問:收到說信息說我的服務(wù)器有對外攻擊請幫檢查下。我檢查沒有發(fā)現(xiàn)異常,收到說信息說我的服務(wù)器有對外攻擊請幫檢查下
答:您好,是我司發(fā)送給您的嗎,您可以把您收到的對外攻擊的信息提供下,并提供下正確遠(yuǎn)程密碼,如需我司協(xié)助排查,會扣除一次金牌服務(wù),您也可以重新提交正確工單類型:【云服務(wù)器】–【系統(tǒng)設(shè)置】–【服務(wù)器負(fù)載高/意外重啟/帶寬跑高/異?,F(xiàn)象排查】非常感謝您長期對我司的支持!
問:您好: 我司收到投訴 127.0.0.1 服務(wù)器對外攻擊網(wǎng)絡(luò)。服務(wù)器可能被黑,請全面查殺病毒或重裝系統(tǒng)處理。請盡快處理以確保服務(wù)器數(shù)據(jù)安全性,如再次收到對外攻擊投訴將關(guān)停服務(wù)器,請立即檢查處理下,謝謝!投訴詳情附后。
電話:郵箱:網(wǎng)址:bingfeng168.cn
郵件事務(wù) / MAIL-6465TCP port 1433 from IP 127.0.0.1
Attention!TCP port 1433 (MS SQL) activity is from IP 127.0.0.1. The scan was on ASBR of at 14:54:34 GMT. More than 60 IP have been in 60 seconds. See the log below.This may mean that the host 127.0.0.1 (or a host a NAT with IP 127.0.0.1) is compromised.Please take and check the for or this to of the IP 127.0.0.1.This was automatically and sent to abuse E-Mail based on WHOIS information.Here is the log (timestamps are GMT):
14:51:39: 127.0.0.1 => 127.0.0.1:1433
14:51:41: 127.0.0.1 => 127.0.0.1:1433
14:51:42: 127.0.0.1 => 127.0.0.1:1433
14:51:42: 127.0.0.1 => 127.0.0.1:1433
14:51:49: 127.0.0.1 => 127.0.0.1:1433
14:51:49: 127.0.0.1 => 127.0.0.1:1433
14:51:50: 127.0.0.1 => 127.0.0.1:1433
14:51:50: 127.0.0.1 => 127.0.0.1:1433
14:51:50: 127.0.0.1 => 127.0.0.1:1433
14:51:50: 127.0.0.1 => 127.0.0.1:1433
14:51:50: 127.0.0.1 => 127.0.0.1:1433
14:51:52: 127.0.0.1 => 127.0.0.1:1433
14:51:52: 127.0.0.1 => 127.0.0.1:1433
14:51:53: 127.0.0.1 => 127.0.0.1:1433
14:51:53: 127.0.0.1 => 127.0.0.1:1433
14:51:56: 127.0.0.1 => 127.0.0.1:1433
14:51:56: 127.0.0.1 => 127.0.0.1:1433
14:51:59: 127.0.0.1 => 127.0.0.1:1433
14:51:59: 127.0.0.1 => 127.0.0.1:1433
14:51:59: 127.0.0.1 => 127.0.0.1:1433
14:52:00: 127.0.0.1 => 127.0.0.1:1433
14:52:01: 127.0.0.1 => 127.0.0.1:1433
14:52:02: 127.0.0.1 => 127.0.0.1:1433
14:52:02: 127.0.0.1 => 127.0.0.1:1433
14:52:02: 127.0.0.1 => 127.0.0.1:1433
14:52:02: 127.0.0.1 => 127.0.0.1:1433
14:52:03: 127.0.0.1 => 127.0.0.1:1433
14:52:05: 127.0.0.1 => 127.0.0.1:1433
14:52:05: 127.0.0.1 => 127.0.0.1:1433
14:52:05: 127.0.0.1 => 127.0.0.1:1433
14:52:05: 127.0.0.1 => 127.0.0.1:1433
14:52:08: 127.0.0.1 => 127.0.0.1:1433
14:52:08: 127.0.0.1 => 127.0.0.1:1433
14:52:09: 127.0.0.1 => 127.0.0.1:1433
14:52:09: 127.0.0.1 => 127.0.0.1:1433
14:52:09: 127.0.0.1 => 127.0.0.1:1433
14:52:10: 127.0.0.1 => 127.0.0.1:1433
14:52:10: 127.0.0.1 => 127.0.0.1:1433
14:52:10: 127.0.0.1 => 127.0.0.1:1433
14:52:13: 127.0.0.1 => 127.0.0.1:1433
14:52:13: 127.0.0.1 => 127.0.0.1:1433
14:52:13: 127.0.0.1 => 127.0.0.1:1433
14:52:14: 127.0.0.1 => 127.0.0.1:1433
14:52:14: 127.0.0.1 => 127.0.0.1:1433
14:52:14: 127.0.0.1 => 127.0.0.1:1433
14:52:15: 127.0.0.1 => 127.0.0.1:1433
14:52:15: 127.0.0.1 => 127.0.0.1:1433
14:52:16: 127.0.0.1 => 127.0.0.1:1433
14:52:17: 127.0.0.1 => 127.0.0.1:1433
14:52:17: 127.0.0.1 => 127.0.0.1:1433
14:52:18: 127.0.0.1 => 127.0.0.1:1433
14:52:18: 127.0.0.1 => 127.0.0.1:1433
14:52:18: 127.0.0.1 => 127.0.0.1:1433
14:52:20: 127.0.0.1 => 127.0.0.1:1433
14:52:20: 127.0.0.1 => 127.0.0.1:1433
14:52:20: 127.0.0.1 => 127.0.0.1:1433
14:52:22: 127.0.0.1 => 127.0.0.1:1433
14:52:23: 127.0.0.1 => 127.0.0.1:1433
14:52:24: 127.0.0.1 => 127.0.0.1:1433
14:52:24: 127.0.0.1 => 127.0.0.1:1433
14:52:24: 127.0.0.1 => 127.0.0.1:1433
14:52:26: 127.0.0.1 => 127.0.0.1:1433
14:52:27: 127.0.0.1 => 127.0.0.1:1433
14:52:28: 127.0.0.1 => 127.0.0.1:1433
14:52:28: 127.0.0.1 => 127.0.0.1:1433
14:52:28: 127.0.0.1 => 127.0.0.1:1433
14:52:28: 127.0.0.1 => 127.0.0.1:1433
14:52:30: 127.0.0.1 => 127.0.0.1:1433
14:52:31: 127.0.0.1 => 127.0.0.1:1433
14:52:33: 127.0.0.1 => 127.0.0.1:1433
14:52:36: 127.0.0.1 => 127.0.0.1:1433
14:52:37: 127.0.0.1 => 127.0.0.1:1433
[Created via e-mail from: NETIS <scanreport@netis.ru>]添加評論
問:服務(wù)器密碼
答:您好,查看是有攻擊的,這邊無法核實(shí)哪些是異常進(jìn)程,您可以下載一個(gè)服務(wù)器安全狗或者云鎖掃描下是否存在木馬文件,如無法掃描出來,建議只有備份好需要的數(shù)據(jù)重裝下系統(tǒng),非常感謝您長期對我司的支持!
問:能否幫我操作下呢 劃掉一次金牌服務(wù)的資格
答:您好,抱歉,經(jīng)分析排查無法找到發(fā)包應(yīng)用,建議您重裝系統(tǒng) ,非常感謝您長期對我司的支持!
問:您好,現(xiàn)在我這個(gè)ip 無法的打開了嗎
答:您好,查看到服務(wù)器仍沒有重裝,當(dāng)前查看到服務(wù)器卡死,可能是服務(wù)器死機(jī)。
問:正在重裝
答:您好,重裝后參考http://bingfeng168.cn/faq/list.asp?unid=853 進(jìn)行安全設(shè)置,同時(shí)安裝安全軟件掃描服務(wù)器。
掃描完成后進(jìn)行恢復(fù)操作http://bingfeng168.cn/faq/list.asp?unid=608 。非常感謝您長期對我司的支持!
西部數(shù)碼(west.cn)是經(jīng)工信部、ICANN、CNNIC認(rèn)證審批,持有ISP、云牌照、IDC、CDN、頂級域名注冊商等全業(yè)務(wù)資質(zhì)的正規(guī)老牌服務(wù)商,自成立至今20余年專注于域名注冊、虛擬主機(jī)、云服務(wù)器、企業(yè)郵箱、企業(yè)建站等互聯(lián)網(wǎng)基礎(chǔ)服務(wù)!
截止目前,已經(jīng)為超過2000萬個(gè)域名提供了注冊、解析等服務(wù),是中國五星級域名注冊注冊商!已為超過50萬個(gè)網(wǎng)站提供了高速穩(wěn)定的云托管服務(wù),獲評中國最受用戶喜歡云主機(jī)服務(wù)商。
西部數(shù)碼提供全方位7X24H專業(yè)售后支撐,域名注冊特價(jià)1元起,高速穩(wěn)定云主機(jī)45元起,更多詳情請瀏覽西部數(shù)碼官網(wǎng):http://bingfeng168.cn/