通过分析日志,发现大部分 ip 都是不同的,但是有一个 ip 从有日志记录开始一直请求短信 我用 nmap 扫描了一下
Not shown: 828 filtered ports, 164 closed ports PORT STATE SERVICE VERSION 900/tcp open omginitialrefs? 1723/tcp open pptp? |_pptp-version: ERROR: Script execution failed (use -d to debug) 12174/tcp open ssh OpenSSH 6.6.1 (protocol 2.0) | ssh-hostkey: | 2048 xxxxx(RSA) |_ 256 xxxx(ECDSA) 16018/tcp open ms-wbt-server Microsoft Terminal Service 18040/tcp open ssh OpenSSH 6.6.1 (protocol 2.0) | ssh-hostkey: | 2048 xxxx (RSA) |_ 256 xxx (ECDSA) 19315/tcp open ms-wbt-server Microsoft Terminal Service 20031/tcp open ms-wbt-server Microsoft Terminal Service 54045/tcp open unknown Service Info: OS: Windows