全球主机交流论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

CeraNetworks网络延迟测速工具IP归属甄别会员请立即修改密码
查看: 1501|回复: 3

vps被停了,ramnode家的!

[复制链接]
发表于 2015-3-18 17:31:28 | 显示全部楼层 |阅读模式
之前发邮件,没开到,今天给停了,发了ticket,还没回复!
这个问题怎么解决!
  1. You appear to be running an open SNMP server at IP address 107.161.118.168 that participated in an attack against a customer of ours, generating large UDP responses to spoofed queries, with those responses becoming fragmented because of their size.

  2. Please consider reconfiguring your SNMP-speaking device in one or more of these ways:

  3. - Block queries made by unauthorized addresses. This can be done with an ACL or other firewall rule.
  4. - Use a different query string than "public" and which cannot be easily guessed by a 3rd party.
  5. - Disable SNMP entirely.

  6. If you are an ISP, please also look at your network configuration and make sure that you do not allow spoofed traffic (that pretends to be from external IP addresses) to leave the network. Hosts that allow spoofed traffic make possible this type of attack.

  7. Example SNMP responses sent to us by your device during the attack are given below.
  8. Date/timestamps (far left) are UTC.

  9. 2015-03-14 03:26:05.187035 IP (tos 0x0, ttl 56, id 0, offset 0, flags [DF], proto UDP (17), length 1305) 107.161.118.168.161 > 66.150.214.x.27015: UDP, length 1277
  10. 0x0000: 4500 0519 0000 4000 3811 a669 6ba1 12a6 E.....@.8..ik...
  11. 0x0010: 4296 d68d 00a1 6987 0505 d8a2 3082 04f9 B.....i.....0...
  12. 0x0020: 0201 0104 0670 7562 6c69 63a2 8204 ea02 .....public.....
  13. 0x0030: 047b 73cc 1302 0100 0201 0030 8204 da30 .{s........0...0
  14. 0x0040: 5606 082b 0601 0201 0101 0004 4a4c 696e V..+........JLin
  15. 0x0050: 7578 ux

  16. (The final octet of our customer's IP address is masked in the above output because some automatic parsers become confused when multiple IP addresses are included. The value of that octet is "141".)
复制代码


给我个解决办法,停止了snmp服务就可以了是吧!
 楼主| 发表于 2015-3-18 17:58:44 来自手机 | 显示全部楼层
谁遇到过,怎么会发攻击?求解决办法!
发表于 2015-3-18 18:03:19 | 显示全部楼层
是不是被抓肉鸡发DDOS了?
 楼主| 发表于 2015-3-18 19:06:53 来自手机 | 显示全部楼层
jianke 发表于 2015-3-18 18:03
是不是被抓肉鸡发DDOS了?

说什么snmp漏洞发包!
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|小黑屋|全球主机交流论坛

GMT+8, 2024-5-2 04:30 , Processed in 0.058858 second(s), 9 queries , Gzip On, MemCache On.

Powered by Discuz! X3.4

© 2001-2023 Discuz! Team.

快速回复 返回顶部 返回列表