- 注册时间
- 2010-3-22
- 最后登录
- 2012-3-12
- 在线时间
- 36 小时
- 阅读权限
- 50
- 积分
- 627
- 帖子
- 10
- 主题
- 2
- 精华
- 0
- UID
- 7333

 - 签到
- 17
- 注册时间
- 2010-3-22
- 最后登录
- 2012-3-12
- 在线时间
- 36 小时
- 阅读权限
- 50
- 积分
- 627
- 帖子
- 10
- 主题
- 2
- 精华
- 0
- UID
- 7333
|
发表于 2011-7-27 11:13:37
|显示全部楼层
今天早上WEB服务器被攻击,造成系统负载突然上升,后台从而打开很慢,查看监控发现流量莫名上升,换衣被攻击,查看WEB日志发现有如下的这样的请求.......122.224.33.56 - - [27/Jul/2011:04:13:11 +0800] "GET /?gallery--n,%E9%AB%98%E7%BA%A7%E9%9D%B4%E5%AD%90%E6%94%AF%E6%92%91%E5%A4%B9;xie;%E7%9F%AD%E7%AD%92%E9%9D%B4%E6%92%91;xie;%E9%9D%B4%E5%A4%B9-grid.html HTTP/1.0" 200 12552 "http://www.bfbfbf.com/?gallery--n,%E5%86%85%E8%A1%A3%E5%B8%A6-grid.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
122.224.33.56 - - [27/Jul/2011:04:13:12 +0800] "GET /plugins/cron/cron.php?action=gallery%3Agrid&p= HTTP/1.0" 200 0 "http://www.bfbfbf.com/?gallery--n,%E9%AB%98%E7%BA%A7%E9%9D%B4%E5%AD%90%E6%94%AF%E6%92%91%E5%A4%B9;xie;%E7%9F%AD%E7%AD%92%E9%9D%B4%E6%92%91;xie;%E9%9D%B4%E5%A4%B9-grid.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
122.224.33.56 - - [27/Jul/2011:04:13:12 +0800] "GET /statics/btn-gocart.gif HTTP/1.0" 500 1818 "http://www.bfbfbf.com/?gallery--n,%E9%AB%98%E7%BA%A7%E9%9D%B4%E5%AD%90%E6%94%AF%E6%92%91%E5%A4%B9;xie;%E7%9F%AD%E7%AD%92%E9%9D%B4%E6%92%91;xie;%E9%9D%B4%E5%A4%B9-grid.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
122.224.33.56 - - [27/Jul/2011:04:13:12 +0800] "GET /index.php?action=gallery%3Agrid&p= HTTP/1.0" 500 2024 "http://www.bfbfbf.com/?gallery--n,%E9%AB%98%E7%BA%A7%E9%9D%B4%E5%AD%90%E6%94%AF%E6%92%91%E5%A4%B9;xie;%E7%9F%AD%E7%AD%92%E9%9D%B4%E6%92%91;xie;%E9%9D%B4%E5%A4%B9-grid.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
122.224.33.56 - - [27/Jul/2011:04:13:18 +0800] "POST /?cart-ajaxAdd.html HTTP/1.0" 200 0 "http://www.bfbfbf.com/?gallery--n,%E9%AB%98%E7%BA%A7%E9%9D%B4%E5%AD%90%E6%94%AF%E6%92%91%E5%A4%B9;xie;%E7%9F%AD%E7%AD%92%E9%9D%B4%E6%92%91;xie;%E9%9D%B4%E5%A4%B9-grid.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
觉得这个IP不正常,就用iptables封掉,发现封掉之后负载才下去......对安全这块不是很擅长,目前公司也没有安全工程师,想请教各位类似这样的攻击属于什么攻击,对于这种类型的攻击以后用方案防范......请各位大牛给小弟一些方法,谢谢。
|
|