- 终端登录情况
last
- ssh登录情况
cat /var/log/secure | grep -i "accepted password"
- 定时任务
cat /var/log/cron
- 统计尝试入侵的IP
cat /var/log/secure|awk '/Failed/{print $(NF-3)}'|sort|uniq -c|awk '{print $2"="$1;}'
- 禁用IP
echo sshd:183.40.138.224:deny >> hosts.deny
crontab -e
/var/spool/cron/crontabs