Comments (9)
这个好久没更新了,有漏洞的。你可以去用别人改的版本,也可以自己修复一下。https://blog.hgtrojan.com/index.php/archives/247/
上面这篇博文的评论区有修复教程。
这个是别人推出漏洞修复版:
https://github.com/yisier/nps
from nps.
这个不是开源的吗?有木马的话自己看源代码自己编译啊
from nps.
这个不是开源的吗?有木马的话自己看源代码自己编译啊
可惜我不是直接用的源码编译, 用的是编译好的, 我想大部分人应该用的都是编译好的版本, 所以在前面有人说最好用源码自己编译,不要用编译好的版本.
from nps.
之前曝光过默认配置有漏洞,要改一下,可以google搜一下
from nps.
怎么更改呢
from nps.
漏洞挺严重的
https://github.com/weishen250/npscrack
from nps.
腾讯云发提醒短信了。
from nps.
0.26.10版本有确定的SSH字典攻击,只要启动npc,在secure日志中就可以看到大量的ssh攻击,我也是花费了几天的时间查清楚的,幸好没有被攻破。
Jun 21 01:42:54 P40 sshd[90342]: Failed password for invalid user rootuser from 127.0.0.1 port 41392 ssh2
Jun 21 01:42:56 P40 sshd[90342]: Connection closed by invalid user rootuser 127.0.0.1 port 41392 [preauth]
Jun 21 01:44:21 P40 sshd[90513]: Invalid user rfm from 127.0.0.1 port 52754
Jun 21 01:44:21 P40 sshd[90513]: pam_unix(sshd:auth): check pass; user unknown
Jun 21 01:44:21 P40 sshd[90513]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=127.0.0.1
Jun 21 01:44:22 P40 sshd[90513]: Failed password for invalid user rfm from 127.0.0.1 port 52754 ssh2
Jun 21 01:44:23 P40 sshd[90513]: Connection closed by invalid user rfm 127.0.0.1 port 52754 [preauth]
Jun 21 01:44:36 P40 sshd[90537]: Invalid user huangmengqi from 127.0.0.1 port 38172
Jun 21 01:44:37 P40 sshd[90537]: pam_unix(sshd:auth): check pass; user unknown
Jun 21 01:44:37 P40 sshd[90537]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=127.0.0.1
Jun 21 01:44:39 P40 sshd[90537]: Failed password for invalid user huangmengqi from 127.0.0.1 port 38172 ssh2
Jun 21 01:44:41 P40 sshd[90537]: Connection closed by invalid user huangmengqi 127.0.0.1 port 38172 [preauth]
Jun 21 01:45:07 P40 sshd[90585]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=127.0.0.1 user=root
Jun 21 01:45:10 P40 sshd[90585]: Failed password for root from 127.0.0.1 port 50230 ssh2
Jun 21 01:45:10 P40 sshd[90585]: Connection closed by authenticating user root 127.0.0.1 port 50230 [preauth]
from nps.
from nps.
Related Issues (20)
- 通过API或者web新增客户端可以自定义id HOT 1
- 服务端window版本报木马,不敢用啊,近期有用的哥们吗? HOT 2
- 域名解析到内网IP地址
- 如果使用tcp隧道,应该怎么获取客户端IP地址呢 HOT 10
- 【新年快乐】请教下域名+Nginx的使用问题 HOT 2
- 请问如何在小米路由中配置自启动? HOT 1
- 域名解析可以支持TCP/UDP吗
- 这个项目为啥没人维护了 HOT 2
- 在服务器同时安装了Nginx和NPS,域名解析不起作用
- nps针对web启用http_cache后,Linux和Windows各自缓存路径在哪里
- Requesting NPS server through iOS mobile end, the request body is lost, and the mobile end reports 408 HOT 2
- 新增客户端状态显示关闭
- 腾讯云报毒
- 网络错误无法重新连接:connect: network is unreachabl
- 希望大佬添加支持打洞技术
- 添加域名解析代理到本地时提示找不到客户端
- 创建一个nps-mux连接服务端会创建一个线程而且不会自动回收
- 为什么显示病毒
- 请问有NPS WebUI server的群晖spk安装包吗?
- 建议客户端id支持ip地址形式或数字+字母、新增资源表单时支持下拉选择客户端id HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from nps.