-
Üyelik
05.01.2014
-
Yaş/Cinsiyet
44 / E
-
Meslek
doktor
-
Konum
İstanbul Anadolu
-
Ad Soyad
M** E**
-
Mesajlar
738
-
Beğeniler
3 / 107
-
Ticaret
2, (%50)
Sunucuma büyük boyutlu bir saldırı olduğundan şüpheleniyorum.
Bunu SSh panelden nasıl anlayabilirim
O an sunucuya bağlı olan aktif ip adreslerini
netstat -ntu komutu ile mi görebiliyorum.
Burada hangi ipden geldiğini nasıl anlayabilirim.
Sunucuya o an kaç bağlantı olduğunu nasıl anlarım
Son Haberler www.haberdetaylari.com
xFeyz
creative solutions
Kullanıcı
-
Üyelik
05.02.2014
-
Yaş/Cinsiyet
28 / E
-
Meslek
developer
-
Konum
Bursa
-
Ad Soyad
F** Ö**
-
Mesajlar
704
-
Beğeniler
195 / 222
-
Ticaret
8, (%100)
access_log'ları kontrol ettiniz mi? isterseniz ilk önce oraya bakın.
EFSANE! | omerbeyoglu.me
-
Üyelik
05.01.2014
-
Yaş/Cinsiyet
44 / E
-
Meslek
doktor
-
Konum
İstanbul Anadolu
-
Ad Soyad
M** E**
-
Mesajlar
738
-
Beğeniler
3 / 107
-
Ticaret
2, (%50)
ESTABLISHED
tcp 0 0 188.40.89.199:47533 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47637 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 85.107.185.0:48261 ESTABLISHED
tcp 0 0 188.40.89.199:47630 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47550 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47529 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:80 141.101.104.49:52398 ESTABLISHED
tcp 0 0 188.40.89.199:47512 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.49:63457 ESTABLISHED
tcp 0 0 188.40.89.199:47604 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47505 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47555 188.40.89.199:7080 TIME_WAIT
tcp 0 0 188.40.89.199:80 141.101.104.253:41205 TIME_WAIT
tcp 0 0 188.40.89.199:47631 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 108.162.246.186:48787 TIME_WAIT
tcp 0 0 188.40.89.199:80 162.158.210.128:40727 TIME_WAIT
tcp 0 0 188.40.89.199:80 141.101.104.240:39670 TIME_WAIT
tcp 0 0 188.40.89.199:47449 188.40.89.199:7080 TIME_WAIT
tcp 0 0 188.40.89.199:47638 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47581 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47633 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47609 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:80 81.213.42.161:55366 FIN_WAIT2
tcp 0 0 188.40.89.199:47580 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47597 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.49:34075 ESTABLISHED
tcp 0 0 188.40.89.199:47535 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 162.158.90.99:50933 ESTABLISHED
tcp 0 0 188.40.89.199:47587 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47636 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 108.162.246.186:17878 ESTABLISHED
tcp 0 0 188.40.89.199:80 162.158.95.204:40569 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.144:57941 ESTABLISHED
tcp 0 0 188.40.89.199:47561 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.196:33842 ESTABLISHED
tcp 0 0 188.40.89.199:80 176.219.152.50:29619 ESTABLISHED
tcp 0 0 188.40.89.199:47538 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:80 141.101.104.49:60620 ESTABLISHED
tcp 0 0 188.40.89.199:47511 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47553 188.40.89.199:7080 TIME_WAIT
tcp 0 0 188.40.89.199:80 162.158.211.126:43143 ESTABLISHED
tcp 0 0 188.40.89.199:80 162.158.210.124:31360 ESTABLISHED
tcp 0 0 188.40.89.199:47578 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47504 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47610 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.143:18188 ESTABLISHED
tcp 0 0 188.40.89.199:47567 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47647 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 162.158.210.124:29443 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.49:18253 TIME_WAIT
tcp 0 0 188.40.89.199:47411 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.52:25100 ESTABLISHED
tcp 0 0 188.40.89.199:47591 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.105.73:60804 ESTABLISHED
tcp 0 0 188.40.89.199:80 108.162.246.186:24204 TIME_WAIT
tcp 0 0 188.40.89.199:80 141.101.104.143:50402 ESTABLISHED
tcp 0 0 188.40.89.199:80 81.213.42.161:55428 FIN_WAIT2
tcp 0 0 188.40.89.199:47603 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47606 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 81.213.42.161:55751 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.105.26:34762 ESTABLISHED
tcp 0 1 188.40.89.199:80 188.58.207.118:63691 FIN_WAIT1
tcp 0 0 188.40.89.199:80 141.101.80.99:22736 TIME_WAIT
tcp 0 0 188.40.89.199:47324 188.40.89.199:7080 TIME_WAIT
tcp 0 0 188.40.89.199:80 141.101.105.23:54267 ESTABLISHED
tcp 0 0 188.40.89.199:80 81.213.42.161:55778 FIN_WAIT2
tcp 0 0 188.40.89.199:80 108.162.229.23:25785 TIME_WAIT
tcp 0 0 188.40.89.199:47622 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47536 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.144:57257 ESTABLISHED
tcp 0 0 188.40.89.199:47574 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.97:13384 ESTABLISHED
tcp 0 0 188.40.89.199:47557 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:80 141.101.104.144:15332 ESTABLISHED
tcp 0 0 188.40.89.199:47607 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:80 141.101.105.14:53374 ESTABLISHED
tcp 0 0 188.40.89.199:80 108.162.246.186:39528 ESTABLISHED
tcp 0 0 188.40.89.199:80 66.249.74.107:61428 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.253:27918 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.188:32213 TIME_WAIT
tcp 0 0 188.40.89.199:47521 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47525 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47634 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.196:30441 ESTABLISHED
tcp 0 0 188.40.89.199:47531 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47582 188.40.89.199:7080 ESTABLISHED
tcp 248 0 188.40.89.199:80 5.24.146.89:60776 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.102:64649 TIME_WAIT
tcp 0 0 188.40.89.199:80 66.249.74.107:62046 TIME_WAIT
tcp 0 0 188.40.89.199:47626 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.206:31746 ESTABLISHED
tcp 0 0 188.40.89.199:47579 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47625 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:80 81.213.42.161:55617 ESTABLISHED
tcp 0 0 188.40.89.199:47612 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47576 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47572 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47596 188.40.89.199:7080 TIME_WAIT
tcp 0 0 188.40.89.199:47583 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:80 141.101.104.250:60365 ESTABLISHED
tcp 0 0 188.40.89.199:47585 188.40.89.199:7080 ESTABLISHED
tcp 0 8048 188.40.89.199:22 94.123.232.79:51442 ESTABLISHED
tcp 0 0 188.40.89.199:80 162.158.211.126:31943 ESTABLISHED
tcp 0 0 188.40.89.199:80 162.158.94.181:29692 TIME_WAIT
tcp 0 0 188.40.89.199:47643 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.234:46830 ESTABLISHED
tcp 0 0 188.40.89.199:47648 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47618 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47532 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47385 188.40.89.199:7080 TIME_WAIT
tcp 0 0 188.40.89.199:47651 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 108.162.246.186:57166 ESTABLISHED
tcp 0 0 188.40.89.199:47632 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47559 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47444 188.40.89.199:7080 TIME_WAIT
tcp 0 0 188.40.89.199:47599 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47534 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47540 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:80 141.101.104.52:48340 ESTABLISHED
tcp 0 0 188.40.89.199:47590 188.40.89.199:7080 TIME_WAIT
tcp 0 0 188.40.89.199:80 173.245.55.114:49263 ESTABLISHED
tcp 0 0 188.40.89.199:47588 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47351 188.40.89.199:7080 TIME_WAIT
tcp 0 0 188.40.89.199:47575 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47552 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.143:57021 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.105.73:36803 ESTABLISHED
tcp 0 0 188.40.89.199:47620 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:80 108.162.246.186:50012 ESTABLISHED
tcp 0 0 188.40.89.199:47530 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:80 141.101.104.97:55851 ESTABLISHED
tcp 0 0 188.40.89.199:47611 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47616 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.175:29946 ESTABLISHED
tcp 0 0 188.40.89.199:47506 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:80 5.24.146.89:54930 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.250:34813 ESTABLISHED
tcp 0 0 188.40.89.199:80 66.249.74.111:61210 ESTABLISHED
tcp 0 0 188.40.89.199:47605 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.97:50477 TIME_WAIT
tcp 0 0 188.40.89.199:80 178.240.203.60:8749 ESTABLISHED
tcp 0 0 188.40.89.199:47539 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47619 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:80 162.158.211.127:37674 ESTABLISHED
tcp 0 0 188.40.89.199:47639 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47566 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47507 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.141:40935 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.104.104:36500 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.105.24:15113 ESTABLISHED
tcp 0 0 188.40.89.199:80 162.158.211.127:44458 ESTABLISHED
tcp 0 0 188.40.89.199:80 162.158.210.123:28814 ESTABLISHED
tcp 0 0 188.40.89.199:47649 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 81.213.42.161:55427 FIN_WAIT2
tcp 0 0 188.40.89.199:47621 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:47515 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 141.101.105.67:64477 TIME_WAIT
tcp 0 0 188.40.89.199:47592 188.40.89.199:7080 ESTABLISHED
tcp 0 0 188.40.89.199:80 162.158.94.182:15699 ESTABLISHED
tcp 0 0 188.40.89.199:47635 188.40.89.199:7080 TIME_WAIT
tcp 0 0 188.40.89.199:80 141.101.105.74:16193 ESTABLISHED
Ek Olarak: kendi ip adresim kendi ip adresime bağlantı mı veriyor nasıl bir saçmalık. 188.40.89.199 bu sunucu ip
Son Haberler www.haberdetaylari.com
xFeyz
creative solutions
Kullanıcı
-
Üyelik
05.02.2014
-
Yaş/Cinsiyet
28 / E
-
Meslek
developer
-
Konum
Bursa
-
Ad Soyad
F** Ö**
-
Mesajlar
704
-
Beğeniler
195 / 222
-
Ticaret
8, (%100)
siteniz aşırı yavaş, sanırsam saldırı alıyorsunuz.
sunucunuzda donanımsal firewall mevcut değil mi? yanılmıyorsam, sunucu arıyorum konunuzda donanımsal firewall olması gerektiğini belirtmiştim.
donanımsal firewall mevcut ve siteniz bu haldeyse, firmanıza ulaşın.
eğer yoksa;
sunucunuzu bir tık olsa rahatlatmak amaçlı reboot komutu verin ilk önce.
ardından, sunucu açılır açılmaz o boşlukta yazılımsal firewall ile portları kontrol edin.
lakin, yazılımsal olarak gelen saldırılar bir kısma kadar bertaraf edilebilir.
şu anda detaylı incelemek / çözüm üretmek için vaktim yok, umarım forumda ilgilenebilecek durumda arkadaşlar vardır,
siz yine de en kısa zamanda -hatta şimdi- firmanıza ulaşın ve durumu bildirin.
EFSANE! | omerbeyoglu.me
-
Üyelik
05.01.2014
-
Yaş/Cinsiyet
44 / E
-
Meslek
doktor
-
Konum
İstanbul Anadolu
-
Ad Soyad
M** E**
-
Mesajlar
738
-
Beğeniler
3 / 107
-
Ticaret
2, (%50)
firewall csf kurdum ve kurtuldum galiba...
Son Haberler www.haberdetaylari.com
-
Üyelik
05.01.2014
-
Yaş/Cinsiyet
44 / E
-
Meslek
doktor
-
Konum
İstanbul Anadolu
-
Ad Soyad
M** E**
-
Mesajlar
738
-
Beğeniler
3 / 107
-
Ticaret
2, (%50)
ama hala kendi ip adresim arasındaki bağlantıları anlamadım örnek
tcp 0 0 188.40.89.199:47539 188.40.89.199:7080 FIN_WAIT2
tcp 0 0 188.40.89.199:47619 188.40.89.199:7080 FIN_WAIT2
Son Haberler www.haberdetaylari.com
-
Üyelik
30.08.2014
-
Yaş/Cinsiyet
34 / E
-
Meslek
bilgisayar mühendisi
-
Konum
İstanbul Avrupa
-
Ad Soyad
A** A**
-
Mesajlar
174
-
Beğeniler
3 / 31
-
Ticaret
15, (%93)
csf öneririm bir çok spamı engeller.