หุ หุ ผมว่าคงไม่เกี่ยวกับ เคสนี้นะ แต่เพิ่งโดนด้วยตัวเองไปสดๆ
จาก 2 ที่นี้ 202.8.87.195 และ 202.8.85.180 วิ่งเข้ามาเหมือนจะ DoS
ที่ apache เครื่องนึงของเรา ติดต่อ proen ให้ช่วยดูให้แล้ว
นี่แค่ติ๊ดเดียวนะครับ
tcp 0 0 x.y.z.181:80 202.8.87.195:4411 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1340 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4924 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4668 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1341 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4669 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4925 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1342 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4926 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4670 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1343 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4671 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4927 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4544 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4800 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1472 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1216 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4545 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4801 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1217 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1473 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4546 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1474 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1218 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4803 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4547 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1219 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1475 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4548 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4804 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1476 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1220 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4549 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4805 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1477 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4806 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4550 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1478 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1222 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4551 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1223 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1479 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4552 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1480 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1224 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4553 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1225 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1481 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4554 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1482 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1226 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4555 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1227 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1483 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4556 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1484 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1228 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4557 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1229 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1485 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4814 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4558 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1486 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1230 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4559 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1231 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1487 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1488 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1232 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4560 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1233 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1489 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4561 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1490 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1234 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4562 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1235 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4563 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1236 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4564 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4820 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1237 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4565 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4821 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1238 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4822 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4566 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1239 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4823 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4567 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1240 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4568 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4824 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1241 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4569 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4825 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1242 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4826 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4570 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1243 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4827 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4571 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1244 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4572 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4828 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1245 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4573 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4829 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1246 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4830 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4574 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1247 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4831 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4575 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4576 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1248 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4577 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4833 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1249 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4834 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4578 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1250 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4835 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4579 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1251 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4580 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4836 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1252 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4581 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4837 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1253 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4838 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4582 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1254 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4839 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4583 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1255 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4584 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4840 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1256 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4585 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1257 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4842 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4586 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4843 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4587 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1259 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4588 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:4844 TIME_WAIT
tcp 0 0 x.y.z.181:80 202.8.87.195:1260 TIME_WAIT
ดูโหลดจากรูป