免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 3680 | 回复: 3
打印 上一主题 下一主题

[网络管理] 服务器是否被入侵了??? [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2007-07-12 09:18 |只看该作者 |倒序浏览
各位:

   我公司服务器采用rhel4 + postfix2.2.10 +openwebmail2.51+httpd2.0.52-9搭建了一个webmail,这两天在查看apache的access.log时,发现可疑日志,比如:
61.142.248.150 - - [09/Jul/2007:14:22:00 +0800] "GET http://data.alexa.com/data?cli=1 ... talled&amzn_id= HTTP/1.1" 301 555 "-" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0; FunWebProducts; .NET CLR 2.0.50727; Alexa Toolbar)"
61.135.166.231 - - [09/Jul/2007:16:37:53 +0800] "GET /mrtg/11.22.33.44_2.html HTTP/1.1" 200 6866 "-" "Baiduspider+(+http://www.baidu.com/search/spider.htm)"
202.103.67.57 - - [09/Jul/2007:17:19:08 +0800] "GET http://www.weibing.com.cn/Editor ... 1w2e3r4t5y6u7i8o9p0*a-b?hash=529C06014892EAE2DCE708391F90173D8CC843B4F65A HTTP/1.0" 404 325 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"
202.103.67.57 - - [09/Jul/2007:19:51:35 +0800] "GET http://www.weibing.com.cn/Editor ... 1w2e3r4t5y6u7i8o9p0*a-b?hash=529C06014892EAE2DCE708391F90173D8CC843B4F65A HTTP/1.0" 404 325 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"
222.222.72.244 - - [11/Jul/2007:22:53:04 +0800] "GET http://yf163.cn/ip88.php HTTP/1.0" 404 281 "http://www.cashsoldier.com/VerifyerLevel.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"222.222.72.244 - - [11/Jul/2007:22:53:04 +0800] "GET http://www.yahoo.com/ HTTP/1.0" 200 5625 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
222.222.72.244 - - [12/Jul/2007:02:14:25 +0800] "GET http://yf163.cn/ip88.php HTTP/1.0" 404 281 "http://www.cashsoldier.com/VerifyerLevel.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"222.222.72.244 - - [12/Jul/2007:02:14:25 +0800] "GET http://www.yahoo.com/ HTTP/1.0" 200 5626 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"

这些都不是我们公司的网站域名,打开http://www.weibing.com.cn/Editor ... 1w2e3r4t5y6u7i8o9p0*a-b?hash=529,显示如下页面:
q1w2e3r4t5y6u7i8o9p0*a-b?hash=529
HTTP_PROXY_CONNECTION:
HTTP_X_FORWARDED_FOR:
HTTP_VIA:
HTTP_MAX_FORWARDS:
REMOTE_ADDR=219.131.234.139
REMOTE_HOST=219.131.234.139
HTTP_PC_REMOTE_ADDR=
HTTP_X_FWD_IP_ADDR=
HTTP_CONNECTION=
VIA:
HTTP_FORWARDED:
FORWARDED:
HTTP_X_BLUECOAT_VIA:
HTTP_PROXY____:
HTTP_PROXY___________:
HTTP_X_HOST:
HTTP_X_REFERER:
HTTP_X_SERVER_HOSTNAME:
PROXY_HOST:
PROXY_PORT:
PROXY_REQUEST:
HTTP_CLIENT_IP:
HTTP_PRAGMA:
super or gateway or noproxy
Level:1
代理级别=超级代理
超级代理1=超级代理
代理级别=超级代理q1w2e3r4t5y6u7i8o9p0*a-b?hash=529

打开http://yf163.cn/ip88.php页面,显示如下:

----------------------------------------


Warning:  gethostbyaddr() [function.gethostbyaddr]: Address is not in a.b.c.d form in d:\vhost\yfd8927868\682\www\ip88.php on line 118


REMOTE_HOST=
REMOTE_ADDR=
----------------------------------------
CS_ProxyJudge Result=HIGH_ANONYMITY
----------------------------------------

而last,lastlog显示正常,请教各位,我是否被入侵了,我该如何处理?谢谢!

论坛徽章:
0
2 [报告]
发表于 2007-07-12 13:06 |只看该作者
自己顶!!!!

论坛徽章:
0
3 [报告]
发表于 2007-07-12 15:51 |只看该作者
再顶!!!!!!!!!!!!!!!!!!
virons 该用户已被删除
4 [报告]
发表于 2007-10-12 10:38 |只看该作者
提示: 作者被禁止或删除 内容自动屏蔽
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP