免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
楼主: quakelee
打印 上一主题 下一主题

大家有空帮看一下是否可能受到攻击 [复制链接]

论坛徽章:
1
荣誉版主
日期:2011-11-23 16:44:17
11 [报告]
发表于 2003-06-29 12:16 |只看该作者

大家有空帮看一下是否可能受到攻击

另外也有可能不是内核崩溃,我记得freebsd如果内核崩溃之后会自动重启的,可是系统挂住了没有自动重启,最后是叫机房的人手动重启的:(

论坛徽章:
0
12 [报告]
发表于 2003-06-29 12:29 |只看该作者

大家有空帮看一下是否可能受到攻击

原帖由 "quakelee" 发表:
   
all services I was running is in the first one,
I have checked the vsftpd's log but is okay.
before crashed it got about 480kb/s packet rate in 5 minutes, and after that the machine crashed.
..........
   

480Kb/s should be  higher, and i can sure you are being attack by udp, check you snmp are open to public..
Try to check there is any advisories on your system application software..

论坛徽章:
1
荣誉版主
日期:2011-11-23 16:44:17
13 [报告]
发表于 2003-06-29 12:36 |只看该作者

大家有空帮看一下是否可能受到攻击

原帖由 "kinux" 发表:
   

480Kb/s should be  higher, and i can sure you are being attack by udp, check you snmp are open to public..
Try to check there is any advisories on your system application software..

the snmp's port is opening
but it dosen't everyone can get the snmp pack, only a community for a ip is allowed. it can make machine down?

论坛徽章:
0
14 [报告]
发表于 2003-06-29 12:45 |只看该作者

大家有空帮看一下是否可能受到攻击

原帖由 "quakelee" 发表:

the snmp's port is opening
but it dosen't everyone can get the snmp pack, only a community for a ip is allowed. it can make machine down?
   
Not sure, but i know snmp is using udp packets, any other service using udp??
such as DNS, OpenSSH(Slapper on linux),     
use sockstat -4 and netstat -a
to find upd and datagram..to check you system..

take a look here
http://www.tisc2001.com/newsletters/324.html

论坛徽章:
0
15 [报告]
发表于 2003-06-29 12:48 |只看该作者

大家有空帮看一下是否可能受到攻击

看来像udp flood

论坛徽章:
1
荣誉版主
日期:2011-11-23 16:44:17
16 [报告]
发表于 2003-06-29 12:49 |只看该作者

大家有空帮看一下是否可能受到攻击

原帖由 "kinux" 发表:
   
Not sure, but i know snmp is using udp packets, any other service using udp??
such as DNS, OpenSSH(Slapper on linux),
   
-________________-

it has a DNS on it maybe is a bind8, I don't exactly now:(
because I just have a part of permit on that server
and a sshd

论坛徽章:
0
17 [报告]
发表于 2003-06-29 13:00 |只看该作者

大家有空帮看一下是否可能受到攻击

原帖由 "quakelee" 发表:
   
-________________-

it has a DNS on it maybe is a bind8, I don't exactly now
because I just have a part of permit on that server
and a sshd
   
Hey!!Hey!!! Don't use this face look at me, i just help to analise any possibilities happened on your system, the problem still need you to solve..with following link, take a look..
http://www.tisc2001.com/newsletters/324.html
also, you DNS runing BIND8, oh no, i have throw BIND aways long time..
take a look here about Bind
http://www.securityfocus.com/guest/17905

论坛徽章:
1
荣誉版主
日期:2011-11-23 16:44:17
18 [报告]
发表于 2003-06-29 13:03 |只看该作者

大家有空帮看一下是否可能受到攻击

原帖由 "kinux" 发表:
   
Hey!!Hey!!! Don't use this face look at me, i just help to analise any possibilities happened on your system, the problem still need you to solve..with following link, take a look..
http://www...........
   
no no It is not face to you
I just feel bad
the boss go out to swim and I am finding the bugs without full permition   

论坛徽章:
0
19 [报告]
发表于 2003-06-29 13:06 |只看该作者

大家有空帮看一下是否可能受到攻击

原帖由 "quakelee" 发表:
   
no no It is not face to you
I just feel bad
the boss go out to swim and I am finding the bugs without full permition   
   
haha!!! just stand there and look the system being attack and going to die...  
^_^!!

论坛徽章:
0
20 [报告]
发表于 2003-06-29 13:08 |只看该作者

大家有空帮看一下是否可能受到攻击

$dig @<victim_ip>; version.bind chaos txt | grep \"8
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP