| 发表于:2007-12-12 10:00:17 楼主 |
紧急求助: 访问速度超慢, web服务80端口出现大量的访问,疑似ddos攻击, 哪位大哥帮忙看下? 谢谢... ping发现大量丢包的情况出现,进入服务器发现 netstat -an 出现大量的80端口扫描; 带宽:3m左右;cpu:5-20%之间 似呼都正常。 怀疑是流量攻击: 用netstat -na命令观察到有大量的established、time_wait等状态存在, tcp 58.61.153.xx:80 220.172.140.233:4974 established tcp 58.61.153.xx:80 220.172.140.233:4976 established tcp 58.61.153.xx:80 220.172.140.233:4978 established tcp 58.61.153.xx:80 220.179.74.210:12705 established tcp 58.61.153.xx:80 220.181.19.164:9569 time_wait tcp 58.61.153.xx:80 220.181.19.164:9618 time_wait tcp 58.61.153.xx:80 220.181.19.164:11039 time_wait ...大量相似 tcp 58.61.153.xx:80 220.181.26.100:38715 time_wait 紧急求助: 访问速度超慢, web服务80端口出现大量的访问,疑似ddos攻击, 哪位大哥帮忙看下? 谢谢... ping发现大量丢包的情况出现,进入服务器发现 netstat -an 出现大量的80端口扫描; 带宽:3m左右;cpu:5-20%之间 似呼都正常。 怀疑是流量攻击: 用netstat -na命令观察到有大量的established、time_wait等状态存在, tcp 58.61.153.xx:80 220.172.140.233:4974 established tcp 58.61.153.xx:80 220.172.140.233:4976 established tcp 58.61.153.xx:80 220.172.140.233:4978 established tcp 58.61.153.xx:80 220.179.74.210:12705 established tcp 58.61.153.xx:80 220.181.19.164:9569 time_wait tcp 58.61.153.xx:80 220.181.19.164:9618 time_wait tcp 58.61.153.xx:80 220.181.19.164:11039 time_wait ...大量相似 tcp 58.61.153.xx:80 220.181.26.100:38715 time_wait tcp 58.61.153.xx:80 220.181.26.100:38962 time_wait tcp 58.61.153.xx:80 220.181.26.100:39377 time_wait tcp 58.61.153.xx:80 220.181.26.100:40501 fin_wait_2 tcp 58.61.153.xx:80 220.181.26.100:40552 fin_wait_2 tcp 58.61.153.xx:80 220.181.26.100:59746 time_wait tcp 58.61.153.xx:80 220.181.26.100:59885 time_wait tcp 58.61.153.xx:80 220.181.26.100:60288 time_wait tcp 58.61.153.xx:80 220.181.26.100:60765 time_wait tcp 58.61.153.xx:80 220.181.26.100:60878 time_wait tcp 58.61.153.xx:80 220.186.42.151:23317 established tcp 58.61.153.xx:80 220.188.151.39:64585 established tcp 58.61.153.xx:80 220.189.215.102:36624 established tcp 58.61.153.xx:80 220.189.252.236:24649 established tcp 58.61.153.xx:80 220.190.77.3:1596 established tcp 58.61.153.xx:80 220.190.77.3:1607 established tcp 58.61.153.xx:80 220.190.77.3:1608 established tcp 58.61.153.xx:80 220.190.77.3:1609 established tcp 58.61.153.xx:80 220.190.77.3:1610 established tcp 58.61.153.xx:80 220.190.77.3:1611 established tcp 58.61.153.xx:80 220.190.77.3:1612 established tcp 58.61.153.xx:80 220.190.77.3:1613 established tcp 58.61.153.xx:80 220.198.168.248:56955 established tcp 58.61.153.xx:80 220.201.2.25:43040 established tcp 58.61.153.xx:80 220.205.4.239:2772 established tcp 58.61.153.xx:80 220.205.4.239:2773 established tcp 58.61.153.xx:80 220.205.4.239:2781 established tcp 58.61.153.xx:80 220.205.4.239:2782 established tcp 58.61.153.xx:80 220.207.78.229:1870 established tcp 58.61.153.xx:80 220.232.107.25:33447 established ...大量相似 tcp 58.61.153.xx:80 220.234.92.202:25320 established ...大量相似 tcp 58.61.153.xx:80 220.234.92.202:25355 established tcp 58.61.153.xx:80 220.234.92.202:25361 established tcp 58.61.153.xx:80 220.249.118.234:53527 established tcp 58.61.153.xx:80 221.0.76.60:53859 established tcp 58.61.153.xx:80 221.0.82.207:1646 established tcp 58.61.153.xx:80 221.3.31.80:1204 established tcp 58.61.153.xx:80 221.3.38.142:4200 established tcp 58.61.153.xx:80 221.3.55.183:2037 established tcp 58.61.153.xx:80 221.10.155.32:1301 established tcp 58.61.153.xx:80 221.12.21.254:7599 established tcp 58.61.153.xx:80 221.133.226.186:27049 established tcp 58.61.153.xx:80 221.133.226.186:27050 established tcp 58.61.153.xx:80 221.133.226.186:27066 established tcp 58.61.153.xx:80 221.133.226.186:27067 established tcp 58.61.153.xx:80 221.136.68.185:20850 established tcp 58.61.153.xx:80 221.197.211.104:1081 established tcp 58.61.153.xx:80 221.200.87.168:53153 established tcp 58.61.153.xx:80 221.202.201.80:9501 established tcp 58.61.153.xx:80 221.205.86.64:4104 established tcp 58.61.153.xx:80 221.208.3.177:1401 established tcp 58.61.153.xx:80 221.216.186.122:56322 established tcp 58.61.153.xx:80 221.223.130.240:48220 established tcp 58.61.153.xx:80 221.224.2.124:3920 established tcp 58.61.153.xx:80 221.224.8.59:63018 established tcp 58.61.153.xx:80 221.229.88.34:2860 established tcp 58.61.153.xx:80 221.229.116.68:1709 established tcp 58.61.153.xx:80 221.230.96.221:11374 established tcp 58.61.153.xx:80 221.230.96.221:11376 established tcp 58.61.153.xx:80 221.230.120.138:2990 established tcp 58.61.153.xx:80 221.232.157.99:47256 established tcp 58.61.153.xx:80 221.232.157.99:47257 established tcp 58.61.153.xx:80 221.236.86.114:1828 established tcp 58.61.153.xx:80 221.236.86.114:1830 established tcp 58.61.153.xx:80 221.239.73.43:4647 established tcp 58.61.153.xx:80 222.22.13.152:1081 established tcp 58.61.153.xx:80 222.38.52.70:4509 established tcp 58.61.153.xx:80 222.43.53.250:1400 established tcp 58.61.153.xx:80 222.44.44.143:17486 established tcp 58.61.153.xx:80 222.45.95.51:2543 established tcp 58.61.153.xx:80 222.46.42.244:10733 established tcp 58.61.153.xx:80 222.64.53.139:30187 established ...大量相似 tcp 58.61.153.xx:80 222.66.102.82:1461 established tcp 58.61.153.xx:80 222.66.226.10:11475 established tcp 58.61.153.xx:80 222.68.181.210:29303 established tcp 58.61.153.xx:80 222.68.181.210:31382 established tcp 58.61.153.xx:80 222.72.139.8:33380 established tcp 58.61.153.xx:80 222.72.248.106:12553 established tcp 58.61.153.xx:80 222.76.31.111:47891 established tcp 58.61.153.xx:80 222.76.31.111:47892 established tcp 58.61.153.xx:80 222.78.200.64:4767 established tcp 58.61.153.xx:80 222.89.91.1:22179 established tcp 58.61.153.xx:80 222.92.128.121:3134 established tcp 58.61.153.xx:80 222.92.212.133:48152 established tcp 58.61.153.xx:80 222.92.212.230:1329 established tcp 58.61.153.xx:80 222.93.79.75:6039 established tcp 58.61.153.xx:80 222.125.65.113:1600 established tcp 58.61.153.xx:80 222.125.65.113:1601 established tcp 58.61.153.xx:80 222.130.243.45:33986 established tcp 58.61.153.xx:80 222.130.243.45:33987 established tcp 58.61.153.xx:80 222.131.35.87:4717 established |
|
|
|
|