日期:2014-05-16  浏览次数:21082 次

大神求助:服务器疑是被攻击,netstat命令看到连接有很多国外IP

使用命令netstat -aop | grep 62013 > ~/netstat-aop-62013.log文件

文件内容如下:

tcp        0      0 *:62013                     *:*                         LISTEN      14530/ssh           off (0.00/0/0)
tcp        0      0 ::ffff:192.168.10.21:62013  43.148.51.119.adsl-po:18121 ESTABLISHED 14530/ssh           off (0.00/0/0)
tcp        0      0 ::ffff:192.168.10.21:62013  104.47.48.119.adsl-po:12595 ESTABLISHED 14530/ssh           off (0.00/0/0)
tcp        0      0 ::ffff:192.168.10.21:62013  3.168.17.175.adsl-poo:51707 ESTABLISHED 14530/ssh           off (0.00/0/0)
tcp        0      0 ::ffff:192.168.10.21:62013  142.45.48.119.adsl-po:38611 ESTABLISHED 14530/ssh           off (0.00/0/0)
tcp        0      0 ::ffff:192.168.10.21:62013  238.165.17.175.adsl-p:55066 FIN_WAIT2   14530/ssh           off (0.00/0/0)
tcp        0      0 ::ffff:192.168.10.21:62013  142.45.48.119.adsl-po:11475 ESTABLISHED 14530/ssh           off (0.00/0/0)
tcp        0      0 ::ffff:192.168.10.21:62013  94.47.48.119.adsl-poo:13057 FIN_WAIT2   14530/ssh           off (0.00/0/0)
tcp        0      0 ::ffff:192.168.10.21:62013  94.47.48.119.adsl-poo:13058 FIN_WAIT2   14530/ssh           off (0.00/0/0)
tcp        0      0 ::ffff:192.168.10.21:62013  142.45.48.119.adsl-po:29648 ESTABLISHED 14530/ssh           off (0.00/0/0)