Home  >  Article  >  Operation and Maintenance  >  How to check if centos is invaded

How to check if centos is invaded

WBOY
WBOYOriginal
2022-02-09 10:14:353545browse

How to check whether centos is invaded: 1. Use the last command to view the system login log; 2. Use the lastb command to view the system login failure log; 3. Use the "last -f /var/log/wtmp" command to view You can log in.

How to check if centos is invaded

The operating environment of this article: centos 6.4 system, Dell G3 computer.

How to check whether centos has been invaded

The last command is used to display recent user or terminal login status. By viewing the log of the program through the last command, the administrator can learn who has or attempted to connect to the login server.

Log in to the system and enter last. Let’s check if anyone has logged in to the system.

As shown below

How to check if centos is invaded

The function of the lastb command is to display recent login failures. Log records, if the server is scanned and blasted, there will be many logs of failed logins

Log in to the system and enter lastb to see if anyone tries to log in to the system

As shown below

How to check if centos is invaded

Check the /var/log/wtmp file to check the suspicious IP login

Log in to the system and enter

last -f /var/log/wtmp

View suspicious logins

As shown below

How to check if centos is invaded

With three simple commands, you can see whether the server has been invaded and logged in.

1: last (view the system login log);

2: lastb (view the system login failure log);

3: last -f /var/log/wtmp (See suspicious logins).

Recommended tutorial: "centos tutorial"

The above is the detailed content of How to check if centos is invaded. For more information, please follow other related articles on the PHP Chinese website!

Statement:
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn