瑞星卡卡安全论坛技术交流区系统软件 局网老是受攻击,请大侠帮忙诊断。

1   1  /  1  页   跳转

局网老是受攻击,请大侠帮忙诊断。

局网老是受攻击,请大侠帮忙诊断。

最近一个星期内,内网老是断线,每次断2-3分钟后就自动连接上了,

查看了下防火墙的日志,
发现有个IP。老是攻击网关
但内网内无这个IP的PC

请大侠支招。谢谢


以下是日志




1 2006-08-10 13:11:14 alert 192.168.0.213 222.216.170.26 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 26 times [Reference: http://www.fortinet.com/ids/ID102891601]
2 2006-08-10 13:11:06 alert 192.168.0.213 218.109.48.2 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 13 times [Reference: http://www.fortinet.com/ids/ID102891601]
3 2006-08-10 13:10:59 alert 192.168.0.213 58.52.75.214 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 6 times [Reference: http://www.fortinet.com/ids/ID102891601]
4 2006-08-10 13:10:54 alert 192.168.0.213 61.178.252.25 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 7 times [Reference: http://www.fortinet.com/ids/ID102891601]
5 2006-08-10 13:10:49 alert 192.168.0.213 222.84.16.203 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 2 times [Reference: http://www.fortinet.com/ids/ID102891601]
6 2006-08-10 13:10:42 alert 192.168.0.213 59.59.144.115 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 11 times [Reference: http://www.fortinet.com/ids/ID102891601]
7 2006-08-10 13:10:35 alert 192.168.0.213 222.84.16.203 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 3 times [Reference: http://www.fortinet.com/ids/ID102891601]
8 2006-08-10 13:10:30 alert 192.168.0.213 58.49.218.14 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 8 times [Reference: http://www.fortinet.com/ids/ID102891601]
9 2006-08-10 13:10:22 alert 192.168.0.213 222.84.16.203 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 3 times [Reference: http://www.fortinet.com/ids/ID102891601]
10 2006-08-10 13:09:34 alert 192.168.0.213 222.182.122.99 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 9 times [Reference: http://www.fortinet.com/ids/ID102891601]
11 2006-08-10 13:09:25 alert 192.168.0.213 222.84.16.203 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 3 times [Reference: http://www.fortinet.com/ids/ID102891601]
12 2006-08-10 13:08:38 alert 192.168.0.213 222.138.79.213 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 11 times [Reference: http://www.fortinet.com/ids/ID102891601]
13 2006-08-10 13:08:31 alert 192.168.0.213 59.59.144.115 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 15 times [Reference: http://www.fortinet.com/ids/ID102891601]
14 2006-08-10 13:08:23 alert 192.168.0.213 222.75.101.197 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 19 times [Reference: http://www.fortinet.com/ids/ID102891601]
15 2006-08-10 13:08:16 alert 192.168.0.213 58.209.203.231 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 21 times [Reference: http://www.fortinet.com/ids/ID102891601]
16 2006-08-10 13:08:08 alert 192.168.0.213 58.52.75.214 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 29 times [Reference: http://www.fortinet.com/ids/ID102891601]
17 2006-08-10 13:07:59 alert 192.168.0.213 60.182.82.230 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 16 times [Reference: http://www.fortinet.com/ids/ID102891601]
18 2006-08-10 13:07:50 alert 192.168.0.213 222.89.60.183 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 16 times [Reference: http://www.fortinet.com/ids/ID102891601]
19 2006-08-10 13:07:43 alert 192.168.0.213 60.191.15.134 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 24 times [Reference: http://www.fortinet.com/ids/ID102891601]
20 2006-08-10 13:07:35 alert 192.168.0.213 59.61.101.94 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 7 times [Reference: http://www.fortinet.com/ids/ID102891601]
21 2006-08-10 13:07:27 alert 192.168.0.213 211.155.251.133 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 18 times [Reference: http://www.fortinet.com/ids/ID102891601]
22 2006-08-10 13:07:20 alert 192.168.0.213 59.59.144.40 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 17 times [Reference: http://www.fortinet.com/ids/ID102891601]
23 2006-08-10 13:07:14 alert 192.168.0.213 61.155.132.237 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 12 times [Reference: http://www.fortinet.com/ids/ID102891601]
24 2006-08-10 13:07:08 alert 192.168.0.213 222.216.170.26 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 13 times [Reference: http://www.fortinet.com/ids/ID102891601]
25 2006-08-10 13:07:02 alert 192.168.0.213 222.75.101.197 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 4 times [Reference: http://www.fortinet.com/ids/ID102891601]
26 2006-08-10 13:06:56 alert 192.168.0.213 222.210.30.154 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 12 times [Reference: http://www.fortinet.com/ids/ID102891601]
27 2006-08-10 13:06:50 alert 192.168.0.213 60.191.15.134 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 4 times [Reference: http://www.fortinet.com/ids/ID102891601]
28 2006-08-10 13:06:44 alert 192.168.0.213 218.19.75.202 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 17 times [Reference: http://www.fortinet.com/ids/ID102891601]
29 2006-08-10 13:06:37 alert 192.168.0.213 125.78.173.211 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 13 times [Reference: http://www.fortinet.com/ids/ID102891601]
30 2006-08-10 13:06:31 alert 192.168.0.213 222.75.101.197 web-server: Apache.CGI.Byterange.Request.DoS, aggregated 
最后编辑2006-08-10 14:42:26
分享到:
gototop
 

呵呵,头疼的Dos攻击,看看,人家在给你提建议呢

http://www.fortinet.com/ids/ID102891601
gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT