免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
楼主: quakelee
打印 上一主题 下一主题

大家有空帮看一下是否可能受到攻击 [复制链接]

论坛徽章:
1
荣誉版主
日期:2011-11-23 16:44:17
21 [报告]
发表于 2003-06-29 13:11 |只看该作者

大家有空帮看一下是否可能受到攻击

原帖由 "kinux" 发表:
   
haha!!! just stand there and look the system being attack and going to die...  
^_^!!
   

that server seems not log the snmp, I think we should log it.
but I scaned that server not found available snmp from outside

论坛徽章:
0
22 [报告]
发表于 2003-06-29 13:18 |只看该作者

大家有空帮看一下是否可能受到攻击

原帖由 "quakelee" 发表:
   

that server seems not log the snmp, I think we should log it.
but I scaned that server not found available snmp from outside
   

if your snmp is not open to public, i don't think it need to log, as it will use a lot of CPU resources..
so check BIND

论坛徽章:
0
23 [报告]
发表于 2003-06-29 13:21 |只看该作者

大家有空帮看一下是否可能受到攻击

$dig @your-dns-server-ip >; db.cache     
$grep DiG db.cache

论坛徽章:
0
24 [报告]
发表于 2003-06-29 15:38 |只看该作者
提示: 作者被禁止或删除 内容自动屏蔽

论坛徽章:
0
25 [报告]
发表于 2003-06-29 15:47 |只看该作者

大家有空帮看一下是否可能受到攻击

原帖由 "bsdxp" 发表:
我这种情况从上周五就发现啦,一台机器的80连接无端端高达100 个同时连接,可就是没记录的,后来查找根源,发现是病毒!!(赶紧去找找你的连接机器吧,好象是一种什么新病毒(具体还没查出来)

不过freebsd倒没..........
   

Port80 是用tcp連接, 不是用udp連接...
如果quakelee被攻击的机是网关, 也许是內网的机中毒引致..

安裝snort会方便一点找出真凶...

论坛徽章:
0
26 [报告]
发表于 2003-06-29 15:49 |只看该作者

大家有空帮看一下是否可能受到攻击

原帖由 "kinux" 发表:
   

Port80 是用tcp連接, 不是用udp連接...

no,no
udp also have port 80

论坛徽章:
0
27 [报告]
发表于 2003-06-29 15:51 |只看该作者

大家有空帮看一下是否可能受到攻击

原帖由 "i2era" 发表:

no,no
udp also have port 80
   

what service...

论坛徽章:
0
28 [报告]
发表于 2003-06-29 15:52 |只看该作者
提示: 作者被禁止或删除 内容自动屏蔽

论坛徽章:
0
29 [报告]
发表于 2003-06-29 16:00 |只看该作者

大家有空帮看一下是否可能受到攻击

我看了log..
主要还是code-red...
[Fri Jun 27 23:01:25 2003] [error] [client 219.140.129.178] File does not exist: /usr/local/www/data/default.ida
[Sat Jun 28 00:09:52 2003] [error] [client 202.159.52.39] File does not exist: /usr/local/www/data/default.ida
[Sat Jun 28 04:00:54 2003] [error] [client 202.138.177.27] File does not exist: /usr/local/www/data/default.ida
[Sat Jun 28 04:29:11 2003] [error] [client 202.85.76.212] File does not exist: /usr/local/www/data/default.ida
[Sat Jun 28 05:21:56 2003] [error] [client 202.75.96.11] File does not exist: /usr/local/www/data/default.ida
[Sat Jun 28 08:01:41 2003] [error] [client 202.88.152.11] File does not exist: /usr/local/www/data/default.ida
[Sat Jun 28 10:09:49 2003] [error] [client 61.167.60.211] File does not exist: /usr/local/www/data/default.ida
[Sat Jun 28 10:31:05 2003] [error] [client 202.85.76.212] File does not exist: /usr/local/www/data/default.ida
[Sat Jun 28 11:16:15 2003] [error] [client 61.50.142.26] File does not exist: /usr/local/www/data/default.ida
[Sat Jun 28 12:14:48 2003] [error] [client 202.85.76.212] File does not exist: /usr/local/www/data/default.ida
[Sat Jun 28 12:48:14 2003] [error] [client 202.85.76.212] File does not exist: /usr/local/www/data/default.ida
[Sat Jun 28 14:06:08 2003] [error] [client 202.84.39.97] File does not exist: /usr/local/www/data/default.ida
[Sat Jun 28 14:16:10 2003] [error] [client 202.85.76.212] File does not exist: /usr/local/www/data/default.ida
[Sat Jun 28 19:01:23 2003] [error] [client 202.85.76.212] File does not exist: /usr/local/www/data/default.ida
[Sat Jun 28 20:58:34 2003] [error] [client 202.165.245.13] File does not exist: /usr/local/www/data/default.ida
[Sat Jun 28 22:55:16 2003] [error] [client 202.85.76.212] File does not exist: /usr/local/www/data/default.ida
[Sun Jun 29 02:07:47 2003] [error] [client 202.85.76.212] File does not exist: /usr/local/www/data/default.ida
[Sun Jun 29 02:24:10 2003] [error] [client 202.59.200.194] File does not exist: /usr/local/www/data/default.ida
[Sun Jun 29 06:57:51 2003] [error] [client 202.85.76.212] File does not exist: /usr/local/www/data/default.ida
[Sun Jun 29 07:36:09 2003] [error] [client 202.85.76.212] File does not exist: /usr/local/www/data/default.ida
[Sun Jun 29 07:48:37 2003] [error] [client 202.41.10.25] File does not exist: /usr/local/www/data/default.ida
[Sun Jun 29 08:26:47 2003] [error] [client 218.91.254.114] File does not exist: /usr/local/www/data/scripts/..%5c%5c../winnt/s
ystem32/cmd.exe
[Sun Jun 29 13:13:38 2003] [error] [client 202.85.76.212] File does not exist: /usr/local/www/data/default.ida
[Sun Jun 29 15:17:19 2003] [error] [client 202.105.197.171] File does not exist: /usr/local/www/data/default.ida

论坛徽章:
0
30 [报告]
发表于 2003-06-29 16:01 |只看该作者

大家有空帮看一下是否可能受到攻击

原帖由 "kinux" 发表:
   

what service...
   
if u like,any service be able to use udp port 80.
well,all of us know tcp or udp have the port 0-65535.
so, if u only know the port num,u could not opinion it was used by tcp or udp,that is why.
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP