FTP서버 브루트포스 공격받는 중입니다
제 FTP 서버에 로긴 시도가 오는데 어떻게 대응해야 되나요?
(000002)2011-07-09 오전 8:31:26 - (not logged in) (59.42.254.81)> USER Administrator
(000002)2011-07-09 오전 8:31:26 - (not logged in) (59.42.254.81)> 331 Password required for administrator
(000002)2011-07-09 오전 8:31:26 - (not logged in) (59.42.254.81)> USER Administrator
(000002)2011-07-09 오전 8:31:26 - (not logged in) (59.42.254.81)> 331 Password required for administrator
(000002)2011-07-09 오전 8:31:26 - (not logged in) (59.42.254.81)> USER Administrator
(000002)2011-07-09 오전 8:31:26 - (not logged in) (59.42.254.81)> 331 Password required for administrator
부터
(000057)2011-07-09 오전 9:27:26 - (not logged in) (59.42.254.81)> USER Administrator
(000057)2011-07-09 오전 9:27:26 - (not logged in) (59.42.254.81)> 331 Password required for administrator
(000057)2011-07-09 오전 9:27:32 - (not logged in) (59.42.254.81)> USER Administrator
(000057)2011-07-09 오전 9:27:32 - (not logged in) (59.42.254.81)> 331 Password required for administrator
(000057)2011-07-09 오전 9:27:40 - (not logged in) (59.42.254.81)> USER Administrator
(000057)2011-07-09 오전 9:27:40 - (not logged in) (59.42.254.81)> 331 Password required for administrator
% APNIC found the following authoritative answer from: whois.apnic.net
% [whois.apnic.net node-5]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html
inetnum: 59.42.254.0 - 59.42.254.82
netname: guangdongguangxintongxinfuwuyou
descr: guangzhoushitianhelongkoudonglu366haoxita2lou
country: CN
admin-c: GZ-AP
tech-c: IC83-AP
mnt-by: MAINT-CHINANET-GD
changed: gdtel_ipreg@163.com 20100102
status: Allocated non-portable
source: APNIC
person: GUANGZHOU WANJIAN
address: No.17, Jiao Chang Xi Road, Guangzhou ,China
country: CN
phone: +86-20-86002309
e-mail: ipadm@gddc.com.cn
remarks: IPMASTER is not for spam complaint,please send spam complaint to abuse@gddc.com.cn
nic-hdl: GZ-AP
mnt-by: MAINT-CHINANET-GD
changed: CHENYIQ@GSTA.COM 20080328
source: APNIC
person: IPMASTER CHINANET-GD
nic-hdl: IC83-AP
e-mail: ipadm@189.cn
address: NO.1,RO.DONGYUANHENG,YUEXIUNAN,GUANGZHOU
phone: +86-20-83877223
fax-no: +86-20-83877223
country: CN
changed: ipadm@189.cn 20110418
mnt-by: MAINT-CHINANET-GD
remarks: IPMASTER is not for spam complaint,please send spam complaint to abuse_gdnoc@189.cn
abuse-mailbox: abuse_gdnoc@189.cn
source: APNIC
59.42.254.81 현재 열린 포트
22, 80, 4400(proxy+)
같은 아이피다 싶으면 그 아이피 막아버리면 되지요.
ftp서버쪽은 사정을 잘 모르겠지만 일반적으론 같은 아이피다 싶으면 그 아이피 막아버리면 되지요.
댓글 달기