.185): 37 Time(s)
root (188.166.22.79): 36 Time(s)
root (45.128.75.150): 36 Time(s)
root (119.29.10.203): 35 Time(s)
root (125.124.5.221): 35 Time(s)
root (203.162.54.243): 35 Time(s)
root (61.82.54.57): 35 Time(s)
root (1.15.25.243): 34 Time(s)
root (122.51.220.15): 34 Time(s)
root (45.43.57.225): 34 Time(s)
root (121.4.131.79): 32 Time(s)
root (159.75.91.89): 32 Time(s)
root (42.192.54.145): 32 Time(s)
root (52.184.91.79): 32 Time(s)
root (81.68.157.155): 32 Time(s)
root (103.168.150.5): 31 Time(s)
root (42.192.84.124): 30 Time(s)
root (217.74.44.204): 29 Time(s)
root (49.232.148.48): 29 Time(s)
root (52.183.128.237): 28 Time(s)
root (101.231.146.34): 26 Time(s)
root (146.56.235.195): 26 Time(s)
root (119.45.37.230): 25 Time(s)
root (211.169.228.35.bc.googleusercontent.com): 25 Time(s)
unknown (52.183.128.237): 22 Time(s)
root (119.84.128.24): 21 Time(s)
root (132.255.253.49): 21 Time(s)
root (49.234.42.234): 21 Time(s)
root (189.222.220.139.dsl.dyn.telnor.net): 20 Time(s)
unknown (217.74.44.204): 20 Time(s)
root (1.117.143.185): 18 Time(s)
root (111.206.4.222): 18 Time(s)
root (182.135.64.12): 18 Time(s)
unknown (42.192.54.145): 18 Time(s)
unknown (52.184.91.79): 18 Time(s)
root (182.254.220.148): 17 Time(s)
unknown (h2821125.stratoserver.net): 17 Time(s)
root (128.199.90.55): 16 Time(s)
unknown (121.4.131.79): 16 Time(s)
root (h2821125.stratoserver.net): 15 Time(s)
unknown (159.75.91.89): 15 Time(s)
unknown (45.43.57.225): 15 Time(s)
unknown (49.232.148.48): 15 Time(s)
unknown (61.82.54.57): 15 Time(s)
unknown (81.68.157.155): 15 Time(s)
unknown (82.166.147.151): 15 Time(s)
root (82.166.147.151): 14 Time(s)
unknown (1.15.25.243): 14 Time(s)
unknown (122.51.220.15): 14 Time(s)
unknown (125.124.5.221): 14 Time(s)
unknown (146.56.235.195): 14 Time(s)
unknown (188.166.22.79): 14 Time(s)
unknown (211.169.228.35.bc.googleusercontent.com): 14 Time(s)
unknown (42.192.84.124): 14 Time(s)
unknown (45.128.75.150): 14 Time(s)
root (221.0.94.20): 13 Time(s)
root (66.98.113.244.16clouds.com): 13 Time(s)
unknown (159.203.111.100): 13 Time(s)
unknown (49.234.42.234): 13 Time(s)
unknown (81.68.123.185): 13 Time(s)
unknown (103.168.150.5): 12 Time(s)
unknown (115.248.153.89): 12 Time(s)
unknown (119.29.10.203): 11 Time(s)
unknown (121.18.88.186): 11 Time(s)
unknown (119.45.37.230): 9 Time(s)
unknown (119.84.128.24): 9 Time(s)
unknown (203.162.54.243): 9 Time(s)
root (89.17.63.85): 8 Time(s)
unknown (101.231.146.34): 8 Time(s)
unknown (141.98.10.82): 8 Time(s)
unknown (182.135.64.12): 8 Time(s)
unknown (182.254.220.148): 8 Time(s)
unknown (189.222.220.139.dsl.dyn.telnor.net): 8 Time(s)
unknown (89.17.63.85): 8 Time(s)
unknown (1.117.143.185): 7 Time(s)
unknown (111.206.4.222): 7 Time(s)
unknown (128.199.90.55): 7 Time(s)
unknown (167.172.69.31): 7 Time(s)
unknown (176.111.173.218): 7 Time(s)
unknown (51.15.197.4): 7 Time(s)
root (113.106.162.114): 6 Time(s)
root (117.248.249.70): 6 Time(s)
root (159.203.111.100): 6 Time(s)
root (167.172.69.31): 6 Time(s)
root (52.131.246.255): 6 Time(s)
unknown (132.255.253.49): 6 Time(s)
unknown (221.0.94.20): 6 Time(s)
unknown (2.236.48.32): 5 Time(s)
unknown (116.117.157.69): 4 Time(s)
unknown (141.98.10.81): 4 Time(s)
unknown (212.193.30.101): 4 Time(s)
unknown (212.193.30.64): 4 Time(s)
unknown (66.98.113.244.16clouds.com): 4 Time(s)
unknown (106.12.202.192): 3 Time(s)
unknown (141.98.10.60): 3 Time(s)
unknown (176.111.173.238): 3 Time(s)
unknown (199.195.251.49): 3 Time(s)
unknown (52.131.246.255): 3 Time(s)
root (45.155.204.39): 2 Time(s)
root (49.233.183.141): 2 Time(s)
root (51.15.197.4): 2 Time(s)
unknown (176.111.173.237): 2 Time(s)
unknown (181.93.216.186): 2 Time(s)
unknown (183.104.206.223): 2 Time(s)
unknown (205.185.121.149): 2 Time(s)
unknown (209.141.53.99): 2 Time(s)
unknown (31.202.97.15): 2 Time(s)
unknown (47-186-103-61.dlls.tx.frontiernet.net): 2 Time(s)
unknown (81.17.18.61): 2 Time(s)
unknown (h2544445.stratoserver.net): 2 Time(s)
bin (167.172.69.31): 1 Time(s)
postgres (217.74.44.204): 1 Time(s)
root (103.133.57.250): 1 Time(s)
root (106.12.202.192): 1 Time(s)
root (106.58.169.162): 1 Time(s)
root (116.117.157.69): 1 Time(s)
root (117.22.230.94): 1 Time(s)
root (119.29.168.177): 1 Time(s)
root (151.69.90.144): 1 Time(s)
root (176.111.173.218): 1 Time(s)
root (222.178.122.85): 1 Time(s)
root (45.135.232.159): 1 Time(s)
root (49.232.214.23): 1 Time(s)
sshd (45.135.232.159): 1 Time(s)
temp (45.43.57.225): 1 Time(s)
unknown (106.12.155.22): 1 Time(s)
unknown (185.129.61.3): 1 Time(s)
unknown (185.247.225.55): 1 Time(s)
unknown (186.42.173.67): 1 Time(s)
unknown (188.126.89.149): 1 Time(s)
unknown (212.193.30.32): 1 Time(s)
unknown (45.135.232.159): 1 Time(s)
unknown (45.155.204.39): 1 Time(s)
unknown (49.232.214.23): 1 Time(s)
uucp (176.111.173.238): 1 Time(s)
Invalid Users:
Unknown Account: 594 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
3 Miscellaneous warnings
18.556K Bytes accepted 19,001
18.556K Bytes sent via SMTP 19,001
======== ==================================================
1 Accepted 100.00%
-------- --------------------------------------------------
1 Total 100.00%
======== ==================================================
4 4xx Reject relay denied 100.00%
-------- --------------------------------------------------
4 Total 4xx Rejects 100.00%
======== ==================================================
53 Connections
25 Connections lost (inbound)
53 Disconnections
1 Removed from queue
1 Sent via SMTP
1 Illegal address syntax in SMTP command
1 SMTP dialog errors
13 Hostname verification errors (FCRDNS)
1 SMTP protocol violations
---------------------- Postfix End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin ------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End -------------------------
--------------------- SSHD Begin ------------------------
Disconnecting after too many authentication failures for user:
root : 1 Time(s)
Failed logins from:
1.15.25.243: 34 times
1.117.143.185: 18 times
35.228.169.211 (211.169.228.35.bc.googleusercontent.com): 25 times
42.192.54.145: 32 times
42.192.84.124: 30 times
45.43.57.225: 35 times
45.128.75.150: 36 times
45.135.232.159: 2 times
45.155.204.39: 2 times
49.232.148.48: 29 times
49.232.214.23: 1 time
49.233.183.141: 2 times
49.234.42.234: 21 times
51.15.197.4 (4-197-15-51.instances.scw.cloud): 2 times
52.131.246.255: 6 times
52.183.128.237: 28 times
52.184.91.79: 32 times
61.82.54.57: 35 times
66.98.113.244 (66.98.113.244.16clouds.com): 13 times
81.68.123.185: 37 times
81.68.157.155: 32 times
81.169.200.132 (h2821125.stratoserver.net): 15 times
82.166.147.151 (82-166-147-151.barak-online.net): 14 times
89.17.63.85: 8 times
101.231.146.34: 26 times
103.133.57.250: 1 time
103.168.150.5: 31 times
106.12.202.192: 1 time
106.58.169.162: 1 time
111.206.4.222: 18 times
113.106.162.114: 6 times
115.248.153.89: 46 times
116.117.157.69: 1 time
117.22.230.94: 1 time
117.248.249.70: 6 times
119.29.10.203: 35 times
119.29.168.177: 1 time
119.45.37.230: 25 times
119.84.128.24: 21 times
121.4.131.79: 32 times
121.18.88.186: 39 times
122.51.220.15: 34 times
125.124.5.221: 35 times
128.199.90.55: 16 times
132.255.253.49 (49.253.255.132.private.lvttelecom.com.br): 21 times
146.56.235.195: 26 times
151.69.90.144: 1 time
159.75.91.89: 32 times
159.203.111.100: 6 times
167.172.69.31: 7 times
176.111.173.218: 1 time
176.111.173.238: 1 time
182.135.64.12: 18 times
182.254.220.148: 17 times
188.166.22.79: 36 times
189.222.220.139 (189.222.220.139.dsl.dyn.telnor.net): 20 times
203.162.54.243 (static.vnpt.vn): 35 times
217.74.44.204 (217.74.44.204): 30 times
221.0.94.20: 13 times
222.178.122.85: 1 time
Illegal users from:
undef: 394 times
1.15.25.243: 14 times
1.117.143.185: 7 times
2.236.48.32: 5 times
31.202.97.15 (31-202-97-15-kh.maxnet.ua): 2 times
35.228.169.211 (211.169.228.35.bc.googleusercontent.com): 14 times
42.192.54.145: 18 times
42.192.84.124: 14 times
45.43.57.225: 15 times
45.128.75.150: 14 times
45.135.232.159: 1 time
45.155.204.39: 1 time
47.186.103.61 (47-186-103-61.dlls.tx.frontiernet.net): 2 times
49.232.148.48: 15 times
49.232.214.23: 1 time
49.234.42.234: 13 times
51.15.197.4 (4-197-15-51.instances.scw.cloud): 7 times
52.131.246.255: 3 times
52.183.128.237: 22 times
52.184.91.79: 18 times
61.82.54.57: 15 times
65.49.20.69 (scan-20.shadowserver.org): 1 time
66.98.113.244 (66.98.113.244.16clouds.com): 4 times
81.17.18.61 (block1-che.interlayer.co.uk): 2 times
81.68.123.185: 13 times
81.68.157.155: 15 times
81.169.200.132 (h2821125.stratoserver.net): 17 times
81.169.229.115 (h2544445.stratoserver.net): 2 times
82.166.147.151 (82-166-147-151.barak-online.net): 15 times
89.17.63.85: 8 times
101.231.146.34: 8 times
103.168.150.5: 12 times
106.12.155.22: 1 time
106.12.202.192: 3 times
111.206.4.222: 7 times
115.248.153.89: 12 times
116.117.157.69: 4 times
119.29.10.203: 11 times
119.45.37.230: 9 times
119.84.128.24: 9 times
121.4.131.79: 16 times
121.18.88.186: 11 times
122.51.220.15: 14 times
125.124.5.221: 14 times
128.199.90.55: 7 times
132.255.253.49 (49.253.255.132.private.lvttelecom.com.br): 6 times
141.98.10.60: 3 times
141.98.10.81: 4 times
141.98.10.82: 8 times
146.56.235.195: 14 times
159.75.91.89: 15 times
159.203.111.100: 13 times
167.172.69.31: 7 times
176.111.173.218: 7 times
176.111.173.237: 2 times
176.111.173.238: 3 times
181.93.216.186 (host186.181-93-216.telecom.net.ar): 2 times
182.135.64.12: 8 times
182.254.220.148: 8 times
183.104.206.223: 2 times
185.129.61.3: 1 time
185.247.225.55: 1 time
186.42.173.67 (67.173.42.186.static.anycast.cnt-grms.ec): 1 time
188.126.89.149: 1 time
188.166.22.79: 14 times
189.222.220.139 (189.222.220.139.dsl.dyn.telnor.net): 8 times
199.195.251.49: 3 times
203.162.54.243 (static.vnpt.vn): 9 times
205.185.121.149: 2 times
209.141.53.99 (abbrinym.com): 2 times
212.193.30.32: 1 time
212.193.30.64: 4 times
212.193.30.101 (slot0.iglogi-camo.com): 4 times
217.74.44.204 (217.74.44.204): 20 times
221.0.94.20: 6 times
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/ploop33257p1 394G 242G 132G 65% /
none 4.0G 0 4.0G 0% /dev
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################
4 Jahre
Logwatch for h2361197.stratoserver.net (Linux)
by root@zapf.in
################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Fri Oct 8 04:42:05 2021
Date Range Processed: yesterday
( 2021-Oct-07 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host: h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [ 79:80 ]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
A total of 8 sites probed the server
107.189.6.44
161.35.230.183
180.214.239.44
186.4.171.93
199.195.248.54
199.195.253.71
20.89.159.109
66.240.205.34
Requests with error response codes
400 Bad Request
null: 8 Time(s)
/config/getuser?index=0: 5 Time(s)
/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh: 2 Time(s)
/.env: 1 Time(s)
/robots.txt: 1 Time(s)
/socket.io/?noteId=siegen17_ak_wissenschaf ... HIRmfrGyaPhAABt: 1 Time(s)
/socket.io/?noteId=siegen17_ak_wissenschaf ... UAc7GRgvaA7AABu: 1 Time(s)
/socket.io/?noteId=siegen17_ak_wissenschaf ... fQrmw1trfMjAABs: 1 Time(s)
/w00tw00t.at.ISC.SANS.DFind:): 1 Time(s)
499 (undefined)
/socket.io/?noteId=siegen17_ak_wissenschaf ... HIRmfrGyaPhAABt: 1 Time(s)
/socket.io/?noteId=siegen17_ak_wissenschaf ... UAc7GRgvaA7AABu: 1 Time(s)
/socket.io/?noteId=siegen17_ak_wissenschaf ... ayL8h7horB1AABv: 1 Time(s)
/socket.io/?noteId=siegen17_ak_wissenschaf ... fQrmw1trfMjAABs: 1 Time(s)
500 Internal Server Error
/: 28 Time(s)
/.env: 5 Time(s)
/GponForm/diag_Form?style/: 4 Time(s)
/ecp/Current/exporttool/microsoft.exchange ... ool.application: 2 Time(s)
/robots.txt: 2 Time(s)
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 2 Time(s)
//login_sid.lua: 1 Time(s)
/?XDEBUG_SESSION_START=phpstorm: 1 Time(s)
/Autodiscover/Autodiscover.xml: 1 Time(s)
/_ignition/execute-solution: 1 Time(s)
/actuator/health: 1 Time(s)
/api/jsonws/invoke: 1 Time(s)
/console/: 1 Time(s)
/index.php?s=/Index/\x5Cthink\x5Capp/invok ... HelloThinkPHP21: 1 Time(s)
/mifs/.;/services/LogService: 1 Time(s)
/owa/auth/logon.aspx: 1 Time(s)
/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f: 1 Time(s)
/owa/auth/x.js: 1 Time(s)
/remote/fgt_lang?lang=/../../../..//////// ... lvpn_websession: 1 Time(s)
/wp-content/plugins/wp-file-manager/readme.txt: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
root (167.172.69.31): 61 Time(s)
root (180.33.245.35.bc.googleusercontent.com): 51 Time(s)
unknown (2.236.48.32): 44 Time(s)
root (191.31.104.17): 40 Time(s)
root (124.137.205.59): 38 Time(s)
root (49.232.110.250): 37 Time(s)
root (201.11.70.28): 36 Time(s)
root (49.232.148.48): 36 Time(s)
root (122.51.27.41): 35 Time(s)
root (203.195.220.117): 35 Time(s)
root (49.232.105.118): 35 Time(s)
root (81.68.215.204): 35 Time(s)
root (81.68.81.31): 35 Time(s)
root (117.232.127.51): 34 Time(s)
root (121.4.141.7): 34 Time(s)
root (159.75.23.229): 34 Time(s)
root (49.232.31.218): 34 Time(s)
root (85.185.161.202): 34 Time(s)
root (111.230.195.170): 33 Time(s)
root (118.89.70.169): 33 Time(s)
root (129.211.49.17): 33 Time(s)
root (49.233.183.141): 32 Time(s)
root (107.182.27.2.16clouds.com): 31 Time(s)
root (109.122.220.34): 31 Time(s)
root (134.175.21.43): 31 Time(s)
root (81.69.35.30): 31 Time(s)
root (106.52.59.65): 30 Time(s)
root (49.234.88.132): 30 Time(s)
root (120.53.121.152): 29 Time(s)
root (rub247.fo00.cn.interbusiness.it): 29 Time(s)
unknown (94.191.60.181): 29 Time(s)
root (106.53.209.243): 27 Time(s)
root (129.211.36.161): 27 Time(s)
root (14.5.12.34): 27 Time(s)
root (181.143.81.52): 27 Time(s)
root (45.40.199.207): 27 Time(s)
root (120.52.93.191): 26 Time(s)
root (114.255.252.30): 25 Time(s)
unknown (167.172.69.31): 25 Time(s)
root (177.144.185.31): 24 Time(s)
root (122.51.77.182): 23 Time(s)
root (118.24.38.117): 22 Time(s)
unknown (180.33.245.35.bc.googleusercontent.com): 22 Time(s)
unknown (45.40.199.207): 22 Time(s)
root (190.145.12.233): 21 Time(s)
root (201.72.190.98): 21 Time(s)
root (203.172.76.4): 21 Time(s)
root (250-72-182-201.provedornetlux.com.br): 21 Time(s)
unknown (rub247.fo00.cn.interbusiness.it): 21 Time(s)
root (mbl-109-61-121.dsl.net.pk): 20 Time(s)
unknown (120.53.121.152): 20 Time(s)
unknown (250-72-182-201.provedornetlux.com.br): 20 Time(s)
root (1.14.72.164): 19 Time(s)
root (42.192.234.117): 19 Time(s)
unknown (81.69.35.30): 19 Time(s)
root (167.99.243.48): 18 Time(s)
root (170.84.184.22): 18 Time(s)
unknown (106.52.59.65): 18 Time(s)
unknown (129.211.49.17): 18 Time(s)
unknown (66.98.113.244.16clouds.com): 18 Time(s)
root (94.191.60.181): 17 Time(s)
unknown (111.230.195.170): 17 Time(s)
unknown (134.175.21.43): 17 Time(s)
root (81.70.178.224): 16 Time(s)
unknown (107.182.27.2.16clouds.com): 16 Time(s)
unknown (117.232.127.51): 16 Time(s)
unknown (118.89.70.169): 16 Time(s)
unknown (49.232.31.218): 16 Time(s)
unknown (49.234.88.132): 16 Time(s)
root (1.117.143.185): 15 Time(s)
root (103.102.153.143): 15 Time(s)
root (49.234.201.237): 15 Time(s)
root (66.98.113.244.16clouds.com): 15 Time(s)
unknown (122.51.27.41): 15 Time(s)
unknown (129.211.36.161): 15 Time(s)
unknown (159.75.23.229): 15 Time(s)
unknown (81.68.81.31): 15 Time(s)
unknown (106.53.209.243): 14 Time(s)
unknown (109.122.220.34): 14 Time(s)
unknown (121.4.141.7): 14 Time(s)
unknown (122.51.77.182): 14 Time(s)
unknown (201.11.70.28): 14 Time(s)
unknown (49.233.183.141): 14 Time(s)
unknown (85.185.161.202): 14 Time(s)
unknown (203.195.220.117): 13 Time(s)
unknown (49.232.105.118): 13 Time(s)
unknown (49.232.110.250): 13 Time(s)
unknown (81.68.215.204): 13 Time(s)
root (132.232.105.237): 12 Time(s)
root (177.144.187.98): 12 Time(s)
unknown (124.137.205.59): 12 Time(s)
root (179.43.175.26): 11 Time(s)
root (58.57.15.29): 11 Time(s)
unknown (132.232.105.237): 11 Time(s)
unknown (177.144.185.31): 11 Time(s)
unknown (49.232.148.48): 11 Time(s)
root (200.49.37.68): 10 Time(s)
root (vmi687767.contaboserver.net): 10 Time(s)
unknown (1.117.143.185): 10 Time(s)
unknown (1.14.72.164): 10 Time(s)
unknown (170.84.184.22): 10 Time(s)
unknown (191.31.104.17): 10 Time(s)
unknown (49.234.201.237): 10 Time(s)
unknown (118.24.38.117): 9 Time(s)
unknown (81.70.178.224): 9 Time(s)
unknown (114.255.252.30): 8 Time(s)
unknown (181.143.81.52): 8 Time(s)
unknown (190.145.12.233): 8 Time(s)
unknown (42.192.234.117): 8 Time(s)
unknown (mbl-109-61-121.dsl.net.pk): 8 Time(s)
unknown (14.5.12.34): 7 Time(s)
unknown (201.72.190.98): 7 Time(s)
unknown (58.57.15.29): 7 Time(s)
root (139.59.92.135): 6 Time(s)
root (srv240-vps-st.jino.ru): 6 Time(s)
unknown (103.102.153.143): 6 Time(s)
unknown (176.111.173.237): 6 Time(s)
unknown (203.172.76.4): 6 Time(s)
unknown (120.52.93.191): 5 Time(s)
root (181.49.2.43): 4 Time(s)
root (221.0.94.20): 4 Time(s)
unknown (176.111.173.238): 4 Time(s)
unknown (179.43.175.26): 4 Time(s)
unknown (200.49.37.68): 4 Time(s)
unknown (vmi687767.contaboserver.net): 4 Time(s)
root (119.29.10.203): 3 Time(s)
unknown (139.59.92.135): 3 Time(s)
unknown (141.98.10.60): 3 Time(s)
unknown (199.195.251.49): 3 Time(s)
unknown (51.15.197.4): 3 Time(s)
unknown (141.98.10.121): 2 Time(s)
unknown (141.98.10.81): 2 Time(s)
unknown (141.98.10.82): 2 Time(s)
unknown (177.144.187.98): 2 Time(s)
unknown (188.126.89.154): 2 Time(s)
unknown (205.185.121.149): 2 Time(s)
unknown (45.135.232.159): 2 Time(s)
unknown (45.93.201.148): 2 Time(s)
unknown (81.25.152.154): 2 Time(s)
unknown (smtp15.walkertexas.de): 2 Time(s)
backup (94.191.60.181): 1 Time(s)
mysql (45.135.232.159): 1 Time(s)
news (94.191.60.181): 1 Time(s)
postgres (167.172.69.31): 1 Time(s)
root (112.33.16.34): 1 Time(s)
root (120.239.57.74): 1 Time(s)
root (2.236.48.32): 1 Time(s)
root (42.192.84.124): 1 Time(s)
root (51.15.197.4): 1 Time(s)
root (58.222.107.253): 1 Time(s)
sys (49.232.148.48): 1 Time(s)
unknown (111.10.24.147): 1 Time(s)
unknown (116.52.1.214): 1 Time(s)
unknown (119.29.10.203): 1 Time(s)
unknown (124.202.180.190): 1 Time(s)
unknown (181.49.2.43): 1 Time(s)
unknown (185.220.102.243): 1 Time(s)
unknown (185.247.225.61): 1 Time(s)
unknown (190.107.170.22): 1 Time(s)
unknown (192.42.116.16): 1 Time(s)
unknown (221.0.94.20): 1 Time(s)
unknown (36.80.48.9): 1 Time(s)
unknown (45.153.160.133): 1 Time(s)
unknown (45.153.160.135): 1 Time(s)
unknown (45.153.160.2): 1 Time(s)
unknown (5.2.73.66): 1 Time(s)
unknown (85.202.80.35): 1 Time(s)
www-data (107.182.27.2.16clouds.com): 1 Time(s)
www-data (45.93.201.148): 1 Time(s)
Invalid Users:
Unknown Account: 861 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
12 Miscellaneous warnings
23.861K Bytes accepted 24,434
23.861K Bytes sent via SMTP 24,434
======== ==================================================
1 Accepted 100.00%
-------- --------------------------------------------------
1 Total 100.00%
======== ==================================================
1 4xx Reject relay denied 100.00%
-------- --------------------------------------------------
1 Total 4xx Rejects 100.00%
======== ==================================================
94 Connections
74 Connections lost (inbound)
94 Disconnections
1 Removed from queue
1 Sent via SMTP
---------------------- Postfix End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin ------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End -------------------------
--------------------- SSHD Begin ------------------------
Failed logins from:
1.14.72.164: 19 times
1.117.143.185: 15 times
2.236.48.32: 1 time
14.5.12.34: 27 times
35.245.33.180 (180.33.245.35.bc.googleusercontent.com): 51 times
42.192.84.124: 1 time
42.192.234.117: 19 times
45.40.199.207: 27 times
45.93.201.148: 1 time
45.135.232.159: 1 time
49.232.31.218: 34 times
49.232.105.118: 35 times
49.232.110.250: 37 times
49.232.148.48: 37 times
49.233.183.141: 32 times
49.234.88.132: 30 times
49.234.201.237: 15 times
51.15.197.4 (4-197-15-51.instances.scw.cloud): 1 time
58.57.15.29: 11 times
58.222.107.253: 1 time
66.98.113.244 (66.98.113.244.16clouds.com): 15 times
81.68.81.31: 35 times
81.68.215.204: 35 times
81.69.35.30: 31 times
81.70.178.224: 16 times
81.177.136.204 (srv240-vps-st.jino.ru): 6 times
85.185.161.202: 34 times
94.191.60.181: 19 times
103.102.153.143 (goldenfast.net): 15 times
106.52.59.65: 30 times
106.53.209.243: 27 times
107.182.27.2 (107.182.27.2.16clouds.com): 32 times
109.122.220.34: 31 times
111.230.195.170: 33 times
112.33.16.34: 1 time
114.255.252.30: 25 times
117.232.127.51: 34 times
118.24.38.117: 22 times
118.89.70.169: 33 times
119.29.10.203: 3 times
120.52.93.191: 26 times
120.53.121.152: 29 times
120.239.57.74: 1 time
121.4.141.7: 34 times
122.51.27.41: 35 times
122.51.77.182: 23 times
124.109.61.121 (mbl-109-61-121.dsl.net.pk): 20 times
124.137.205.59: 38 times
129.211.36.161: 27 times
129.211.49.17: 33 times
132.232.105.237: 12 times
134.175.21.43: 31 times
139.59.92.135 (printasia.in): 6 times
159.75.23.229: 34 times
167.99.243.48: 18 times
167.172.69.31: 62 times
170.84.184.22: 18 times
177.144.185.31 (177-144-185-31.user.vivozap.com.br): 24 times
177.144.187.98 (177-144-187-98.user.vivozap.com.br): 12 times
179.43.175.26: 11 times
181.49.2.43: 4 times
181.143.81.52 (static-181-143-81-52.une.net.co): 27 times
190.145.12.233: 21 times
191.31.104.17 (191.31.104.17.static.gvt.net.br): 40 times
194.163.142.182 (vmi687767.contaboserver.net): 10 times
194.184.245.247 (rub247.fo00.cn.interbusiness.it): 29 times
200.49.37.68: 10 times
201.11.70.28: 36 times
201.72.190.98: 21 times
201.182.72.250 (250-72-182-201.provedornetlux.com.br): 21 times
203.172.76.4 (reverse-203-172-76-4.csloxinfo.net): 21 times
203.195.220.117: 35 times
221.0.94.20: 4 times
Illegal users from:
undef: 572 times
1.14.72.164: 10 times
1.117.143.185: 10 times
2.236.48.32: 44 times
5.2.73.66: 1 time
14.5.12.34: 7 times
35.245.33.180 (180.33.245.35.bc.googleusercontent.com): 22 times
36.80.48.9: 1 time
42.192.234.117: 8 times
45.40.199.207: 22 times
45.93.201.148: 2 times
45.135.232.159: 2 times
45.153.160.2: 1 time
45.153.160.133: 1 time
45.153.160.135: 1 time
49.232.31.218: 16 times
49.232.105.118: 13 times
49.232.110.250: 13 times
49.232.148.48: 11 times
49.233.183.141: 14 times
49.234.88.132: 16 times
49.234.201.237: 10 times
51.15.197.4 (4-197-15-51.instances.scw.cloud): 3 times
58.57.15.29: 7 times
65.49.20.67 (scan-18.shadowserver.org): 1 time
66.98.113.244 (66.98.113.244.16clouds.com): 18 times
81.25.152.154 (81-25-152-154.junet.se): 2 times
81.68.81.31: 15 times
81.68.215.204: 13 times
81.69.35.30: 19 times
81.70.178.224: 9 times
85.185.161.202: 14 times
85.202.80.35: 1 time
94.191.60.181: 29 times
103.102.153.143 (goldenfast.net): 6 times
106.52.59.65: 18 times
106.53.209.243: 14 times
107.182.27.2 (107.182.27.2.16clouds.com): 16 times
109.122.220.34: 14 times
111.10.24.147: 1 time
111.230.195.170: 17 times
114.255.252.30: 8 times
116.52.1.214: 1 time
117.232.127.51: 16 times
118.24.38.117: 9 times
118.89.70.169: 16 times
119.29.10.203: 1 time
120.52.93.191: 5 times
120.53.121.152: 20 times
121.4.141.7: 14 times
122.51.27.41: 15 times
122.51.77.182: 14 times
124.109.61.121 (mbl-109-61-121.dsl.net.pk): 9 times
124.137.205.59: 12 times
124.202.180.190: 1 time
129.211.36.161: 15 times
129.211.49.17: 18 times
132.232.105.237: 11 times
134.175.21.43: 17 times
139.59.92.135 (printasia.in): 3 times
141.98.10.60: 3 times
141.98.10.81: 2 times
141.98.10.82: 2 times
141.98.10.121: 2 times
159.75.23.229: 15 times
167.172.69.31: 25 times
170.84.184.22: 10 times
176.111.173.237: 6 times
176.111.173.238: 4 times
177.144.185.31 (177-144-185-31.user.vivozap.com.br): 11 times
177.144.187.98 (177-144-187-98.user.vivozap.com.br): 2 times
178.73.215.171 (178-73-215-171-static.glesys.net): 1 time
179.43.175.26: 4 times
181.49.2.43: 1 time
181.143.81.52 (static-181-143-81-52.une.net.co): 8 times
185.220.102.243 (185-220-102-243.torservers.net): 1 time
185.247.225.61: 1 time
188.126.89.154: 2 times
190.107.170.22: 1 time
190.145.12.233: 8 times
191.31.104.17 (191.31.104.17.static.gvt.net.br): 10 times
192.42.116.16 (tor-exit.hartvoorinternetvrijheid.nl): 1 time
194.163.142.182 (vmi687767.contaboserver.net): 4 times
194.184.245.247 (rub247.fo00.cn.interbusiness.it): 21 times
199.195.251.49: 3 times
200.49.37.68: 4 times
201.11.70.28: 14 times
201.72.190.98: 7 times
201.182.72.250 (250-72-182-201.provedornetlux.com.br): 20 times
203.172.76.4 (reverse-203-172-76-4.csloxinfo.net): 6 times
203.195.220.117: 13 times
205.185.118.82 (smtp15.walkertexas.de): 2 times
205.185.121.149: 2 times
221.0.94.20: 1 time
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/ploop33257p1 394G 242G 132G 65% /
none 4.0G 0 4.0G 0% /dev
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################
4 Jahre
[MediaWiki-announce] Subject: MediaWiki Extensions and Skins Security Release Supplement (1.31.16/1.35.4/1.36.2)
by Maryum Styles
Greetings-
With the security/maintenance release of MediaWiki 1.31.16/1.35.4/1.36.2
[0], we would also like to provide this supplementary announcement of
MediaWiki extensions and skins with now-public Phabricator tasks, security
patches and backports [1]:
== DataDump ==
+ (T286376, CVE-2021-32774) - Potential CSRF generating dumps
<
https://github.com/miraheze/DataDump/commit/67a82b76e186925330b89ace9c5fd...
>
== GlobalWatchlist ==
+ (T286385, CVE-2021-42046) - XSS in GlobalWatchlist
<https://gerrit.wikimedia.org/r/q/Ib7f9b009730fe0df283cec1169f84c7a83a58b1d>
<https://gerrit.wikimedia.org/r/q/Id2204fb5afe591d63764466de35ac0aaa5999983>
== Translate ==
+ (T286884, CVE-2021-42049) - Oversight action not reversible in translated
page
<https://gerrit.wikimedia.org/r/q/I4d95220ef414337147235f7ebedc9b945c3348e3
>
== GrowthExperiments ==
+ (T289063, CVE-2021-42047) - Mentor dashboard: Permanent XSS exploitable
by wiki admins
<
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/GrowthExperiments/+...
>
== GrowthExperiments ==
+ (T289064, CVE-2021-42048) - Newcomer homepage Impact module: Permanent
XSS exploitable by admins for new accounts
<https://gerrit.wikimedia.org/r/q/Iaa90a8976834d70caad592e9d1b18510318db537
>
== SecurePoll ==
+ (T289385, CVE-2021-42045) - Modified HTTP headers allow XSS
<https://gerrit.wikimedia.org/r/q/I4f04083cd00884d3b85245460774c81c7639a578>
== Growth Experiments ==
+ (T289408, CVE-2021-42044) - Permanent XSS exploitable by wiki admins
(client-side part)
<https://gerrit.wikimedia.org/r/q/I858d55fb2eca9b50ac6ef5a6f2a7b2784f0fa0d6>
== Growth Experiments ==
+ (T290692, CVE-2021-42042) - Permanent XSS exploitable by wiki admins in
SpecialEditGrowthConfig
<https://gerrit.wikimedia.org/r/q/Ibeb13d032ca044af53f6b2334e27b6b97b6f4e9f>
== Loops ==
+ (T287347, CVE-2021-42040) - Loops can cause php-fpm exhaustion
<https://gerrit.wikimedia.org/r/q/I0caf6f129f94612b5bcf406a171aa5ffedea1f80>
== CentralAuth ==
+ (T291696, CVE-2021-42041) - XSS vulnerability in the 'setchange' log
<https://gerrit.wikimedia.org/r/q/I7aeaa6e4de5ccaa5eeb6bf4fb00c96b01d5fea35>
== MediaSearch ==
+ (T291600, CVE-2021-42043) - XSS on Special:MediaSearch
<https://gerrit.wikimedia.org/r/q/If64eb5842237c92290d07ebc3fe14710d9de3fc2>
The Wikimedia Security Team recommends updating these extensions and/or
skins to the current master branch or relevant, supported release branch
[2] as soon as possible. Some of the referenced Phabricator tasks above
_may_ still be private. Unfortunately, when security issues are reported,
sometimes sensitive information is exposed and since Phabricator is
historical, we cannot make these tasks public without exposing this
sensitive information. If you have any additional questions or concerns
regarding this update, please feel free to contact security(a)wikimedia.org
or file a security task within Phabricator [3].
[0]
https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wiki...
[1] https://phabricator.wikimedia.org/T285414
[2] https://www.mediawiki.org/wiki/Version_lifecycle
[3] https://www.mediawiki.org/wiki/Reporting_security_bugs
_______________________________________________
MediaWiki announcements mailing list
To unsubscribe, go to:
4 Jahre