代理的系统日志爆满,是否被攻击了,是什么攻击?
代理的系统日志爆满,是否被攻击了,是什么攻击?
OS:Redhat Linux 9
iptables做NAT
/var/message系统日志如下
- Apr 29 04:11:23 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=219.133.49.172 DST=*.*.*.* LEN=92 TOS=0x00 PREC=0x00 TTL=55 ID=0 DF PROTO=UDP SPT=8000 DPT=4002 LEN=72
- Apr 29 04:11:23 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=218.202.218.16 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=58428 DF PROTO=TCP SPT=55772 DPT=18493 WINDOW=64240 RES=0x00 SYN URGP=0
- Apr 29 04:11:23 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=218.62.90.118 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=114 ID=42647 DF PROTO=TCP SPT=53726 DPT=18493 WINDOW=16384 RES=0x00 SYN URGP=0
- Apr 29 04:11:23 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=61.128.167.26 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=53 ID=6141 DF PROTO=TCP SPT=2828 DPT=8968 WINDOW=14600 RES=0x00 SYN URGP=0
- Apr 29 04:11:23 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=61.50.141.194 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=51 ID=62667 DF PROTO=TCP SPT=40660 DPT=18493 WINDOW=8192 RES=0x00 SYN URGP=0
- Apr 29 04:11:24 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=61.50.141.194 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=51 ID=62713 DF PROTO=TCP SPT=40661 DPT=18493 WINDOW=8192 RES=0x00 SYN URGP=0
- Apr 29 04:11:24 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=61.128.167.26 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=53 ID=6196 DF PROTO=TCP SPT=2828 DPT=8968 WINDOW=14600 RES=0x00 SYN URGP=0
- Apr 29 04:11:25 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=61.144.99.93 DST=*.*.*.* LEN=56 TOS=0x00 PREC=0x00 TTL=54 ID=16663 PROTO=ICMP TYPE=3 CODE=3 [SRC=*.*.*.* DST=61.144.99.93 LEN=48 TOS=0x00 PREC=0x00 TTL=118 ID=41931 DF PROTO=TCP INCOMPLETE [8 bytes] ]
- Apr 29 04:11:25 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=61.128.167.26 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=53 ID=6235 DF PROTO=TCP SPT=2828 DPT=8968 WINDOW=14600 RES=0x00 SYN URGP=0
- Apr 29 04:11:26 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=61.50.141.194 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=51 ID=62853 DF PROTO=TCP SPT=40661 DPT=18493 WINDOW=8192 RES=0x00 SYN URGP=0
- Apr 29 04:11:26 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=61.144.99.93 DST=*.*.*.* LEN=56 TOS=0x00 PREC=0x00 TTL=54 ID=16679 PROTO=ICMP TYPE=3 CODE=3 [SRC=*.*.*.* DST=61.144.99.93 LEN=48 TOS=0x00 PREC=0x00 TTL=118 ID=41972 DF PROTO=TCP INCOMPLETE [8 bytes] ]
- Apr 29 04:11:26 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=220.133.80.206 DST=*.*.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=110 ID=24276 DF PROTO=TCP SPT=17174 DPT=4133 WINDOW=17280 RES=0x00 ACK FIN URGP=0
- Apr 29 04:11:26 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=220.133.80.206 DST=*.*.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=110 ID=24363 DF PROTO=TCP SPT=17174 DPT=4170 WINDOW=17280 RES=0x00 ACK FIN URGP=0
- Apr 29 04:11:27 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=61.144.99.93 DST=*.*.*.* LEN=56 TOS=0x00 PREC=0x00 TTL=54 ID=16706 PROTO=ICMP TYPE=3 CODE=3 [SRC=*.*.*.* DST=61.144.99.93 LEN=48 TOS=0x00 PREC=0x00 TTL=118 ID=42032 DF PROTO=TCP INCOMPLETE [8 bytes] ]
- Apr 29 04:11:27 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=64.180.0.77 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=107 ID=8760 DF PROTO=TCP SPT=4021 DPT=18493 WINDOW=65535 RES=0x00 SYN URGP=0
- Apr 29 04:11:28 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=221.238.147.13 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=17118 DF PROTO=TCP SPT=9719 DPT=18493 WINDOW=65535 RES=0x00 SYN URGP=0
- Apr 29 04:11:29 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=221.238.147.13 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=17179 DF PROTO=TCP SPT=9719 DPT=18493 WINDOW=65535 RES=0x00 SYN URGP=0
- Apr 29 04:11:30 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=218.202.218.16 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=62918 DF PROTO=TCP SPT=55772 DPT=18493 WINDOW=64240 RES=0x00 SYN URGP=0
- Apr 29 04:11:30 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=221.238.147.13 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=17228 DF PROTO=TCP SPT=9719 DPT=18493 WINDOW=65535 RES=0x00 SYN URGP=0
- Apr 29 04:11:30 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=68.120.130.14 DST=*.*.*.* LEN=64 TOS=0x00 PREC=0x00 TTL=48 ID=7110 PROTO=TCP SPT=3000 DPT=18493 WINDOW=8192 RES=0x00 SYN URGP=0
- Apr 29 04:12:33 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=218.83.37.202 DST=*.*.*.* LEN=64 TOS=0x00 PREC=0x00 TTL=54 ID=63355 DF PROTO=TCP SPT=2653 DPT=18493 WINDOW=65535 RES=0x00 SYN URGP=0
- Apr 29 04:12:33 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=69.86.143.225 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=104 ID=62297 DF PROTO=TCP SPT=3183 DPT=18493 WINDOW=65535 RES=0x00 SYN URGP=0
- Apr 29 04:12:33 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=222.216.16.196 DST=*.*.*.* LEN=56 TOS=0x00 PREC=0x00 TTL=55 ID=19903 PROTO=ICMP TYPE=3 CODE=3 [SRC=*.*.*.* DST=222.216.16.196 LEN=48 TOS=0x00 PREC=0x00 TTL=118 ID=43776 DF PROTO=TCP INCOMPLETE [8 bytes] ]
- Apr 29 04:12:33 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=24.86.121.123 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=114 ID=59796 DF PROTO=TCP SPT=3409 DPT=18493 WINDOW=64240 RES=0x00 SYN URGP=0
- Apr 29 04:12:33 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=163.17.14.5 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=102 ID=59516 DF PROTO=TCP SPT=3396 DPT=18493 WINDOW=64240 RES=0x00 SYN URGP=0
- Apr 29 04:12:33 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=221.227.37.82 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=4795 DF PROTO=TCP SPT=2962 DPT=18493 WINDOW=65535 RES=0x00 SYN URGP=0
- Apr 29 04:12:33 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=83.199.173.200 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=110 ID=8686 DF PROTO=TCP SPT=4759 DPT=18493 WINDOW=16384 RES=0x00 SYN URGP=0
- Apr 29 04:12:33 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=222.216.16.196 DST=*.*.*.* LEN=56 TOS=0x00 PREC=0x00 TTL=55 ID=19909 PROTO=ICMP TYPE=3 CODE=3 [SRC=*.*.*.* DST=222.216.16.196 LEN=48 TOS=0x00 PREC=0x00 TTL=118 ID=43852 DF PROTO=TCP INCOMPLETE [8 bytes] ]
- Apr 29 04:12:34 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=222.216.16.196 DST=*.*.*.* LEN=56 TOS=0x00 PREC=0x00 TTL=55 ID=19915 PROTO=ICMP TYPE=3 CODE=3 [SRC=*.*.*.* DST=222.216.16.196 LEN=48 TOS=0x00 PREC=0x00 TTL=118 ID=43915 DF PROTO=TCP INCOMPLETE [8 bytes] ]
- Apr 29 04:12:35 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=221.227.37.82 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=5065 DF PROTO=TCP SPT=2962 DPT=18493 WINDOW=65535 RES=0x00 SYN URGP=0
- Apr 29 04:12:35 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=84.9.128.176 DST=*.*.*.* LEN=52 TOS=0x00 PREC=0x00 TTL=44 ID=39468 DF PROTO=TCP SPT=2922 DPT=18493 WINDOW=64240 RES=0x00 SYN URGP=0
- Apr 29 04:12:46 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=222.76.67.99 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=51 ID=54582 PROTO=TCP SPT=2115 DPT=18493 WINDOW=8192 RES=0x00 SYN URGP=0
- Apr 29 04:12:46 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=80.6.223.202 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=103 ID=64924 DF PROTO=TCP SPT=64160 DPT=8968 WINDOW=65535 RES=0x00 SYN URGP=0
- Apr 29 04:12:47 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=203.125.207.194 DST=*.*.*.* LEN=56 TOS=0x00 PREC=0x00 TTL=45 ID=29794 PROTO=ICMP TYPE=3 CODE=3 [SRC=*.*.*.* DST=203.125.207.194 LEN=48 TOS=0x00 PREC=0x00 TTL=114 ID=44372 DF PROTO=TCP INCOMPLETE [8 bytes] ]
- Apr 29 04:12:48 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=219.71.92.186 DST=*.*.*.* LEN=52 TOS=0x00 PREC=0x00 TTL=45 ID=13391 DF PROTO=TCP SPT=2947 DPT=18493 WINDOW=64240 RES=0x00 SYN URGP=0
- Apr 29 04:12:49 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=218.24.219.156 DST=*.*.*.* LEN=56 TOS=0x00 PREC=0x00 TTL=53 ID=1330 PROTO=ICMP TYPE=3 CODE=3 [SRC=*.*.*.* DST=218.24.219.156 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=44437 DF PROTO=TCP INCOMPLETE [8 bytes] ]
- Apr 29 04:12:50 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=218.24.219.156 DST=*.*.*.* LEN=56 TOS=0x00 PREC=0x00 TTL=53 ID=1332 PROTO=ICMP TYPE=3 CODE=3 [SRC=*.*.*.* DST=218.24.219.156 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=44477 DF PROTO=TCP INCOMPLETE [8 bytes] ]
- Apr 29 04:12:51 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=84.9.128.176 DST=*.*.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=44 ID=40628 PROTO=TCP SPT=20000 DPT=4719 WINDOW=0 RES=0x00 ACK RST URGP=0
- Apr 29 04:12:51 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=218.24.219.156 DST=*.*.*.* LEN=56 TOS=0x00 PREC=0x00 TTL=53 ID=1342 PROTO=ICMP TYPE=3 CODE=3 [SRC=*.*.*.* DST=218.24.219.156 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=44517 DF PROTO=TCP INCOMPLETE [8 bytes] ]
- Apr 29 04:12:52 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=218.28.13.242 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=54843 DF PROTO=TCP SPT=2780 DPT=8968 WINDOW=64240 RES=0x00 SYN URGP=0
- Apr 29 04:12:52 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=218.68.246.98 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=4203 DF PROTO=TCP SPT=3945 DPT=18493 WINDOW=64800 RES=0x00 SYN URGP=0
- Apr 29 04:12:53 Gateway kernel: IN=eth0 OUT= MAC=00:13:20:1b:d5:9b:00:90:1a:40:2a:90:08:00 SRC=218.28.13.242 DST=*.*.*.* LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=55648 DF PROTO=TCP SPT=2780 DPT=8968 WINDOW=64240 RES=0x00 SYN URGP=0
复制代码
是否成了肉鸡,被人黑了。请前辈帮忙看看,先行谢过!
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
我遇到跟你一样的问题,我估计不是你说中毒了,你把IPTABLES 重启一下就好了,具体原因还在检查当中