- 終端登入情況
last
- ssh登入情況
cat /var/log/secure | grep -i "accepted password"
- 定時任務
cat /var/log/cron
- 統計嘗試入侵的IP
cat /var/log/secure|awk '/Failed/{print $(NF-3)}'|sort|uniq -c|awk '{print $2"="$1;}'
- 禁用IP
echo sshd:183.40.138.224:deny >> hosts.deny
crontab -e
/var/spool/cron/crontabs