主机部署在腾讯云上,使用lamp 部署oneinstack之后 查看 Apache_log 记录时发现大量异常连接请求
类似于
1.160.42.190 - - [08/Mar/2017:08:27:43 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1.160.42.190 - - [08/Mar/2017:08:28:14 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1.160.42.190 - - [08/Mar/2017:08:28:49 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1.160.42.190 - - [08/Mar/2017:08:38:56 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1.160.42.190 - - [08/Mar/2017:08:39:35 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1.160.42.190 - - [08/Mar/2017:08:39:59 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1.160.42.190 - - [08/Mar/2017:08:40:50 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
189.253.192.123 - - [08/Mar/2017:08:42:26 +0800] "GET / HTTP/1.0" 200 10546
1.160.42.190 - - [08/Mar/2017:08:46:30 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
类似于
1.160.42.190 - - [08/Mar/2017:08:27:43 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1.160.42.190 - - [08/Mar/2017:08:28:14 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1.160.42.190 - - [08/Mar/2017:08:28:49 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1.160.42.190 - - [08/Mar/2017:08:38:56 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1.160.42.190 - - [08/Mar/2017:08:39:35 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1.160.42.190 - - [08/Mar/2017:08:39:59 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1.160.42.190 - - [08/Mar/2017:08:40:50 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
189.253.192.123 - - [08/Mar/2017:08:42:26 +0800] "GET / HTTP/1.0" 200 10546
1.160.42.190 - - [08/Mar/2017:08:46:30 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
107.151.148.193 - - [08/Mar/2017:08:23:07 +0800] "GET http://www.sbjudge2.com/azenv.php HTTP/1.1" 404 2175
107.151.148.193 - - [08/Mar/2017:08:23:07 +0800] "CONNECT http://www.alipay.com:443 HTTP/1.1" 200 10546
107.151.148.193 - - [08/Mar/2017:08:23:07 +0800] "\x80\x9b\x01\x03\x01" 400 226
请问如何处理
3 Answers
这应该就是“网络嗅探”了,虽然屏蔽了ip,但是嗅探仍然继续,以域名的方式。
1-160-42-190.dynamic.hinet.net - - [08/Mar/2017:15:17:30 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1-160-42-190.dynamic.hinet.net - - [08/Mar/2017:15:17:59 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
esp-148-193.adhesivetalk.com - - [08/Mar/2017:15:19:29 +0800] "GET http://proxyjudge.us/ HTTP/1.1" 200 10546
esp-148-193.adhesivetalk.com - - [08/Mar/2017:15:19:30 +0800] "CONNECT http://www.alipay.com:443 HTTP/1.1" 200 10546
esp-148-193.adhesivetalk.com - - [08/Mar/2017:15:19:31 +0800] "\x80\x9b\x01\x03\x01" 400 226
5.178.86.74 - - [08/Mar/2017:15:20:45 +0800] "CONNECT check.best-proxies.ru:80 HTTP/1.1" 400 226
1-160-42-190.dynamic.hinet.net - - [08/Mar/2017:15:25:02 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
23.251.63.45 - - [08/Mar/2017:15:34:39 +0800] "GET http://fr.cyberpods.net/ HTTP/1.1" 200 10546
23.251.63.45 - - [08/Mar/2017:15:34:42 +0800] "CONNECT http://www.alipay.com:443 HTTP/1.1" 200 10546
23.251.63.45 - - [08/Mar/2017:15:34:42 +0800] "\x80\x98\x01\x03\x01" 400 226
1-160-42-190.dynamic.hinet.net - - [08/Mar/2017:15:36:20 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1-160-42-190.dynamic.hinet.net - - [08/Mar/2017:15:36:38 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1-160-42-190.dynamic.hinet.net - - [08/Mar/2017:15:17:30 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1-160-42-190.dynamic.hinet.net - - [08/Mar/2017:15:17:59 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
esp-148-193.adhesivetalk.com - - [08/Mar/2017:15:19:29 +0800] "GET http://proxyjudge.us/ HTTP/1.1" 200 10546
esp-148-193.adhesivetalk.com - - [08/Mar/2017:15:19:30 +0800] "CONNECT http://www.alipay.com:443 HTTP/1.1" 200 10546
esp-148-193.adhesivetalk.com - - [08/Mar/2017:15:19:31 +0800] "\x80\x9b\x01\x03\x01" 400 226
5.178.86.74 - - [08/Mar/2017:15:20:45 +0800] "CONNECT check.best-proxies.ru:80 HTTP/1.1" 400 226
1-160-42-190.dynamic.hinet.net - - [08/Mar/2017:15:25:02 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
23.251.63.45 - - [08/Mar/2017:15:34:39 +0800] "GET http://fr.cyberpods.net/ HTTP/1.1" 200 10546
23.251.63.45 - - [08/Mar/2017:15:34:42 +0800] "CONNECT http://www.alipay.com:443 HTTP/1.1" 200 10546
23.251.63.45 - - [08/Mar/2017:15:34:42 +0800] "\x80\x98\x01\x03\x01" 400 226
1-160-42-190.dynamic.hinet.net - - [08/Mar/2017:15:36:20 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
1-160-42-190.dynamic.hinet.net - - [08/Mar/2017:15:36:38 +0800] "CONNECT mx-tw.mail.gm0.yahoodns.net:25 HTTP/1.0" 200 10546
Please login or Register to submit your answer