以下是ftp的記錄日志:
最近一兩周都沒有使用過ftp根據,都ftp的記錄日志卻每天都在生成記錄,而且ftp的匿名登錄也都是關閉著的,如果是遭受到了攻擊的話,哪有什么辦法可以解決?
#Software: Microsoft Internet Information Services 7.0
#Version: 1.0
#Date: 2017-01-11 02:51:40
#Fields: time c-ip cs-method cs-uri-stem sc-status sc-win32-status
02:51:40 122.224.153.109 [39208]closed - 421 121
08:10:15 140.205.225.183 [39471]USER anonymous 331 0
08:10:15 140.205.225.183 [39471]PASS - 530 1326
08:10:15 140.205.225.183 [39471]USER anonymous 331 0
08:10:15 140.205.225.183 [39471]PASS admin 530 1326
08:10:15 140.205.225.183 [39471]USER anonymous 331 0
08:10:15 140.205.225.183 [39471]PASS 123456 530 1326
08:10:15 140.205.225.183 [39471]USER anonymous 331 0
08:10:15 140.205.225.183 [39471]PASS ftp 530 1326
08:10:15 140.205.225.183 [39471]USER anonymous 331 0
08:10:15 140.205.225.183 [39471]PASS test 530 1326
08:10:15 140.205.225.183 [39471]USER anonymous 331 0
08:10:15 140.205.225.183 [39471]PASS 1qazxsw2 530 1326
08:10:15 140.205.225.183 [39471]USER anonymous 331 0
08:10:15 140.205.225.183 [39471]PASS 123 530 1326
08:10:15 140.205.225.183 [39471]USER anonymous 331 0
08:10:15 140.205.225.183 [39471]PASS 12345678 530 1326
08:10:15 140.205.225.183 [39471]USER anonymous 331 0
08:10:15 140.205.225.183 [39471]PASS root 530 1326
08:10:15 140.205.225.183 [39471]USER ftp 331 0
08:10:15 140.205.225.183 [39471]PASS - 530 1326
08:10:15 140.205.225.183 [39471]USER ftp 331 0
08:10:15 140.205.225.183 [39471]PASS admin 530 1326
08:10:15 140.205.225.183 [39471]USER ftp 331 0
08:10:15 140.205.225.183 [39471]PASS 123456 530 1326
08:10:15 140.205.225.183 [39471]USER ftp 331 0
08:10:15 140.205.225.183 [39471]PASS ftp 530 1326
08:10:15 140.205.225.183 [39471]USER ftp 331 0
08:10:16 140.205.225.183 [39471]PASS test 530 1326
08:10:16 140.205.225.183 [39471]USER ftp 331 0
08:10:16 140.205.225.183 [39471]PASS 1qazxsw2 530 1326
08:10:16 140.205.225.183 [39471]USER ftp 331 0
08:10:16 140.205.225.183 [39471]PASS 123 530 1326
08:10:16 140.205.225.183 [39471]USER ftp 331 0
08:10:16 140.205.225.183 [39471]PASS 12345678 530 1326
08:10:16 140.205.225.183 [39471]USER ftp 331 0
08:10:16 140.205.225.183 [39471]PASS root 530 1326
08:10:16 140.205.225.183 [39471]USER test 331 0
08:10:16 140.205.225.183 [39471]PASS - 530 1326
08:10:16 140.205.225.183 [39471]USER test 331 0
08:10:16 140.205.225.183 [39471]PASS - 530 1326
08:10:16 140.205.225.183 [39471]USER test 331 0
08:10:16 140.205.225.183 [39471]PASS - 530 1326
08:10:16 140.205.225.183 [39471]USER test 331 0
08:10:16 140.205.225.183 [39471]PASS - 530 1326
08:10:16 140.205.225.183 [39471]USER test 331 0
08:10:16 140.205.225.183 [39471]PASS - 530 1326
08:10:16 140.205.225.183 [39471]USER test 331 0
08:10:16 140.205.225.183 [39471]PASS - 530 1326
08:10:16 140.205.225.183 [39471]USER test 331 0
08:10:16 140.205.225.183 [39471]PASS - 530 1326
08:10:16 140.205.225.183 [39471]USER test 331 0
08:10:16 140.205.225.183 [39471]PASS - 530 1326
08:10:17 140.205.225.183 [39471]USER test 331 0
08:10:17 140.205.225.183 [39471]PASS - 530 1326
08:10:17 140.205.225.183 [39471]USER admin 331 0
08:10:17 140.205.225.183 [39471]PASS - 530 1326
08:10:17 140.205.225.183 [39471]USER admin 331 0
08:10:17 140.205.225.183 [39471]PASS - 530 1326
08:10:17 140.205.225.183 [39471]USER admin 331 0
08:10:17 140.205.225.183 [39471]PASS - 530 1326
08:10:17 140.205.225.183 [39471]USER admin 331 0
08:10:17 140.205.225.183 [39471]PASS - 530 1326
08:10:17 140.205.225.183 [39471]USER admin 331 0
08:10:17 140.205.225.183 [39471]PASS - 530 1326
08:10:17 140.205.225.183 [39471]USER admin 331 0
08:10:17 140.205.225.183 [39471]PASS - 530 1326
08:10:17 140.205.225.183 [39471]USER admin 331 0
08:10:17 140.205.225.183 [39471]PASS - 530 1326
08:10:17 140.205.225.183 [39471]USER admin 331 0
08:10:17 140.205.225.183 [39471]PASS - 530 1326
08:10:17 140.205.225.183 [39471]USER admin 331 0
08:10:17 140.205.225.183 [39471]PASS - 530 1326
08:10:17 140.205.225.183 [39471]USER user 331 0
08:10:17 140.205.225.183 [39471]PASS - 530 1326
08:10:17 140.205.225.183 [39471]USER user 331 0
08:10:17 140.205.225.183 [39471]PASS - 530 1326
08:10:17 140.205.225.183 [39471]USER user 331 0
08:10:17 140.205.225.183 [39471]PASS - 530 1326
08:10:18 140.205.225.183 [39471]USER user 331 0
08:10:18 140.205.225.183 [39471]PASS - 530 1326
08:10:18 140.205.225.183 [39471]USER user 331 0
08:10:18 140.205.225.183 [39471]PASS - 530 1326
08:10:18 140.205.225.183 [39471]USER user 331 0
08:10:18 140.205.225.183 [39471]PASS - 530 1326
08:10:18 140.205.225.183 [39471]USER user 331 0
08:10:18 140.205.225.183 [39471]PASS - 530 1326
08:10:18 140.205.225.183 [39471]USER user 331 0
08:10:18 140.205.225.183 [39471]PASS - 530 1326
08:10:18 140.205.225.183 [39471]USER user 331 0
08:10:18 140.205.225.183 [39471]PASS - 530 1326
08:10:18 140.205.225.183 [39471]USER root 331 0
08:10:18 140.205.225.183 [39471]PASS - 530 1326
08:10:18 140.205.225.183 [39471]USER root 331 0
08:10:18 140.205.225.183 [39471]PASS - 530 1326
08:10:18 140.205.225.183 [39471]USER root 331 0
08:10:18 140.205.225.183 [39471]PASS - 530 1326
08:10:18 140.205.225.183 [39471]USER root 331 0
08:10:18 140.205.225.183 [39471]PASS - 530 1326
08:10:18 140.205.225.183 [39471]USER root 331 0
08:10:18 140.205.225.183 [39471]PASS - 530 1326
08:10:18 140.205.225.183 [39471]USER root 331 0
08:10:18 140.205.225.183 [39471]PASS - 530 1326
08:10:18 140.205.225.183 [39471]USER root 331 0
08:10:18 140.205.225.183 [39471]PASS - 530 1326
08:10:19 140.205.225.183 [39471]USER root 331 0
08:10:19 140.205.225.183 [39471]PASS - 530 1326
08:10:19 140.205.225.183 [39471]USER root 331 0
08:10:19 140.205.225.183 [39471]PASS - 530 1326
uj5u.com熱心網友回復:
是黑客入侵,用爆破,知道IP之后,把IP屏蔽掉就好了,但是你上面的IP好像是云盾在做安全檢測。看一下這個帖子
https://help.aliyun.com/knowledge_detail/37436.html
轉載請註明出處,本文鏈接:https://www.uj5u.com/caozuo/122010.html
標籤:安全技術/病毒
