aidevs
V2EX  ›  问与答

在公司服务上发现木马,服务器开启了日志,记录到了入侵者的 IP,怎么请他喝茶?

  •  
  •   aidevs · Jan 3, 2015 · 5491 views
    This topic created in 4147 days ago, the information mentioned may be changed or developed.
    详细访问日志:



    12-31 11:01:45 POST /.m/static/img/static.aspx - 80 - 113.76.193.74 Baiduspider 200 0 64 82586
    12-31 11:01:45 POST /.m/static/img/static.aspx - 80 - 113.76.193.74 Baiduspider 200 0 64 51870
    12-31 11:01:45 POST /.m/static/img/static.aspx - 80 - 113.76.193.74 Baiduspider 200 0 0 9781


    12-31 12:03:29 POST /.m/static/img/static.aspx - 80 - 113.76.193.74 Baiduspider 200 0 0 62
    12-31 12:03:30 POST /.m/static/img/static.aspx - 80 - 113.76.193.74 Baiduspider 200 0 0 62
    12-31 12:03:32 POST /.m/static/img/static.aspx - 80 - 113.76.193.74 Baiduspider 200 0 0 62

    12-31 14:07:05 POST /.m/static/img/static.aspx - 80 - 219.135.67.177 Baiduspider 200 0 0 78
    12-31 14:07:08 POST /.m/static/img/static.aspx - 80 - 219.135.67.177 Baiduspider 200 0 0 46


    12-31 23:02:36 POST /.m/static/img/static.aspx - 80 - 14.125.36.190 Baiduspider 200 0 0 1918
    12-31 23:03:01 POST /.m/static/img/static.aspx - 80 - 14.125.36.190 Baiduspider 200 0 0 93
    12-31 23:03:05 POST /.m/static/img/static.aspx - 80 - 14.125.36.190 Baiduspider 200 0 0 62
    12-31 23:03:07 POST /.m/static/img/static.aspx - 80 - 14.125.36.190 Baiduspider 200 0 0 78
    12-31 23:03:10 POST /.m/static/img/static.aspx - 80 - 14.125.36.190 Baiduspider 200 0 0 109

    12-31 23:08:06 POST /.m/static/img/static.aspx - 80 - 14.125.36.190 Baiduspider 200 0 0 109
    12-31 23:08:08 POST /.m/static/img/static.aspx - 80 - 14.125.36.190 Baiduspider 200 0 0 62
    12-31 23:08:11 POST /.m/static/img/static.aspx - 80 - 14.125.36.190 Baiduspider 200 0 0 78
    12-31 23:08:13 POST /.m/static/img/static.aspx - 80 - 14.125.36.190 Baiduspider 200 0 0 78
    12-31 23:08:15 POST /.m/static/img/static.aspx - 80 - 14.125.36.190 Baiduspider 200 0 0 93

    12-31 23:25:14 POST /.m/static/img/static.aspx - 80 - 14.125.36.190 Baiduspider 200 0 0 78
    12-31 23:25:17 POST /.m/static/img/static.aspx - 80 - 14.125.36.190 Baiduspider 200 0 0 78
    12-31 23:25:19 POST /.m/static/img/static.aspx - 80 - 14.125.36.190 Baiduspider 200 0 0 468




    01-02 00:47:59 POST /.m/static/img/static.aspx - 80 - 113.76.129.248 Baiduspider 200 0 64 58858
    01-02 00:48:00 POST /.m/static/img/static.aspx - 80 - 113.76.129.248 Baiduspider 200 0 0 18002

    01-02 01:05:11 POST /.m/static/img/static.aspx - 80 - 113.76.129.248 Baiduspider 200 0 0 62
    01-02 01:05:14 POST /.m/static/img/static.aspx - 80 - 113.76.129.248 Baiduspider 200 0 0 62
    01-02 01:05:17 POST /.m/static/img/static.aspx - 80 - 113.76.129.248 Baiduspider 200 0 0 62
    01-02 01:05:24 POST /.m/static/img/static.aspx - 80 - 113.76.129.248 Baiduspider 200 0 0 5101
    01-02 01:05:27 POST /.m/static/img/static.aspx - 80 - 113.76.129.248 Baiduspider 200 0 0 62
    01-02 01:05:29 POST /.m/static/img/static.aspx - 80 - 113.76.129.248 Baiduspider 200 0 0 62
    01-02 01:05:34 POST /.m/static/img/static.aspx - 80 - 113.76.129.248 Baiduspider 200 0 0 78
    01-02 01:05:44 POST /.m/static/img/static.aspx - 80 - 113.76.129.248 Baiduspider 200 0 0 62

    01-02 03:12:41 POST /.m/static/img/static.aspx - 80 - 113.76.129.248 Baiduspider 200 0 0 3213
    01-02 03:12:32 POST /.m/static/img/static.aspx - 80 - 113.76.129.248 Baiduspider 200 0 0 218





    01-02 23:57:35 POST /aspnet_client/system_web/client/env.aspx - 80 - 14.123.240.85 Baiduspider 200 0 0 717
    01-02 23:56:16 POST /.m/static/img/static.aspx - 80 - 14.123.240.85 Baiduspider 404 0 64 23446

    01-03 00:03:01 POST /aspnet_client/system_web/client/env.aspx - 80 - 14.123.240.85 Baiduspider 200 0 0 6427
    01-03 00:03:26 POST /aspnet_client/system_web/client/env.aspx - 80 - 14.123.240.85 Baiduspider 200 0 0 2854
    01-03 00:38:42 POST /aspnet_client/system_web/client/env.aspx - 80 - 14.123.240.85 Baiduspider 200 0 0 1294
    01-03 00:38:44 POST /aspnet_client/system_web/client/env.aspx - 80 - 14.123.240.85 Baiduspider 200 0 0 202
    01-03 00:38:46 POST /aspnet_client/system_web/client/env.aspx - 80 - 14.123.240.85 Baiduspider 200 0 0
    Supplement 1  ·  Jan 3, 2015
    这些文件 之前服务器上是没有的,
    我已经确认是入侵者上传的木马
    20 replies    2015-01-04 21:46:16 +08:00
    pfitseng
        1
    pfitseng  
       Jan 3, 2015
    评估损失,去当地公安局报案
    mahone3297
        2
    mahone3297  
       Jan 3, 2015
    不懂,请教下。。。
    都是 Baiduspider ,是入侵者?
    tabris17
        3
    tabris17  
       Jan 3, 2015
    好,把李彦宏抓起来
    halczy
        5
    halczy  
       Jan 3, 2015
    非常眼熟...

    目测以上两个IP都是广州电信家庭拨号拿到的动态IP. 找公安问电信.
    sanddudu
        6
    sanddudu  
       Jan 3, 2015
    @mahone3297 UA 是可以伪造的,普通的爬虫进行这些访问很可疑
    wzzyj8
        7
    wzzyj8  
       Jan 3, 2015
    @mahone3297
    @tabris17

    应该是伪装成spider穿过WAF吧
    aidevs
        8
    aidevs  
    OP
       Jan 3, 2015
    @mahone3297
    @tabris17

    可以伪造 user-agent
    flynaj
        9
    flynaj  
       Jan 3, 2015 via Android
    Baiduspider说明对方是伪装过的了,ip很有可能也是代理的ip
    aidevs
        10
    aidevs  
    OP
       Jan 3, 2015
    @flynaj 额,有可能
    9hills
        11
    9hills  
       Jan 3, 2015 via iPhone
    建议自身做好安全措施,报警无用。除非你是12306
    sneezry
        12
    sneezry  
       Jan 3, 2015
    @mahone3297
    @tabris17
    spider肿么会发送POST请求
    chone
        13
    chone  
       Jan 3, 2015 via iPhone
    记录到ip应该是跳板,先处理好漏洞吧。
    longear
        14
    longear  
       Jan 3, 2015
    这些黑产贩子才不会傻到用自己的IP等着查水表呢, 都是用肉鸡间接入侵,还不知道用了几跳呢。
    你要举报多半是给无辜受害者找麻烦。
    fising
        15
    fising  
       Jan 3, 2015 via iPad
    警察会管你这些破事儿
    mahone3297
        16
    mahone3297  
       Jan 3, 2015
    @sanddudu
    @dbfox
    我知道,ua是可以伪造的。。。
    我是想说,如何看出这是入侵者。。。
    lz作为服务器管理员,可能可以看出,这些文件,是不存在的,是后来有人上传的,是木马。
    我们,今天看帖子的人,如何看出这是入侵?post请求吗?
    lvye
        17
    lvye  
       Jan 4, 2015 via iPhone
    @mahone3297 img目录下放可执行脚本 而且还取掩人耳目的名字
    ksupertu
        18
    ksupertu  
       Jan 4, 2015
    1、网上110报警平台;
    2、装个安全狗扫一遍网马
    gpg
        19
    gpg  
       Jan 4, 2015
    报警无用。除非你是12306
    abanx
        20
    abanx  
       Jan 4, 2015
    这黑客怎么也不清理log?
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   4687 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 195ms · UTC 04:04 · PVG 12:04 · LAX 21:04 · JFK 00:04
    ♥ Do have faith in what you're doing.