|
最近服务器被别人攻击,IP地址都是国外的。半夜三更系统负载会到94。
日志如下:
/etc/cron.daily/00webalizer:
Error: Skipping oversized log record
Error: Skipping oversized log record
Error: Skipping oversized log record
Error: Skipping oversized log record
Error: Skipping oversized log record
Error: Skipping oversized log record
Error: Skipping oversized log record
Error: Skipping oversized log record
Error: Skipping oversized log record
Error: Skipping oversized log record
Error: Skipping oversized log record
Error: Skipping oversized log record
Error: Skipping oversized log record
Error: Skipping oversized log record
Error: Skipping oversized log record
Did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA:
86.35.83.210 : 4 Time(s)
216.255.6.116 : 3 Time(s)
211.244.151.78 : 2 Time(s)
195.22.38.173 : 1 Time(s)
217.225.228.190 : 1 Time(s)
87.248.66.45 : 1 Time(s)
84.26.3.15 : 1 Time(s)
207.236.241.150 : 1 Time(s)
84.30.50.225 : 1 Time(s)
85.18.136.108 : 1 Time(s)
81.75.116.73 : 1 Time(s)
83.27.132.34 : 1 Time(s)
85.83.0.52 : 1 Time(s)
200.45.226.19 : 1 Time(s)
69.253.25.53 : 1 Time(s)
59.95.224.199 : 1 Time(s)
189.163.11.234 : 1 Time(s)
然后就是邮件pop还有vsftp当掉。
atd服务死掉和xfs也完蛋了。
有谁可以出点主意怎么阻止这样的攻击?!
谢谢阿! |
|