- 論壇徽章:
- 0
|
被UDP攻擊,詳情如貼
tcpdump 抓包如下:
20:35:37.529087 IP 61.53.229.191.2823 > 221.8.17.22.80: UDP, length 4
20:35:37.529100 IP 221.192.121.124.1431 > 221.8.17.22.80: UDP, length 4
20:35:37.529136 IP 124.90.26.124.1359 > 221.8.17.22.80: UDP, length 4
20:35:37.529185 IP 60.3.170.224.4629 > 221.8.17.22.80: UDP, length 4
20:35:37.529223 IP 211.103.79.8.54561 > 221.8.17.22.80: UDP, length 4
20:35:37.529272 IP 121.51.24.96.1882 > 221.8.17.22.80: UDP, length 4
20:35:37.530251 IP 124.234.242.151.4649 > 221.8.17.22.80: UDP, length 4
20:35:37.530290 IP 218.104.90.252.37557 > 221.8.17.22.80: UDP, length 4
20:35:37.530337 IP 203.92.154.37.29635 > 221.8.17.22.80: UDP, length 4
20:35:37.530369 IP 60.14.58.86.1529 > 221.8.17.22.80: UDP, length 4
20:35:37.530423 IP 124.234.242.151.4641 > 221.8.17.22.80: UDP, length 4
20:35:37.530461 IP 218.84.213.83.49626 > 221.8.17.22.80: UDP, length 4
20:35:37.530498 IP 58.17.35.242.31688 > 221.8.17.22.80: UDP, length 4
20:35:37.530546 IP 221.195.216.52.1343 > 221.8.17.22.80: UDP, length 4
20:35:37.530584 IP 218.84.213.83.12706 > 221.8.17.22.80: UDP, length 4
20:35:37.530633 IP 124.91.104.236.1270 > 221.8.17.22.80: UDP, length 4
20:35:37.530665 IP 124.234.242.151.4653 > 221.8.17.22.80: UDP, length 4
20:35:37.530707 IP 124.234.242.151.4655 > 221.8.17.22.80: UDP, length 4
20:35:37.530755 IP 222.130.30.182.3810 > 221.8.17.22.80: UDP, length 4
20:35:37.530789 IP 124.234.242.151.4643 > 221.8.17.22.80: UDP, length 4
20:35:37.530842 IP 61.53.229.191.2828 > 221.8.17.22.80: UDP, length 4
20:35:37.530879 IP 124.234.242.151.4648 > 221.8.17.22.80: UDP, length 4
我用腳本查過(guò),大概有30-200個(gè)外網(wǎng)IP不等.全國(guó)各地哪都有.
當(dāng)攻擊開(kāi)始時(shí),有如下證狀:
CPU占用率加大
開(kāi)始時(shí)丟包,然后掉網(wǎng),帶寬全部被占滿(mǎn)
iptables 中設(shè)置了將所有UDP協(xié)議發(fā)往80端口的包全部DROP,
iptables -vnL 結(jié)果顯示確實(shí)丟棄了很多包,但這根本不能解決問(wèn)題,網(wǎng)速一樣的慢,一樣的掉線(xiàn),
郁悶中....
遇到這種問(wèn)題,只能求助于防火墻嗎?前幾天試過(guò)銳捷的那個(gè)路由器,說(shuō)是能防住每分/秒(忘了)300M攻擊,還是什么電信級(jí)路由器,比LINUX死的還快.
誰(shuí)有好的解決辦法?或是比較好用的防火墻,請(qǐng)留言.謝謝. |
|