全球主机交流论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

CeraNetworks网络延迟测速工具IP归属甄别会员请立即修改密码
查看: 2247|回复: 17

[美国VPS] 拜拜了 五毛机

[复制链接]
发表于 2020-9-6 06:50:20 | 显示全部楼层 |阅读模式
刚给我发的邮件 然后我就赶紧登上去看看 一看 被封了,好气 啥也没干 直接删了


По факту обнаружения вредоносной активности с вашего IP адреса, в соответствии пунктам  2.3 и 2.4 Приложения 1 к Договору публичной оферты ваш сервер будет остановлен и заблокирован.
Во избежание блокировки просим устранить указанные далее нарушения в течение суток.

Пожалуйста, ознакомьтесь с инцидентом:
Лог копировать сюда или ссылка на SBL
----
Kind regards,
Ruvds abuse team.
---- Пересылаемое сообщение от root@pluto.tectus.net (root) ---
Отправитель: root@pluto.tectus.net (root)
Получатель: support@ruvds.com
Тема: attacks from your network to my server
Дата: 05.09.2020 19:59:05 (Europe/Moscow)


Dear support/abuse/whatever team/or to whom it may concern,

I've been running this server (tectus.net / 85.183.147.115) a while now and I've
allways been tolerant to some script kiddies trying to breach into it using port
22 (ssh).

But after some time it began to anoy me and now I will report each of these
incidents to your distribution lists for further action.

Below is the jwhois output from the delinquent using the IP 45.143.94.92 at
2020-09-05 18:58:06 (GMT+1) from where I got your contact details:

--------------------------------------------------------------------------------
[Querying whois.arin.net]
[Redirected to whois.ripe.net]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
%       To receive output for a database update, use the "-B" flag.

% Information related to '45.143.94.0 - 45.143.94.255'

% Abuse contact for '45.143.94.0 - 45.143.94.255' is 'support@ruvds.com'

inetnum:        45.143.94.0 - 45.143.94.255
netname:        RU-RUVDS-20191211
country:        RU
org:            ORG-MFL16-RIPE
admin-c:        RVS268-RIPE
tech-c:         RVS268-RIPE
status:         ASSIGNED PA
mnt-by:         IP-RIPE
mnt-routes:     MNT-RETN
mnt-domains:    MNT-RETN
created:        2019-12-11T11:28:12Z
last-modified:  2019-12-11T11:28:32Z
source:         RIPE

organisation:   ORG-MFL16-RIPE
org-name:       MT FINANCE LLC
org-type:       OTHER
address:        Glinischevskiy per., 3, kom. 226
address:        125009 Moscow
address:        Russia
abuse-c:        RVS268-RIPE
mnt-ref:        IP-RIPE
mnt-by:         IP-RIPE
created:        2018-10-16T15:38:35Z
last-modified:  2018-10-16T15:39:37Z
source:         RIPE # Filtered

role:           RU VDS Support
address:        Glinischevskiy per., 3, kom. 226
address:        125009 Moscow
address:        Russia
abuse-mailbox:  support@ruvds.com
admin-c:        YB1456-RIPE
tech-c:         YB1456-RIPE
nic-hdl:        RVS268-RIPE
mnt-by:         IP-RIPE
created:        2018-10-16T15:38:36Z
last-modified:  2018-10-16T15:39:16Z
source:         RIPE # Filtered

% Information related to '45.143.94.0/24AS9002'

route:          45.143.94.0/24
descr:          RU-RUVDS
origin:         AS9002
mnt-by:         MNT-RETN
created:        2019-12-11T12:50:36Z
last-modified:  2019-12-11T12:50:36Z
source:         RIPE

% This query was served by the RIPE Database Query Service version 1.97.2
(HEREFORD)

--------------------------------------------------------------------------------


The reason why I'm sending you this mail, is the following /var/log/secure log
entry of my server:
--------------------------------------------------------------------------------
Sep 5 18:58:06 pluto sshd[22231]: Failed password for root from 45.143.94.92 port
40726 ssh2
--------------------------------------------------------------------------------


So could you please give the above mentioned user of your network a warning, block
the ip traffic to my server, or do whatever else is needed to stop me sending you
these messages.


Thanks
root@tectus.net

---- Конец пересылаемого сообщения ---
 楼主| 发表于 2020-9-6 06:58:38 | 显示全部楼层

一直用着还挺好 我用的也少 几天才用一次然后就给封了  真是搞不懂
发表于 2020-9-6 07:00:09 | 显示全部楼层
要真的是无辜的 pp争议解决把钱找回来吧
 楼主| 发表于 2020-9-6 07:07:48 | 显示全部楼层
shaoyedrl 发表于 2020-9-6 07:00
要真的是无辜的 pp争议解决把钱找回来吧

以后要是有三毛再买 余额先留着吧 反正用掉的钱 也用过机器了
发表于 2020-9-6 07:12:22 | 显示全部楼层
似乎你不是第一个
 楼主| 发表于 2020-9-6 07:33:00 | 显示全部楼层
wifitry 发表于 2020-9-6 07:12
似乎你不是第一个

是啥 真的是 也没看明白咋会儿 反正直接封了
发表于 2020-9-6 07:40:15 | 显示全部楼层
好像给你写原因了
 楼主| 发表于 2020-9-6 07:47:51 | 显示全部楼层
lylcyndi 发表于 2020-9-6 07:40
好像给你写原因了

是的 主要是没看懂  最主要的是 我特么啥都没干 上面就一个魔法
发表于 2020-9-6 07:51:13 来自手机 | 显示全部楼层
用的有一键脚本?vps用的默认密码?没修改ssh 22端口?
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|小黑屋|全球主机交流论坛

GMT+8, 2024-4-29 20:01 , Processed in 0.121034 second(s), 9 queries , Gzip On, MemCache On.

Powered by Discuz! X3.4

© 2001-2023 Discuz! Team.

快速回复 返回顶部 返回列表