問(wèn):收到說(shuō)信息說(shuō)我的服務(wù)器有對(duì)外攻擊請(qǐng)幫檢查下。我檢查沒(méi)有發(fā)現(xiàn)異常,收到說(shuō)信息說(shuō)我的服務(wù)器有對(duì)外攻擊請(qǐng)幫檢查下
答:您好,是我司發(fā)送給您的嗎,您可以把您收到的對(duì)外攻擊的信息提供下,并提供下正確遠(yuǎn)程密碼,如需我司協(xié)助排查,會(huì)扣除一次金牌服務(wù),您也可以重新提交正確工單類(lèi)型:【云服務(wù)器】–【系統(tǒng)設(shè)置】–【服務(wù)器負(fù)載高/意外重啟/帶寬跑高/異?,F(xiàn)象排查】非常感謝您長(zhǎng)期對(duì)我司的支持!
問(wèn):您好: 我司收到投訴 127.0.0.1 服務(wù)器對(duì)外攻擊網(wǎng)絡(luò)。服務(wù)器可能被黑,請(qǐng)全面查殺病毒或重裝系統(tǒng)處理。請(qǐng)盡快處理以確保服務(wù)器數(shù)據(jù)安全性,如再次收到對(duì)外攻擊投訴將關(guān)停服務(wù)器,請(qǐng)立即檢查處理下,謝謝!投訴詳情附后。
電話(huà):郵箱:網(wǎng)址:www.ps-sw.cn
郵件事務(wù) / MAIL-6465TCP port 1433 from IP 127.0.0.1
Attention!TCP port 1433 (MS SQL) activity is from IP 127.0.0.1. The scan was on ASBR of at 14:54:34 GMT. More than 60 IP have been in 60 seconds. See the log below.This may mean that the host 127.0.0.1 (or a host a NAT with IP 127.0.0.1) is compromised.Please take and check the for or this to of the IP 127.0.0.1.This was automatically and sent to abuse E-Mail based on WHOIS information.Here is the log (timestamps are GMT):
14:51:39: 127.0.0.1 => 127.0.0.1:1433
14:51:41: 127.0.0.1 => 127.0.0.1:1433
14:51:42: 127.0.0.1 => 127.0.0.1:1433
14:51:42: 127.0.0.1 => 127.0.0.1:1433
14:51:49: 127.0.0.1 => 127.0.0.1:1433
14:51:49: 127.0.0.1 => 127.0.0.1:1433
14:51:50: 127.0.0.1 => 127.0.0.1:1433
14:51:50: 127.0.0.1 => 127.0.0.1:1433
14:51:50: 127.0.0.1 => 127.0.0.1:1433
14:51:50: 127.0.0.1 => 127.0.0.1:1433
14:51:50: 127.0.0.1 => 127.0.0.1:1433
14:51:52: 127.0.0.1 => 127.0.0.1:1433
14:51:52: 127.0.0.1 => 127.0.0.1:1433
14:51:53: 127.0.0.1 => 127.0.0.1:1433
14:51:53: 127.0.0.1 => 127.0.0.1:1433
14:51:56: 127.0.0.1 => 127.0.0.1:1433
14:51:56: 127.0.0.1 => 127.0.0.1:1433
14:51:59: 127.0.0.1 => 127.0.0.1:1433
14:51:59: 127.0.0.1 => 127.0.0.1:1433
14:51:59: 127.0.0.1 => 127.0.0.1:1433
14:52:00: 127.0.0.1 => 127.0.0.1:1433
14:52:01: 127.0.0.1 => 127.0.0.1:1433
14:52:02: 127.0.0.1 => 127.0.0.1:1433
14:52:02: 127.0.0.1 => 127.0.0.1:1433
14:52:02: 127.0.0.1 => 127.0.0.1:1433
14:52:02: 127.0.0.1 => 127.0.0.1:1433
14:52:03: 127.0.0.1 => 127.0.0.1:1433
14:52:05: 127.0.0.1 => 127.0.0.1:1433
14:52:05: 127.0.0.1 => 127.0.0.1:1433
14:52:05: 127.0.0.1 => 127.0.0.1:1433
14:52:05: 127.0.0.1 => 127.0.0.1:1433
14:52:08: 127.0.0.1 => 127.0.0.1:1433
14:52:08: 127.0.0.1 => 127.0.0.1:1433
14:52:09: 127.0.0.1 => 127.0.0.1:1433
14:52:09: 127.0.0.1 => 127.0.0.1:1433
14:52:09: 127.0.0.1 => 127.0.0.1:1433
14:52:10: 127.0.0.1 => 127.0.0.1:1433
14:52:10: 127.0.0.1 => 127.0.0.1:1433
14:52:10: 127.0.0.1 => 127.0.0.1:1433
14:52:13: 127.0.0.1 => 127.0.0.1:1433
14:52:13: 127.0.0.1 => 127.0.0.1:1433
14:52:13: 127.0.0.1 => 127.0.0.1:1433
14:52:14: 127.0.0.1 => 127.0.0.1:1433
14:52:14: 127.0.0.1 => 127.0.0.1:1433
14:52:14: 127.0.0.1 => 127.0.0.1:1433
14:52:15: 127.0.0.1 => 127.0.0.1:1433
14:52:15: 127.0.0.1 => 127.0.0.1:1433
14:52:16: 127.0.0.1 => 127.0.0.1:1433
14:52:17: 127.0.0.1 => 127.0.0.1:1433
14:52:17: 127.0.0.1 => 127.0.0.1:1433
14:52:18: 127.0.0.1 => 127.0.0.1:1433
14:52:18: 127.0.0.1 => 127.0.0.1:1433
14:52:18: 127.0.0.1 => 127.0.0.1:1433
14:52:20: 127.0.0.1 => 127.0.0.1:1433
14:52:20: 127.0.0.1 => 127.0.0.1:1433
14:52:20: 127.0.0.1 => 127.0.0.1:1433
14:52:22: 127.0.0.1 => 127.0.0.1:1433
14:52:23: 127.0.0.1 => 127.0.0.1:1433
14:52:24: 127.0.0.1 => 127.0.0.1:1433
14:52:24: 127.0.0.1 => 127.0.0.1:1433
14:52:24: 127.0.0.1 => 127.0.0.1:1433
14:52:26: 127.0.0.1 => 127.0.0.1:1433
14:52:27: 127.0.0.1 => 127.0.0.1:1433
14:52:28: 127.0.0.1 => 127.0.0.1:1433
14:52:28: 127.0.0.1 => 127.0.0.1:1433
14:52:28: 127.0.0.1 => 127.0.0.1:1433
14:52:28: 127.0.0.1 => 127.0.0.1:1433
14:52:30: 127.0.0.1 => 127.0.0.1:1433
14:52:31: 127.0.0.1 => 127.0.0.1:1433
14:52:33: 127.0.0.1 => 127.0.0.1:1433
14:52:36: 127.0.0.1 => 127.0.0.1:1433
14:52:37: 127.0.0.1 => 127.0.0.1:1433
[Created via e-mail from: NETIS <scanreport@netis.ru>]添加評(píng)論
問(wèn):服務(wù)器密碼
答:您好,查看是有攻擊的,這邊無(wú)法核實(shí)哪些是異常進(jìn)程,您可以下載一個(gè)服務(wù)器安全狗或者云鎖掃描下是否存在木馬文件,如無(wú)法掃描出來(lái),建議只有備份好需要的數(shù)據(jù)重裝下系統(tǒng),非常感謝您長(zhǎng)期對(duì)我司的支持!
問(wèn):能否幫我操作下呢 劃掉一次金牌服務(wù)的資格
答:您好,抱歉,經(jīng)分析排查無(wú)法找到發(fā)包應(yīng)用,建議您重裝系統(tǒng) ,非常感謝您長(zhǎng)期對(duì)我司的支持!
問(wèn):您好,現(xiàn)在我這個(gè)ip 無(wú)法的打開(kāi)了嗎
答:您好,查看到服務(wù)器仍沒(méi)有重裝,當(dāng)前查看到服務(wù)器卡死,可能是服務(wù)器死機(jī)。
問(wèn):正在重裝
答:您好,重裝后參考http://www.ps-sw.cn/faq/list.asp?unid=853 進(jìn)行安全設(shè)置,同時(shí)安裝安全軟件掃描服務(wù)器。
掃描完成后進(jìn)行恢復(fù)操作http://www.ps-sw.cn/faq/list.asp?unid=608 。非常感謝您長(zhǎng)期對(duì)我司的支持!
西部數(shù)碼(west.cn)是經(jīng)工信部、ICANN、CNNIC認(rèn)證審批,持有ISP、云牌照、IDC、CDN、頂級(jí)域名注冊(cè)商等全業(yè)務(wù)資質(zhì)的正規(guī)老牌服務(wù)商,自成立至今20余年專(zhuān)注于域名注冊(cè)、虛擬主機(jī)、云服務(wù)器、企業(yè)郵箱、企業(yè)建站等互聯(lián)網(wǎng)基礎(chǔ)服務(wù)!
截止目前,已經(jīng)為超過(guò)2000萬(wàn)個(gè)域名提供了注冊(cè)、解析等服務(wù),是中國(guó)五星級(jí)域名注冊(cè)注冊(cè)商!已為超過(guò)50萬(wàn)個(gè)網(wǎng)站提供了高速穩(wěn)定的云托管服務(wù),獲評(píng)中國(guó)最受用戶(hù)喜歡云主機(jī)服務(wù)商。
西部數(shù)碼提供全方位7X24H專(zhuān)業(yè)售后支撐,域名注冊(cè)特價(jià)1元起,高速穩(wěn)定云主機(jī)45元起,更多詳情請(qǐng)瀏覽西部數(shù)碼官網(wǎng):http://www.ps-sw.cn/