|
|
系统是RH8.0,硬件配置:P4 1.8G/512m/40G/
开启的服务有:Mail web SMB mrtg ,这段时间负载总是奇高,导致内都不收信的状况,平时敲个命令有时候也等好一会儿,原来有启动图形界面,现在只启动文本模式,也没见负载比较正常。特别是用户在收信时,负载明显上升。
下面是messages的部分信息,大家看一下我是不是中招了,218.85.XXX.XXX是我改的
Dec 19 04:03:35 crnlinux syslogd 1.4.1: restart.
Dec 19 04:03:47 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=00:d0:f8:3d:27:a6:00:04:dd:fa:bd:1f:08:00 SRC=168.95.1.1 DST=218.85.XXX.XXX LEN=71 TOS=0x00 PREC=0x00 TTL=241 ID=1990 DF PROTO=UDP SPT=53 DPT=34305 LEN=51
Dec 19 04:04:01 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=00:d0:f8:3d:27:a6:00:04:dd:fa:bd:1f:08:00 SRC=168.95.1.1 DST=218.85.XXX.XXX LEN=71 TOS=0x00 PREC=0x00 TTL=241 ID=61859 DF PROTO=UDP SPT=53 DPT=34305 LEN=51
Dec 19 04:05:01 crnlinux net-snmp[802]: Connection from udp:218.85.XXX.XXX:34412
Dec 19 04:05:01 crnlinux net-snmp[802]: Received SNMP packet(s) from udp:218.85.XXX.XXX:34412
Dec 19 04:05:01 crnlinux net-snmp[802]: Connection from udp:218.85.XXX.XXX:34412
Dec 19 04:05:01 crnlinux net-snmp[802]: Received SNMP packet(s) from udp:218.85.XXX.XXX:34412
Dec 19 04:05:10 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=00:d0:f8:3d:27:a6:00:04:dd:fa:bd:1f:08:00 SRC=168.95.1.1 DST=218.85.XXX.XXX LEN=73 TOS=0x00 PREC=0x00 TTL=241 ID=57400 DF PROTO=UDP SPT=53 DPT=34412 LEN=53
Dec 19 04:05:36 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=00:d0:f8:3d:27:a6:00:04:dd:fa:bd:1f:08:00 SRC=168.95.1.1 DST=218.85.XXX.XXX LEN=72 TOS=0x00 PREC=0x00 TTL=241 ID=25275 DF PROTO=UDP SPT=53 DPT=34409 LEN=52
Dec 19 04:07:39 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:11:09:9b:63:f6:08:00 SRC=218.85.129.70 DST=218.85.129.71 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=38748 PROTO=UDP SPT=137 DPT=137 LEN=58
Dec 19 04:07:40 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:11:09:9b:63:f6:08:00 SRC=218.85.129.70 DST=218.85.129.71 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=38761 PROTO=UDP SPT=137 DPT=137 LEN=58
Dec 19 04:07:41 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:11:09:9b:63:f6:08:00 SRC=218.85.129.70 DST=218.85.129.71 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=38762 PROTO=UDP SPT=137 DPT=137 LEN=58
Dec 19 04:07:46 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:11:09:9b:63:f6:08:00 SRC=218.85.129.70 DST=218.85.129.71 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=38768 PROTO=UDP SPT=137 DPT=137 LEN=58
Dec 19 04:07:47 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:11:09:9b:63:f6:08:00 SRC=218.85.129.70 DST=218.85.129.71 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=38769 PROTO=UDP SPT=137 DPT=137 LEN=58
Dec 19 04:07:47 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:11:09:9b:63:f6:08:00 SRC=218.85.129.70 DST=218.85.129.71 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=38770 PROTO=UDP SPT=137 DPT=137 LEN=58
Dec 19 04:10:03 crnlinux net-snmp[802]: Connection from udp:218.85.XXX.XXX:34412
Dec 19 04:10:03 crnlinux net-snmp[802]: Received SNMP packet(s) from udp:218.85.XXX.XXX:34412
Dec 19 04:10:03 crnlinux net-snmp[802]: Connection from udp:218.85.XXX.XXX:34412
Dec 19 04:10:03 crnlinux net-snmp[802]: Received SNMP packet(s) from udp:218.85.XXX.XXX:34412
Dec 19 04:12:19 crnlinux kernel: fp=TCP:1 a=DROP IN=eth1 OUT= MAC=00:d0:f8:3d:27:a6:00:04:dd:fa:bd:1f:08:00 SRC=218.85.110.87 DST=218.85.XXX.XXX LEN=48 TOS=0x00 PREC=0x00 TTL=124 ID=27998 DF PROTO=TCP SPT=4784 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
Dec 19 04:12:22 crnlinux kernel: fp=TCP:1 a=DROP IN=eth1 OUT= MAC=00:d0:f8:3d:27:a6:00:04:dd:fa:bd:1f:08:00 SRC=218.85.110.87 DST=218.85.XXX.XXX LEN=48 TOS=0x00 PREC=0x00 TTL=124 ID=28336 DF PROTO=TCP SPT=4784 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
Dec 19 04:12:27 crnlinux su(pam_unix)[32023]: session opened for user news by (uid=0)
Dec 19 04:12:27 crnlinux su(pam_unix)[32023]: session closed for user news
Dec 19 04:15:01 crnlinux net-snmp[802]: Connection from udp:218.85.XXX.XXX:34412
Dec 19 04:15:01 crnlinux net-snmp[802]: Received SNMP packet(s) from udp:218.85.XXX.XXX:34412
Dec 19 04:15:01 crnlinux net-snmp[802]: Connection from udp:218.85.XXX.XXX:34412
Dec 19 04:15:01 crnlinux net-snmp[802]: Received SNMP packet(s) from udp:218.85.XXX.XXX:34412
Dec 19 04:15:48 crnlinux kernel: fp=TCP:1 a=DROP IN=eth1 OUT= MAC=00:d0:f8:3d:27:a6:00:04:dd:fa:bd:1f:08:00 SRC=218.85.90.189 DST=218.85.XXX.XXX LEN=48 TOS=0x00 PREC=0x00 TTL=124 ID=41831 DF PROTO=TCP SPT=2367 DPT=135 WINDOW=32000 RES=0x00 SYN URGP=0
Dec 19 04:16:45 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=00:d0:f8:3d:27:a6:00:04:dd:fa:bd:1f:08:00 SRC=61.178.172.100 DST=218.85.XXX.XXX LEN=404 TOS=0x00 PREC=0x00 TTL=117 ID=19517 PROTO=UDP SPT=4228 DPT=1434 LEN=384
Dec 19 04:18:12 crnlinux kernel: fp=TCP:1 a=DROP IN=eth1 OUT= MAC=00:d0:f8:3d:27:a6:00:04:dd:fa:bd:1f:08:00 SRC=211.87.198.222 DST=218.85.XXX.XXX LEN=40 TOS=0x00 PREC=0x00 TTL=47 ID=47075 DF PROTO=TCP SPT=12200 DPT=1080 WINDOW=8192 RES=0x00 SYN URGP=0
Dec 19 04:19:42 crnlinux kernel: fp=TCP:1 a=DROP IN=eth1 OUT= MAC=00:d0:f8:3d:27:a6:00:04:dd:fa:bd:1f:08:00 SRC=64.4.55.74 DST=218.85.XXX.XXX LEN=40 TOS=0x00 PREC=0x00 TTL=116 ID=48877 DF PROTO=TCP SPT=80 DPT=1218 WINDOW=64459 RES=0x00 ACK URGP=0
Dec 19 04:19:42 crnlinux kernel: fp=TCP:1 a=DROP IN=eth1 OUT= MAC=00:d0:f8:3d:27:a6:00:04:dd:fa:bd:1f:08:00 SRC=64.4.55.90 DST=218.85.XXX.XXX LEN=40 TOS=0x00 PREC=0x00 TTL=116 ID=52165 DF PROTO=TCP SPT=80 DPT=1219 WINDOW=64459 RES=0x00 ACK URGP=0
Dec 19 04:19:53 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:11:09:9b:63:f6:08:00 SRC=218.85.129.70 DST=218.85.129.71 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=39472 PROTO=UDP SPT=137 DPT=137 LEN=58
Dec 19 04:19:54 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:11:09:9b:63:f6:08:00 SRC=218.85.129.70 DST=218.85.129.71 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=39473 PROTO=UDP SPT=137 DPT=137 LEN=58
Dec 19 04:19:54 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:11:09:9b:63:f6:08:00 SRC=218.85.129.70 DST=218.85.129.71 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=39474 PROTO=UDP SPT=137 DPT=137 LEN=58
Dec 19 04:19:57 crnlinux kernel: fp=TCP:1 a=DROP IN=eth1 OUT= MAC=00:d0:f8:3d:27:a6:00:04:dd:fa:bd:1f:08:00 SRC=218.85.90.189 DST=218.85.XXX.XXX LEN=48 TOS=0x00 PREC=0x00 TTL=124 ID=13648 DF PROTO=TCP SPT=2911 DPT=135 WINDOW=32000 RES=0x00 SYN URGP=0
Dec 19 04:20:00 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:11:09:9b:63:f6:08:00 SRC=218.85.129.70 DST=218.85.129.71 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=39493 PROTO=UDP SPT=137 DPT=137 LEN=58
Dec 19 04:20:00 crnlinux kernel: fp=TCP:1 a=DROP IN=eth1 OUT= MAC=00:d0:f8:3d:27:a6:00:04:dd:fa:bd:1f:08:00 SRC=218.85.90.189 DST=218.85.XXX.XXX LEN=48 TOS=0x00 PREC=0x00 TTL=124 ID=14274 DF PROTO=TCP SPT=2911 DPT=135 WINDOW=32000 RES=0x00 SYN URGP=0
Dec 19 04:20:00 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:11:09:9b:63:f6:08:00 SRC=218.85.129.70 DST=218.85.129.71 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=39494 PROTO=UDP SPT=137 DPT=137 LEN=58
Dec 19 04:20:01 crnlinux kernel: fp=UDP:2 a=DROP IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:11:09:9b:63:f6:08:00 SRC=218.85.129.70 DST=218.85.129.71 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=39495 PROTO=UDP SPT=137 DPT=137 LEN=58
Dec 19 04:20:01 crnlinux kernel: fp=TCP:1 a=DROP IN=eth1 OUT= MAC=00:d0:f8:3d:27:a6:00:04:dd:fa:bd:1f:08:00 SRC=64.4.55.90 DST=218.85.XXX.XXX LEN=40 TOS=0x00 PREC=0x00 TTL=116 ID=6638 DF PROTO=TCP SPT=80 DPT=1219 WINDOW=0 RES=0x00 ACK RST URGP=0
Dec 19 04:20:01 crnlinux net-snmp[802]: Connection from udp:218.85.XXX.XXX:34412
下面是用nmap扫描的
Starting nmap V. 3.00 ( www.insecure.org/nmap/ )
Interesting ports on (192.168.0.137):
(The 1594 ports scanned but not shown below are in state: closed)
Port State Service
22/tcp open ssh
25/tcp open smtp
80/tcp open http
110/tcp open pop-3
111/tcp open sunrpc
139/tcp open netbios-ssn
443/tcp open https
Nmap run completed -- 1 IP address (1 host up) scanned in 2 seconds |
|