惡意連線又一樁!

這個版面主要討論 debian 在 server 端的應用問題, server 種類繁多..舉凡 Web Server 、 File Server、 DHCP Server..等等。

版主: 阿信

惡意連線又一樁!

文章aeolustw » 週四 7月 30, 2009 8:07 am

應該只能偵對MS Server攻擊!

Linux Server 應該是無效??
74.208.16.39 - - [30/Jul/2009:03:45:58 +0800] "PUT /index.htm HTTP/1.0" 405 286 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:45:58 +0800] "PUT /index.html HTTP/1.0" 405 287 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:45:58 +0800] "PUT /welcome.htm HTTP/1.0" 405 288 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:45:59 +0800] "PUT /welcome.html HTTP/1.0" 405 289 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:45:59 +0800] "PUT /home.htm HTTP/1.0" 405 285 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:45:59 +0800] "PUT /home.html HTTP/1.0" 405 286 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:45:59 +0800] "PUT /index.aspx HTTP/1.0" 405 287 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:00 +0800] "PUT /defaut.aspx HTTP/1.0" 405 288 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:00 +0800] "PUT /home.aspx HTTP/1.0" 405 286 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:00 +0800] "PUT /default.htm HTTP/1.0" 405 288 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:00 +0800] "PUT /default.html HTTP/1.0" 405 289 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:00 +0800] "PUT /index.asp HTTP/1.0" 405 286 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:01 +0800] "PUT /main.htm HTTP/1.0" 405 285 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:01 +0800] "PUT /iisstart.asp HTTP/1.0" 405 289 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:01 +0800] "PUT /main.html HTTP/1.0" 405 286 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:01 +0800] "PUT /main.asp HTTP/1.0" 405 285 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:01 +0800] "PUT /main.aspx HTTP/1.0" 405 286 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:02 +0800] "PUT /default.asp HTTP/1.0" 405 288 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:02 +0800] "PUT /home.asp HTTP/1.0" 405 285 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:02 +0800] "PUT /index.php HTTP/1.0" 302 3 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:02 +0800] "PUT /default.php HTTP/1.0" 404 2299 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:03 +0800] "PUT /home.php HTTP/1.0" 404 2299 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:03 +0800] "PUT /iisstart.asp HTTP/1.0" 405 289 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:03 +0800] "PUT /localstart.asp HTTP/1.0" 405 291 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
74.208.16.39 - - [30/Jul/2009:03:46:03 +0800] "GET / HTTP/1.0" 302 3 "-" "-"
圖檔
個人網站
測試Linux Server+光世代
主站,購物,相簿...
頭像
aeolustw
可愛的小學生
可愛的小學生
 
文章: 78
註冊時間: 週六 11月 01, 2008 9:36 pm
來自: Taiwan

文章crack888wei » 週四 11月 19, 2009 3:26 pm

你是單機使用嗎?可以使用單機防火牆建議加入
#過慮蠕蟲病毒

#444/445/69/135/139

###-----------------------------------------------------------------###

iptables -A FORWARD -p tcp --dport 4444 -j DROP

iptables -A FORWARD -p udp --dport 4444 -j DROP

iptables -A FORWARD -p tcp --dport 445 -j DROP

iptables -A FORWARD -p udp --dport 445 -j DROP

iptables -A FORWARD -p tcp --dport 69 -j DROP

iptables -A FORWARD -p udp --dport 69 -j DROP

iptables -A FORWARD -p tcp --dport 135 -j DROP

iptables -A FORWARD -p udp --dport 135 -j DROP

iptables -A FORWARD -p tcp --dport 139 -j DROP

iptables -A FORWARD -p udp --dport 139 -j DROP
謙虛學習,小弟我也是新手回答不對的地方請各位前輩指導我一下謝謝^^
crack888wei
可愛的小學生
可愛的小學生
 
文章: 19
註冊時間: 週三 10月 07, 2009 9:47 am

文章aeolustw » 週五 11月 20, 2009 11:52 am

感恩,收下. ;-)
圖檔
個人網站
測試Linux Server+光世代
主站,購物,相簿...
頭像
aeolustw
可愛的小學生
可愛的小學生
 
文章: 78
註冊時間: 週六 11月 01, 2008 9:36 pm
來自: Taiwan


回到 debian server

誰在線上

正在瀏覽這個版面的使用者:沒有註冊會員 和 1 位訪客