当前位置: 技术问答>linux和unix
大神求助:服务器疑是被攻击,netstat命令看到连接有很多国外IP
来源: 互联网 发布时间:2017-04-17
本文导语: 使用命令netstat -aop | grep 62013 > ~/netstat-aop-62013.log文件 文件内容如下: tcp 0 0 *:62013 *:* LISTEN 14530/ssh off (0.00/0/...
使用命令netstat -aop | grep 62013 > ~/netstat-aop-62013.log文件
文件内容如下:
tcp 0 0 *:62013 *:* LISTEN 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 43.148.51.119.adsl-po:18121 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 104.47.48.119.adsl-po:12595 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 3.168.17.175.adsl-poo:51707 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:38611 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 238.165.17.175.adsl-p:55066 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:11475 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:13057 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:13058 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:29648 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 3.168.17.175.adsl-poo:55286 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 22.47.48.119.adsl-poo:22853 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:37340 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 146.171.17.175.adsl-p:34406 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 22.47.48.119.adsl-pool:5184 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 65.44.48.119.adsl-poo:16660 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:13577 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 14.47.48.119.adsl-poo:24665 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 165.166.17.175.adsl-p:20569 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 146.171.17.175.adsl-p:vstat ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 55.168.17.175.adsl-po:22980 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 246.171.17.17:gxs-data-port ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 165.166.17.175.adsl-p:16965 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-pool:dwf ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-po:12459 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 146.171.17.175.adsl-p:61054 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:13072 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 54.169.17.175.adsl-po:21214 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:32451 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 219.170.17.175.adsl-p:17715 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:13074 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 65.44.48.119.ads:lm-sserver ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 3.168.17.175.adsl-poo:55271 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 165.166.17.175.adsl-p:57166 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 104.47.48.119.adsl-po:29480 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 54.169.17.175.adsl-po:22224 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 246.171.17.175.adsl-p:11284 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 43.148.51.119.adsl-po:30423 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 165.166.17.175.a:tarantella ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 104.47.48.119.adsl-poo:6189 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 146.171.17.175.adsl-p:61042 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-po:11160 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 65.44.48.119.adsl-pool:9784 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 165.166.17.175.adsl-p:51319 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:13093 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 22.47.48.119.adsl-poo:18029 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-po:11676 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-poo:6812 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 51.168.17.175.:bex-webadmin ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-po:18333 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 ::ffff:124.235.120.15:53609 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-po:18334 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 165.166.17.175.adsl-p:39280 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 130.167.17.175.adsl-p:11353 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 246.171.17.175.adsl-po:6945 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 51.168.17.175.adsl-poo:6119 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:28414 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 246.171.17.175.adsl-po:7712 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 51.168.17.175.adsl-poo:6118 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-po:11153 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 22.47.48.119.adsl-poo:18789 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 51.168.17.175.adsl-poo:6117 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 104.47.48.119.adsl-po:10520 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-po:16530 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 22.47.48.119.adsl-poo:18016 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:40955 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 43.148.51.119.adsl-po:61924 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 22.47.48.119.adsl-pool.:cbt ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 104.47.48.119.ad:trellisagt ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 246.171.17.175.adsl-p:10553 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 104.47.48.119.adsl-poo:8706 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:10036 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 146.171.17.175.:tw-auth-key ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:47077 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:12848 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 14.47.48.119.adsl-poo:19040 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 65.44.48.119.adsl-pool:9773 ESTABLISHED
其中头几个IP都是国外的,而此服务器是给国内特定用户使用的.
不知道这种情况是属于被攻击中还是正常现象???
由于长度限制只贴出了前几行的网络连接信息,
62013端口的连接文本有93KB大小, 774行(连接)
请大神解释.
|
如果是给内网,就在iptables上面做规则,允许内网网段