Server: 217.182.171.171:22672 · Debian 10 · TinyCP + WordPress · autore: Hermes Agent
ANOMALIE RILEVATE — richiesto follow-up
Riepilogo esecutivo
Uptime
11 giorni · load 0.00/0.02/0.00
Access logcurrente
NON leggibile con sudo -n attuale
wp-login/xmlrpcoggi
26 richieste da audit web 21/07
fail2ban
wordpress / wordpress-users / dovecot / sshd
1) Rotte esposte
- 22 SSH
- 25/465/587 SMTP
- 143/993/995/110 IMAP/POP3
- 21 FTP
- 2121 TinyCP
- 80/443 HTTP
- 3306 MySQL solo 127.0.0.1
Porte attese per server web+mail. Nessun listener anomalo oltre il normale stack TinyCP.
2) Fingerprinting e file esposi
/test/process.php
Quarantena; WP 6.6.5
readme.html
Esposto su 3 siti WP
license.txt
Esposto su 3 siti WP
xmlrpc.php
Presente sui 3 siti; .htaccess bloccato solo su dominanostra.it
wp-config.php
0644 invece di 0640/0600
Siti WP
dominanostra.it 6.6.5 · home.dominanostra.it 6.9.5 · ticker.dominanostra.it 7.0.2
3) Attacchi e brute-force
wp-login/xmlrpc oggi
26 richieste (audit web 21/07)
Probe xmlrpc
IP 2407:aa80::/32 prova decine di path /xmlrpc.php alternativi con UA Chrome/Firefox/Edge
Auth failures da mezzanotte
0 confermati su auth.log
fail2ban wordpress
0 active/0 banned
fail2ban wordpress-users
0 active/0 banned · 1 hit sul per-vhost
fail2ban dovecot
0 active/1 banned
4) Mail
Exim
Non-open-relay confermato
R=unknown_user_router
Presente da root/www-data/monnis; routing utente inesistente
Dovecot backend
/etc/dovecot/users assente → SQL/TinyCP
MX cocinalia.net
mail.cocinalia.net — dominio remoto, non ospitato qui
5) Log e conservazione
Access log corrente
NON leggibile da questo agente con sudo -n attuale
Error log
NON leggibile da questo agente con sudo -n attuale
fail2ban/exim log
Leggibili
Rotazione Apache
365 giorni; storico lungo disponibile in .gz
6) Raccomandazioni
- Bassa: nascondi readme.html e license.txt via .htaccess/sito.
- Media: porta wp-config.php a 0640/0600.
- Alta: estendi sudoers per leggere dominanostra.it.access.log corrente e error.log; oggi l'analisi errori è impedita.
- Media: valuta rate-limit/blocco geografico per 2407:aa80::/32 (scan xmlrpc massivo).
- Bassa: gestisci certificato TLS se vuoi uscire dal self-signed.
Audit readonly. Nessuna modifica sul server.