瀏覽單個文章
shinnlu
Advance Member
 

加入日期: Jan 2003
文章: 334
apache 遭到不明連線攻擊

前幾天主機掛掉重裝,結果重裝之後就遇到一堆不明連線攻擊,就好像被 ddos 一樣,來自世界各地的 ip 都有,擋也擋不完

115.159.45.101 - - [05/Mar/2015:11:06:17 +0800] "CONNECT 113.106.100.126:806 HTTP/1.1" 405 234 "-" "-"
61.147.96.238 - - [05/Mar/2015:11:06:17 +0800] "CONNECT 14.17.109.152:802 HTTP/1.0" 405 234 "-" "-"
115.29.128.237 - - [05/Mar/2015:11:06:18 +0800] "GET http://www.baidu.com/s?wd=" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; SE 2.X MetaSr 1.0)"
5.79.162.226 - - [05/Mar/2015:11:06:18 +0800] "GET http://check2.zennolab.com/proxy.php HTTP/1.1" 404 207 "RefererString" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:24.0) Gecko/20100101 Firefox/24.0"
59.175.227.254 - - [05/Mar/2015:11:06:19 +0800] "POST http://b2c.csair.com/B2C40/modules/...electDirect.jsp HTTP/1.1" 404 248 "http://b2c.csair.com" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
112.26.64.61 - - [05/Mar/2015:11:06:19 +0800] "GET http://www.douyutv.com/live_specifi..._info?fromuid=6 HTTP/1.1" 404 230 "http://www.douyutv.com/live_specific/get_room_show_info?fromuid=640" "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)"
115.29.128.228 - - [05/Mar/2015:11:06:20 +0800] "GET http://www.baidu.com/s?wd=h" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; SE 2.X MetaSr 1.0)"

首先排除網站裡面的程式被篡改,因為我把全部的檔案移除,也是有同樣的問題
我有用 ProxyRequest On,因為要把某個路徑導到內部伺服器,但就算關掉也是一樣

好像我家的主機被當成跳板一樣,有什麼方法可以擋掉這些莫名的連線呢?
     
      
舊 2015-03-05, 11:07 AM #1
回應時引用此文章
shinnlu離線中