- 论坛徽章:
- 8
|
本帖最后由 zl624867243 于 2015-11-08 13:24 编辑
云主机对外扫描,我ps 了,也netstat了,但是iftop和nethlog总是可疑看到对外在发布流量。
看了/var/log/wtmp .message,secure等等。
实在找不到事哪个软件在对外扫描。求思路?
ps -aux和iftop -i eth1的在附件里,
netstat -ano 都找不到iftop里的ip- USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
- root 1 0.0 0.0 10372 744 ? Ss 10:32 0:02 init [3]
- root 2 0.0 0.0 0 0 ? S< 10:32 0:00 [migration/0]
- root 3 0.0 0.0 0 0 ? SN 10:32 0:00 [ksoftirqd/0]
- root 4 0.0 0.0 0 0 ? S< 10:32 0:00 [watchdog/0]
- root 5 0.0 0.0 0 0 ? S< 10:32 0:00 [migration/1]
- root 6 0.0 0.0 0 0 ? SN 10:32 0:00 [ksoftirqd/1]
- root 7 0.0 0.0 0 0 ? S< 10:32 0:00 [watchdog/1]
- root 8 0.0 0.0 0 0 ? S< 10:32 0:00 [migration/2]
- root 9 0.0 0.0 0 0 ? SN 10:32 0:00 [ksoftirqd/2]
- root 10 0.0 0.0 0 0 ? S< 10:32 0:00 [watchdog/2]
- root 11 0.0 0.0 0 0 ? S< 10:32 0:00 [migration/3]
- root 12 0.0 0.0 0 0 ? SN 10:32 0:00 [ksoftirqd/3]
- root 13 0.0 0.0 0 0 ? S< 10:32 0:00 [watchdog/3]
- root 14 0.0 0.0 0 0 ? S< 10:32 0:00 [events/0]
- root 15 0.0 0.0 0 0 ? S< 10:32 0:00 [events/1]
- root 16 0.0 0.0 0 0 ? S< 10:32 0:00 [events/2]
- root 17 0.0 0.0 0 0 ? S< 10:32 0:00 [events/3]
- root 18 0.0 0.0 0 0 ? S< 10:32 0:00 [khelper]
- root 53 0.0 0.0 0 0 ? S< 10:32 0:00 [kthread]
- root 60 0.0 0.0 0 0 ? S< 10:32 0:00 [kblockd/0]
- root 61 0.0 0.0 0 0 ? S< 10:32 0:00 [kblockd/1]
- root 62 0.0 0.0 0 0 ? S< 10:32 0:00 [kblockd/2]
- root 63 0.0 0.0 0 0 ? S< 10:32 0:00 [kblockd/3]
- root 64 0.0 0.0 0 0 ? S< 10:32 0:00 [kacpid]
- root 111 0.0 0.0 0 0 ? S< 10:32 0:00 [cqueue/0]
- root 112 0.0 0.0 0 0 ? S< 10:32 0:00 [cqueue/1]
- root 113 0.0 0.0 0 0 ? S< 10:32 0:00 [cqueue/2]
- root 114 0.0 0.0 0 0 ? S< 10:32 0:00 [cqueue/3]
- root 117 0.0 0.0 0 0 ? S< 10:32 0:00 [khubd]
- root 119 0.0 0.0 0 0 ? S< 10:32 0:00 [kseriod]
- root 211 0.0 0.0 0 0 ? S 10:32 0:00 [khungtaskd]
- root 212 0.0 0.0 0 0 ? S 10:32 0:00 [pdflush]
- root 213 0.0 0.0 0 0 ? S 10:32 0:00 [pdflush]
- root 214 0.0 0.0 0 0 ? S< 10:32 0:00 [kswapd0]
- root 215 0.0 0.0 0 0 ? S< 10:32 0:00 [aio/0]
- root 216 0.0 0.0 0 0 ? S< 10:32 0:00 [aio/1]
- root 217 0.0 0.0 0 0 ? S< 10:32 0:00 [aio/2]
- root 218 0.0 0.0 0 0 ? S< 10:32 0:00 [aio/3]
- root 355 0.0 0.0 0 0 ? S< 10:32 0:00 [kpsmoused]
- root 367 0.0 0.0 0 0 ? S< 10:32 0:00 [xenwatch]
- root 368 0.0 0.0 0 0 ? S< 10:32 0:00 [xenbus]
- root 414 0.0 0.0 0 0 ? S< 10:32 0:00 [ata/0]
- root 415 0.0 0.0 0 0 ? S< 10:32 0:00 [ata/1]
- root 416 0.0 0.0 0 0 ? S< 10:32 0:00 [ata/2]
- root 417 0.0 0.0 0 0 ? S< 10:32 0:00 [ata/3]
- root 418 0.0 0.0 0 0 ? S< 10:32 0:00 [ata_aux]
- root 434 0.0 0.0 0 0 ? S< 10:32 0:00 [kstriped]
- root 455 0.0 0.0 0 0 ? S< 10:33 0:01 [kjournald]
- root 477 0.0 0.0 0 0 ? S< 10:33 0:00 [kauditd]
- root 505 0.0 0.0 12640 768 ? S<s 10:33 0:00 /sbin/udevd -d
- root 959 0.0 0.0 0 0 ? S< 10:33 0:00 [net_accel/0]
- root 960 0.0 0.0 0 0 ? S< 10:33 0:00 [net_accel/1]
- root 962 0.0 0.0 0 0 ? S< 10:33 0:00 [net_accel/2]
- root 963 0.0 0.0 0 0 ? S< 10:33 0:00 [net_accel/3]
- root 1276 0.0 0.0 0 0 ? S< 10:33 0:00 [kmpathd/0]
- root 1277 0.0 0.0 0 0 ? S< 10:33 0:00 [kmpathd/1]
- root 1278 0.0 0.0 0 0 ? S< 10:33 0:00 [kmpathd/2]
- root 1279 0.0 0.0 0 0 ? S< 10:33 0:00 [kmpathd/3]
- root 1280 0.0 0.0 0 0 ? S< 10:33 0:00 [kmpath_handlerd]
- root 1303 0.0 0.0 0 0 ? S< 10:33 0:00 [kjournald]
- root 1697 0.0 0.0 10132 804 ? Ss 10:33 0:00 syslogd -m 0
- root 1702 0.0 0.0 3828 440 ? Ss 10:33 0:00 klogd -x
- rpc 1712 0.0 0.0 8076 608 ? Ss 10:33 0:00 portmap
- root 1744 0.0 0.0 0 0 ? S< 10:33 0:00 [rpciod/0]
- root 1745 0.0 0.0 0 0 ? S< 10:33 0:00 [rpciod/1]
- root 1746 0.0 0.0 0 0 ? S< 10:33 0:00 [rpciod/2]
- root 1747 0.0 0.0 0 0 ? S< 10:33 0:00 [rpciod/3]
- rpcuser 1756 0.0 0.0 11076 824 ? Ss 10:33 0:00 rpc.statd
- root 1778 0.0 0.0 22812 508 ? Ss 10:33 0:00 rpc.idmapd
- nscd 1832 0.0 0.0 201732 1524 ? Ssl 10:33 0:05 /usr/sbin/nscd
- root 1861 0.0 0.0 81476 2164 ? Ssl 10:33 0:02 /usr/local/aegis/aegis_update/AliYunDunUpdate
- root 1878 0.0 0.0 64820 1240 ? Ss 10:33 0:00 /usr/sbin/sshd
- root 1889 0.0 0.1 229796 7556 ? Ss 10:33 0:00 /usr/sbin/httpd
- root 1897 0.0 0.0 10148 600 ? Ss 10:33 0:00 /usr/sbin/pptpd
- root 1905 0.0 0.0 74840 1184 ? Ss 10:33 0:00 crond
- apache 1925 0.0 0.1 229796 4320 ? S 10:33 0:00 /usr/sbin/httpd
- apache 1926 0.0 0.1 229796 4320 ? S 10:33 0:00 /usr/sbin/httpd
- apache 1927 0.0 0.1 229796 4320 ? S 10:33 0:00 /usr/sbin/httpd
- apache 1928 0.0 0.1 229796 4320 ? S 10:33 0:00 /usr/sbin/httpd
- apache 1929 0.0 0.1 229796 4320 ? S 10:33 0:00 /usr/sbin/httpd
- apache 1930 0.0 0.1 229796 4320 ? S 10:33 0:00 /usr/sbin/httpd
- apache 1931 0.0 0.1 229796 4320 ? S 10:33 0:00 /usr/sbin/httpd
- apache 1932 0.0 0.1 229796 4320 ? S 10:33 0:00 /usr/sbin/httpd
- root 1944 0.0 0.8 410304 34364 ? Sl 10:33 0:01 /usr/bin/python2.6 /usr/bin/salt-minion -d
- root 1948 0.0 0.0 31628 280 ? Ssl 10:33 0:00 /usr/sbin/gshelld
- root 1961 0.2 0.0 9468 1064 ? Ss 10:33 0:23 /usr/local/ntp/bin/ntpd -c /usr/local/ntp/etc/ntp.conf -p /usr/local/ntp/tmp/ntpd.pid
- nagios 1973 0.0 0.0 39996 1076 ? Ss 10:33 0:00 /usr/local/nagios/bin/nrpe -c /usr/local/nagios/etc/nrpe.cfg -d
- root 1998 0.0 0.0 41164 984 ? Ss 10:33 0:00 nginx: master process /usr/local/nginx/sbin/nginx
- www 2000 0.0 0.6 67144 27492 ? S 10:33 0:00 nginx: worker process
- www 2001 0.0 0.6 67144 27356 ? S 10:33 0:00 nginx: worker process
- www 2002 0.0 0.6 67144 27568 ? S 10:33 0:00 nginx: worker process
- www 2003 0.0 0.6 67296 27620 ? S 10:33 0:00 nginx: worker process
- root 2040 0.3 5.3 1706288 218392 ? Sl 10:33 0:30 /usr/bin/java -Djava.util.logging.config.file=/usr/local/edm/conf/logging.properties -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -server -XX:PermSize=128M -XX:MaxPermSize=256m -Djava.endorsed.dirs=/usr/local/edm/endorsed -classpath /usr/local/edm/bin/bootstrap.jar -Dcatalina.base=/usr/local/edm -Dcatalina.home=/usr/local/edm -Djava.io.tmpdir=/usr/local/edm/temp org.apache.catalina.startup.Bootstrap start
- root 2077 1.1 14.6 1582352 592936 ? Sl 10:33 1:51 /usr/bin/java -Xms1G -Xmx1G -Djava.util.logging.config.file=logging.properties -Djava.security.auth.login.config=/usr/local/activemq/conf/login.config -Dcom.sun.management.jmxremote -Djava.awt.headless=true -Djava.io.tmpdir=/usr/local/activemq/tmp -Dactivemq.classpath=/usr/local/activemq/conf; -Dactivemq.home=/usr/local/activemq -Dactivemq.base=/usr/local/activemq -Dactivemq.conf=/usr/local/activemq/conf -Dactivemq.data=/usr/local/activemq/data -jar /usr/local/activemq/bin/activemq.jar start
- root 2078 0.0 0.0 85688 2000 ? Sl 10:33 0:00 /opt/soft/redis-2.8.8/src/redis-server *:7001
- root 2079 0.0 0.0 85688 1992 ? Sl 10:33 0:00 /opt/soft/redis-2.8.8/src/redis-server *:6389
- root 2080 0.0 0.0 85952 2136 ? Sl 10:33 0:00 /opt/soft/redis-2.8.8/src/redis-server *:6381
- root 2081 0.0 0.0 85688 1992 ? Sl 10:33 0:00 /opt/soft/redis-2.8.8/src/redis-server *:7002
- root 2082 0.0 0.0 86484 2380 ? Sl 10:33 0:00 /opt/soft/redis-2.8.8/src/redis-server *:6384
- root 2083 0.9 0.1 91680 6520 ? Sl 10:33 1:30 /opt/soft/redis-2.8.8/src/redis-server *:6379
- root 2120 0.0 0.0 133388 3472 ? Ss 10:33 0:00 php-fpm: master process (/opt/php5.3/etc/php-fpm.conf)
- www 2122 0.3 0.3 140364 13788 ? S 10:33 0:32 php-fpm: pool www
- root 2459 0.0 0.0 91044 3540 ? Ss 10:33 0:02 sshd: root@pts/0,pts/2
- root 2510 0.0 0.0 68456 1752 pts/0 Ss 10:33 0:00 -bash
- root 2650 0.0 0.0 90428 3544 ? Ss 10:33 0:00 sshd: root@pts/1
- root 2693 0.0 0.0 68456 1752 pts/1 Ss 10:33 0:00 -bash
- nagios 2957 0.0 0.0 23836 1324 ? Ssl 10:34 0:02 /usr/local/nagios/bin/nagios -d /usr/local/nagios/etc/nagios.cfg
- root 2961 0.0 0.0 3816 504 tty1 Ss+ 10:34 0:00 /sbin/mingetty tty1
- root 2962 0.0 0.0 3816 504 tty2 Ss+ 10:34 0:00 /sbin/mingetty tty2
- zabbix 3205 0.0 0.0 104328 2836 ? S 10:34 0:00 /usr/local/zabbix/sbin/zabbix_server
- zabbix 3230 0.0 0.0 47672 852 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_agentd
- zabbix 3232 0.0 0.0 47672 1068 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_agentd: collector [idle 1 sec]
- zabbix 3233 0.0 0.0 47676 1160 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_agentd: listener #1 [waiting for connection]
- zabbix 3234 0.0 0.0 47676 1132 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_agentd: listener #2 [waiting for connection]
- zabbix 3235 0.0 0.0 47676 1132 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_agentd: listener #3 [waiting for connection]
- zabbix 3236 0.0 0.0 47692 944 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_agentd: active checks #1 [idle 1 sec]
- root 3270 0.0 0.0 68260 1432 ? S 10:35 0:00 /bin/sh /opt/mysql/bin/mysqld_safe --datadir=/opt/data/dbdata/mysqldata --pid-file=/opt/data/dbdata/mysqldata/nagios.com.pid
- mysql 4128 0.4 3.5 528596 143964 ? Sl 10:35 0:43 /opt/mysql/bin/mysqld --basedir=/opt/mysql --datadir=/opt/data/dbdata/mysqldata --plugin-dir=/opt/mysql/lib/mysql/plugin --user=mysql --log-error=/opt/data/dbdata/mysqldata/nagios.com.err --open-files-limit=65535 --pid-file=/opt/data/dbdata/mysqldata/nagios.com.pid --socket=/opt/mysql/tmp/mysql.sock --port=3306
- zabbix 4183 0.0 0.0 104328 2244 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: configuration syncer [synced configuration in 0.033895 sec, idle 60 sec]
- zabbix 4184 0.0 0.0 104328 1212 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: db watchdog [synced alerts config in 0.001157 sec, idle 60 sec]
- zabbix 4185 0.0 0.2 160688 11408 ? S 10:35 0:04 /usr/local/zabbix/sbin/zabbix_server: poller #1 [got 8 values in 0.026112 sec, idle 1 sec]
- zabbix 4186 0.0 0.2 160652 11336 ? S 10:35 0:04 /usr/local/zabbix/sbin/zabbix_server: poller #2 [got 0 values in 0.000004 sec, idle 1 sec]
- zabbix 4187 0.0 0.2 160656 11428 ? S 10:35 0:03 /usr/local/zabbix/sbin/zabbix_server: poller #3 [got 9 values in 0.025155 sec, idle 1 sec]
- zabbix 4188 0.0 0.2 160652 11464 ? S 10:35 0:04 /usr/local/zabbix/sbin/zabbix_server: poller #4 [got 0 values in 0.000002 sec, idle 1 sec]
- zabbix 4189 0.0 0.2 160652 11248 ? S 10:35 0:03 /usr/local/zabbix/sbin/zabbix_server: poller #5 [got 0 values in 0.000002 sec, idle 1 sec]
- zabbix 4190 0.0 0.1 160548 5148 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: unreachable poller #1 [got 0 values in 0.000003 sec, idle 5 sec]
- zabbix 4191 0.0 0.0 104620 1896 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: trapper #1 [processed data in 0.000258 sec, waiting for connection]
- zabbix 4192 0.0 0.0 104620 1896 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: trapper #2 [processed data in 0.001277 sec, waiting for connection]
- zabbix 4193 0.0 0.0 104620 1896 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: trapper #3 [processed data in 0.002787 sec, waiting for connection]
- zabbix 4195 0.0 0.0 104620 1896 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: trapper #4 [processed data in 0.002482 sec, waiting for connection]
- zabbix 4197 0.0 0.0 104620 1896 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: trapper #5 [processed data in 0.002839 sec, waiting for connection]
- zabbix 4199 0.0 0.0 104780 1068 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: icmp pinger #1 [got 0 values in 0.000004 sec, idle 5 sec]
- zabbix 4201 0.0 0.0 104544 1524 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: alerter [sent alerts: 0 success, 0 fail in 0.000641 sec, idle 30 sec]
- zabbix 4202 0.0 0.0 104868 1676 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: housekeeper [deleted 55091 hist/trends, 0 items, 0 events, 0 sessions, 0 alarms, 0 audit items in 11.921236 sec, idle 1 hour(s)]
- zabbix 4204 0.0 0.0 104480 2540 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: timer #1 [processed 27 triggers, 0 events in 0.000525 sec, 0 maintenances in 0.000000 sec, idle 30 sec]
- zabbix 4205 0.0 0.0 104332 1216 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: http poller #1 [got 0 values in 0.000585 sec, idle 5 sec]
- zabbix 4207 0.0 0.0 160088 2960 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: discoverer #1 [processed 0 rules in 0.000559 sec, idle 60 sec]
- zabbix 4209 0.0 0.2 104972 8880 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: history syncer #1 [synced 0 items in 0.000001 sec, idle 5 sec]
- zabbix 4210 0.0 0.2 104964 8144 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: history syncer #2 [synced 0 items in 0.000001 sec, idle 5 sec]
- zabbix 4212 0.0 0.1 104872 7828 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: history syncer #3 [synced 80 items in 0.002552 sec, idle 5 sec]
- zabbix 4215 0.0 0.1 105060 7324 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: history syncer #4 [synced 0 items in 0.000002 sec, idle 5 sec]
- zabbix 4217 0.0 0.0 104452 2144 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: escalator [processed 0 escalations in 0.000436 sec, idle 3 sec]
- zabbix 4218 0.0 0.0 104332 1216 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: proxy poller #1 [exchanged data with 0 proxies in 0.000003 sec, idle 5 sec]
- zabbix 4220 0.0 0.0 104328 1028 ? S 10:35 0:00 /usr/local/zabbix/sbin/zabbix_server: self-monitoring [processed data in 0.000004 sec, idle 1 sec]
- root 4242 0.0 0.0 68460 1780 pts/2 Ss+ 10:35 0:00 -bash
- root 4293 0.0 0.2 273196 8408 ? Sl 10:35 0:01 /usr/local/aegis/aegis_client/aegis_00_79/AliYunDun
- www 5373 0.3 0.4 144224 17504 ? S 10:40 0:29 php-fpm: pool www
- root 6056 0.0 0.0 65624 1012 pts/1 R+ 13:17 0:00 ps -aux
- root 7732 0.0 0.0 123024 1992 ? Sl 10:52 0:00 /usr/local/aegis/aegis_quartz/aegis_quartz
- root 11633 46.3 0.6 45604 26868 pts/0 S+ 11:11 58:46 nethogs eth1
- www 14694 0.3 0.4 144480 17448 ? R 11:26 0:23 php-fpm: pool www
复制代码 |
|