日期:2014-05-17  浏览次数:20778 次

关于DDOS攻击,求解决方案
最近系统不太稳定,经过检查,发现是遭受DDOS攻击。先列出日志

环境如下:
windows server 2008、apache2.2

Java code

46.17.98.211 - - [11/Jun/2012:15:33:30 +0800] "GET http://www.eliteforo.com/forumdisplay.php?2-General&sort=title&order=desc HTTP/1.0" 200 49300
68.233.239.10 - - [11/Jun/2012:15:33:35 +0800] "CONNECT 218.219.71.179:25 HTTP/1.0" 403 218
94.228.203.175 - - [11/Jun/2012:15:33:29 +0800] "CONNECT ru.4game.com:443 HTTP/1.1" 200 -
196.218.255.86 - - [11/Jun/2012:15:33:35 +0800] "GET http://login.bjs.yahoo.com/config/pwtoken_get?login=gillyflower&src=ygodgw&passwd=246a715e36ed8fca9be9e2444d887586&challenge=gGL7qB72A1Z47GpC7ICGzkb5wmoj&md5=1 HTTP/1.0" 200 4
74.53.9.50 - - [11/Jun/2012:15:33:35 +0800] "GET http://www.worldlingo.com/en/products_services/worldlingo_translator.html HTTP/1.1" 200 6818
178.150.142.129 - - [11/Jun/2012:15:33:33 +0800] "POST http://www.trebesingerteufel.at/index.php?content=bookwrite HTTP/1.1" 200 19699
94.228.203.175 - - [11/Jun/2012:15:33:12 +0800] "CONNECT www.ea.com:443 HTTP/1.0" 200 -
46.17.98.211 - - [11/Jun/2012:15:33:34 +0800] "GET http://www.eliteoutlaws.net/smf/index.php?action=post;topic=2817.0;num_replies=2 HTTP/1.0" 200 254
220.168.97.24 - - [11/Jun/2012:15:33:36 +0800] "GET http://v3.stat.ku6.com/dostatv.do?method=setVideoPlayCount&o=14168027&c=107000&v=WgGCxZckGELdNM2GIZqaCg..&rnd=0.17257032496854663 HTTP/1.1" 200 172
203.93.208.66 - - [11/Jun/2012:15:33:33 +0800] "GET http://www.onlinedown.net/newhuagg/softdown_ggg_new.js HTTP/1.1" 200 1424
212.117.172.80 - - [11/Jun/2012:15:33:35 +0800] "POST http://212.117.172.80/proxy5/check.php HTTP/1.1" 200 500
74.73.7.221 - - [11/Jun/2012:15:33:37 +0800] "POST http://www.datpiff.com/xml/mixtapes.php HTTP/1.0" 503 323
62.76.43.241 - - [11/Jun/2012:15:33:34 +0800] "GET http://tune.yandex.ru/region/ HTTP/1.1" 200 18704
121.54.22.85 - - [11/Jun/2012:15:33:37 +0800] "GET /login.yahoo.com/config/login_unlock?login=sarah-b.rm:123 HTTP/1.0" 404 72
74.53.9.50 - - [11/Jun/2012:15:33:36 +0800] "POST http://www.worldlingo.com/wl/ajax//call/plaincall/__System.pageLoaded.dwr HTTP/1.1" 200 195
178.150.142.129 - - [11/Jun/2012:15:33:28 +0800] "POST http://singpatana.net/index.php?name=gbook&file=commit HTTP/1.1" 200 21495
178.150.142.129 - - [11/Jun/2012:15:33:34 +0800] "GET http://zgtcw.eb2m.com/news/view/6 HTTP/1.1" 200 1745
46.17.98.211 - - [11/Jun/2012:15:33:34 +0800] "GET http://www.eurobricks.com/forum/index.php?app=core&module=global&section=register HTTP/1.0" 200 15207
178.150.142.129 - - [11/Jun/2012:15:33:36 +0800] "GET http://ebisuno.com/cgi/faq/index.cgi?print+201206/120610000.txt HTTP/1.1" 200 4354
196.218.255.86 - - [11/Jun/2012:15:33:37 +0800] "GET http://login.bjs.yahoo.com/config/pwtoken_get?login=gilsonite&src=ygodgw&passwd=246a715e36ed8fca9be9e2444d887586&challenge=gGL7qB72A1Z47GpC7ICGzkb5wmoj&md5=1 HTTP/1.0" 200 4
72.44.197.252 - - [11/Jun/2012:15:33:37 +0800] "GET http://local.yahoo.com/results?stx=Drug+Stores&csz=Depew+NY&ycatfilt=96928176 HTTP/1.1" 302 81
109.169.76.10 - - [11/Jun/2012:15:33:33 +0800] "GET http://www.ongamepoker.com/games/handhistory/?sRoundReference=R5-247756712-1 HTTP/1.1" 200 532
178.65.156.181 - - [11/Jun/2012:15:33:35 +0800] "POST http://199.80.55.135/login.html HTTP/1.1" 200 11301
74.53.9.50 - - [11/Jun/2012:15:33:37 +0800] "POST http://www.worldlingo.com/wl/ajax//call/plaincall/ServiceApi.retrieveTranslation.dwr HTTP/1.1" 200 146
46.17.98.211 - - [11/Jun/2012:15:33:36 +0800] "GET http://www.fanofalex.com/phpBB/images/avatars/mp3-sasha-htm.html HTTP/1.0" 4