Skip to content

Instantly share code, notes, and snippets.

@stopandcatchfire
Forked from gfoss/ssh-attempts.txt
Created February 27, 2016 07:43
Show Gist options
  • Save stopandcatchfire/5d03cb78dfc184ee9e9f to your computer and use it in GitHub Desktop.
Save stopandcatchfire/5d03cb78dfc184ee9e9f to your computer and use it in GitHub Desktop.
grep IP addresses from auth logs to see attempted ssh attempts into your box w/ invalid creds {ubuntu}
#search for invalid logon attempts, pull out IP, remove dupes, sort...
$ grep -rhi 'invalid' /var/log/auth.log* | awk '{print $10}' | uniq | sort > ~/ips.txt
#look em up
$ for i in `cat ~/ips.txt`; do @nslookup $i 2>/dev/null | grep Name | tail -n 1 | cut -d " " -f 3; done > ~/who.txt
# :-) #
$ do moar things...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment