vps交流

堪萨斯滥用警告,这是啥???


是不是密码泄露被人拿去干坏事了??
我该咋解释?

69.30.232.1/32 has been nullrouted at this time for outbound SYN Floods. It is likely that your service has became compromised and requires your immediate attention. Please reply back to this ticket once you have this resolved.

Date first seen Duration Proto Src IP Addr Flows(%) Packets(%) Bytes(%) pps bps bpp
2022-08-15 18:20:00.029 299.893 any 69.30.232.1 4137(100.0) 33.9 M(100.0) 31.6 G(100.0) 113007 844.1 M 933

Date first seen Duration Proto Src IP Addr堪萨斯滥用警告,这是啥???ort Dst IP Addr堪萨斯滥用警告,这是啥???ort Flags Tos Packets Bytes Flows
2022-08-15 18:20:00.029 0.000 TCP 69.30.232.1:47390 -> 103.116.72.10:80 0x82 0 8192 7.7 M 1
2022-08-15 18:20:00.076 0.000 TCP 69.30.232.1:60834 -> 103.116.72.10:80 ….S. 0 8192 7.8 M 1
2022-08-15 18:20:00.150 0.000 TCP 69.30.232.1:44223 -> 103.116.72.10:80 0xc2 0 8192 7.5 M 1
2022-08-15 18:20:00.178 0.000 TCP 69.30.232.1:15974 -> 103.116.72.10:80 ….S. 0 8192 7.8 M 1
2022-08-15 18:20:00.215 0.000 TCP 69.30.232.1:62512 -> 103.116.72.10:80 ….S. 0 8192 7.8 M 1
2022-08-15 18:20:00.343 0.000 TCP 69.30.232.1:44298 -> 103.116.72.10:80 ….S. 0 8192 7.5 M 1
2022-08-15 18:20:00.466 0.000 TCP 69.30.232.1:23568 -> 103.116.72.10:80 ….S. 0 8192 7.8 M 1
2022-08-15 18:20:00.515 0.000 TCP 69.30.232.1:39390 -> 103.116.72.10:80 ….S. 0 8192 7.6 M 1
2022-08-15 18:20:00.540 0.000 TCP 69.30.232.1:59281 -> 103.116.72.10:80 ….S. 0 8192 7.8 M 1
2022-08-15 18:20:00.615 0.000 TCP 69.30.232.1:12467 -> 103.116.72.10:80 ….S. 0 8192 7.8 M 1
2022-08-15 18:20:00.643 0.000 TCP 69.30.232.1:64521 -> 103.116.72.10:80 ….S. 0 8192 7.8 M 1
2022-08-15 18:20:00.740 0.000 TCP 69.30.232.1:33673 -> 103.116.72.10:80 ….S. 0 8192 7.6 M 1
2022-08-15 18:20:00.791 0.000 TCP 69.30.232.1:31393 -> 103.116.72.10:80 0xc2 0 8192 7.7 M 1
2022-08-15 18:20:00.853 0.000 TCP 69.30.232.1:30914 -> 103.116.72.10:80 0x82 0 8192 7.8 M 1
2022-08-15 18:20:01.040 0.000 TCP 69.30.232.1:8170 -> 103.116.72.10:80 ….S. 0 8192 7.8 M 1
2022-08-15 18:20:01.066 0.000 TCP 69.30.232.1:10607 -> 103.116.72.10:80 0x42 0 8192 7.6 M 1
2022-08-15 18:20:01.192 0.000 TCP 69.30.232.1:52738 -> 103.116.72.10:80 ….S. 0 8192 7.5 M 1
2022-08-15 18:20:01.192 0.000 TCP 69.30.232.1:2445 -> 103.116.72.10:80 ….S. 0 8192 7.8 M 1
2022-08-15 18:20:01.243 0.000 TCP 69.30.232.1:64710 -> 103.116.72.10:80 ….S. 0 8192 7.5 M 1
2022-08-15 18:20:01.243 0.000 TCP 69.30.232.1:38269 -> 103.116.72.10:80 ….S. 0 8192 7.8 M 1
Summary: total flows: 20, total bytes: 154009600, total packets: 163840, avg bps: 1014890280, avg pps: 134958, avg bpp: 940

意思就是说,你的IP对外发包了。估计是用了什么不明来历的脚本中毒了吧。
干PT  一天3-5TB  没滥用警告

hfhfg 发表于 2022-8-16 12:34
意思就是说,你的IP对外发包了。估计是用了什么不明来历的脚本中毒了吧。 …

可能是弱密码吧。。。堪萨斯滥用警告,这是啥???

stingeo 发表于 2022-8-16 12:43
可能是弱密码吧。。。

如果没有重要数据,直接回复中毒之类,要求重装。不过不知道会不会收费。。。

楼上的都不看log直接张口就来吗堪萨斯滥用警告,这是啥???

hfhfg 发表于 2022-8-15 19:51
如果没有重要数据,直接回复中毒之类,要求重装。不过不知道会不会收费。。。 …

开工单人工重装,不收费

直接后台重装系统吧

emptysuns 发表于 2022-8-16 12:56
开工单人工重装,不收费

看来很多人都在用这家堪萨斯滥用警告,这是啥???