网站被攻击啦!!!

网站被攻击啦!!!以下是截取的部分log
118.79.197.119 – – [30/Sep/2010:22:14:53 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
61.150.93.133 – – [30/Sep/2010:22:14:53 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
202.101.153.186 – – [30/Sep/2010:22:14:54 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
59.57.91.185 – – [30/Sep/2010:22:14:54 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
110.73.186.69 – – [30/Sep/2010:22:14:55

118.79.197.119 – – [30/Sep/2010:22:14:53 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
61.150.93.133 – – [30/Sep/2010:22:14:53 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
202.101.153.186 – – [30/Sep/2010:22:14:54 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
59.57.91.185 – – [30/Sep/2010:22:14:54 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
110.73.186.69 – – [30/Sep/2010:22:14:55 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
113.137.226.26 – – [30/Sep/2010:22:14:55 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
221.217.136.114 – – [30/Sep/2010:22:14:55 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
221.217.136.114 – – [30/Sep/2010:22:14:56 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
60.189.219.96 – – [30/Sep/2010:22:14:57 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
115.170.55.185 – – [30/Sep/2010:22:14:57 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
121.20.16.206 – – [30/Sep/2010:22:14:57 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
27.189.198.249 – – [30/Sep/2010:22:14:57 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
183.30.94.149 – – [30/Sep/2010:22:14:58 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
124.91.56.13 – – [30/Sep/2010:22:14:58 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
27.36.173.113 – – [30/Sep/2010:22:14:58 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
219.129.197.12 – – [30/Sep/2010:22:15:00 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
113.69.247.52 – – [30/Sep/2010:22:15:00 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
119.135.222.99 – – [30/Sep/2010:22:15:00 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
61.163.35.7 – – [30/Sep/2010:22:15:00 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
27.38.37.246 – – [30/Sep/2010:22:15:00 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
61.150.93.133 – – [30/Sep/2010:22:15:00 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
115.216.56.204 – – [30/Sep/2010:22:15:00 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
220.179.63.18 – – [30/Sep/2010:22:15:01 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
222.131.8.169 – – [30/Sep/2010:22:15:01 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
113.69.247.52 – – [30/Sep/2010:22:15:01 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
27.38.37.246 – – [30/Sep/2010:22:15:01 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
113.14.91.96 – – [30/Sep/2010:22:15:01 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
220.184.142.41 – – [30/Sep/2010:22:15:01 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
220.243.63.217 – – [30/Sep/2010:22:15:01 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
116.208.142.23 – – [30/Sep/2010:22:15:02 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
113.83.58.6 – – [30/Sep/2010:22:15:02 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
119.123.204.41 – – [30/Sep/2010:22:15:03 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
218.72.160.11 – – [30/Sep/2010:22:15:04 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
218.72.160.11 – – [30/Sep/2010:22:15:04 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
218.65.28.100 – – [30/Sep/2010:22:15:04 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
123.234.104.38 – – [30/Sep/2010:22:15:05 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
114.98.88.127 – – [30/Sep/2010:22:15:05 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
113.237.53.140 – – [30/Sep/2010:22:15:05 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
183.4.244.136 – – [30/Sep/2010:22:15:06 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
123.131.110.103 – – [30/Sep/2010:22:15:06 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
218.4.145.250 – – [30/Sep/2010:22:15:06 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
218.4.145.250 – – [30/Sep/2010:22:15:06 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
220.191.234.194 – – [30/Sep/2010:22:15:06 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
115.55.230.220 – – [30/Sep/2010:22:15:07 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
113.68.80.11 – – [30/Sep/2010:22:15:08 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
123.81.46.37 – – [30/Sep/2010:22:15:08 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
222.245.125.133 – – [30/Sep/2010:22:15:08 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
121.15.21.208 – – [30/Sep/2010:22:15:08 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
219.128.68.56 – – [30/Sep/2010:22:15:08 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
123.5.61.4 – – [30/Sep/2010:22:15:08 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
211.3.111.233 – – [30/Sep/2010:22:15:09 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
220.249.183.74 – – [30/Sep/2010:22:15:09 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
124.200.241.45 – – [30/Sep/2010:22:15:09 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
219.132.30.82 – – [30/Sep/2010:22:15:09 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
118.253.104.73 – – [30/Sep/2010:22:15:09 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
123.121.207.246 – – [30/Sep/2010:22:15:10 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
61.140.36.27 – – [30/Sep/2010:22:15:10 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
124.200.241.45 – – [30/Sep/2010:22:15:10 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
60.161.2.109 – – [30/Sep/2010:22:15:10 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
220.191.234.194 – – [30/Sep/2010:22:15:10 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
220.191.234.194 – – [30/Sep/2010:22:15:11 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
61.136.78.130 – – [30/Sep/2010:22:15:11 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
218.201.78.52 – – [30/Sep/2010:22:15:11 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
123.150.108.102 – – [30/Sep/2010:22:15:12 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
119.32.52.165 – – [30/Sep/2010:22:15:12 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
218.58.11.153 – – [30/Sep/2010:22:15:13 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
116.18.217.112 – – [30/Sep/2010:22:15:14 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
61.150.93.133 – – [30/Sep/2010:22:15:14 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
110.73.186.69 – – [30/Sep/2010:22:15:15 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
59.57.91.185 – – [30/Sep/2010:22:15:15 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
202.101.153.186 – – [30/Sep/2010:22:15:16 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
113.137.226.26 – – [30/Sep/2010:22:15:16 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
60.189.219.96 – – [30/Sep/2010:22:15:17 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
221.217.136.114 – – [30/Sep/2010:22:15:17 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
121.20.16.206 – – [30/Sep/2010:22:15:18 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
27.189.198.249 – – [30/Sep/2010:22:15:18 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
221.217.136.114 – – [30/Sep/2010:22:15:19 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
183.30.94.149 – – [30/Sep/2010:22:15:19 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
115.170.55.185 – – [30/Sep/2010:22:15:19 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
27.36.173.113 – – [30/Sep/2010:22:15:20 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
124.91.56.13 – – [30/Sep/2010:22:15:20 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
61.163.35.7 – – [30/Sep/2010:22:15:20 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
219.129.197.12 – – [30/Sep/2010:22:15:21 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
220.179.63.18 – – [30/Sep/2010:22:15:21 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
119.135.222.99 – – [30/Sep/2010:22:15:21 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
61.150.93.133 – – [30/Sep/2010:22:15:21 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
27.38.37.246 – – [30/Sep/2010:22:15:21 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
115.216.56.204 – – [30/Sep/2010:22:15:21 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
119.123.204.41 – – [30/Sep/2010:22:15:22 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
113.69.247.52 – – [30/Sep/2010:22:15:22 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
220.184.142.41 – – [30/Sep/2010:22:15:22 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
222.131.8.169 – – [30/Sep/2010:22:15:22 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
27.38.37.246 – – [30/Sep/2010:22:15:22 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
113.14.91.96 – – [30/Sep/2010:22:15:22 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
220.243.63.217 – – [30/Sep/2010:22:15:23 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
116.208.142.23 – – [30/Sep/2010:22:15:23 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
113.69.247.52 – – [30/Sep/2010:22:15:23 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
113.83.58.6 – – [30/Sep/2010:22:15:23 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
113.26.3.202 – – [30/Sep/2010:22:15:24 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
218.72.160.11 – – [30/Sep/2010:22:15:24 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
218.72.160.11 – – [30/Sep/2010:22:15:24 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
119.123.204.41 – – [30/Sep/2010:22:15:25 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
123.234.104.38 – – [30/Sep/2010:22:15:25 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
218.4.145.250 – – [30/Sep/2010:22:15:26 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
218.4.145.250 – – [30/Sep/2010:22:15:26 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
114.98.88.127 – – [30/Sep/2010:22:15:26 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
220.191.234.194 – – [30/Sep/2010:22:15:26 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
183.4.244.136 – – [30/Sep/2010:22:15:27 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
218.65.28.87 – – [30/Sep/2010:22:15:27 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
123.131.110.103 – – [30/Sep/2010:22:15:27 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
113.68.80.11 – – [30/Sep/2010:22:15:28 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
115.55.230.220 – – [30/Sep/2010:22:15:28 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
219.128.68.56 – – [30/Sep/2010:22:15:29 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
211.3.111.233 – – [30/Sep/2010:22:15:29 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
123.81.46.37 – – [30/Sep/2010:22:15:29 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
121.15.21.208 – – [30/Sep/2010:22:15:29 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
222.245.125.133 – – [30/Sep/2010:22:15:29 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
113.237.53.140 – – [30/Sep/2010:22:15:30 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
220.249.183.74 – – [30/Sep/2010:22:15:30 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
118.253.104.73 – – [30/Sep/2010:22:15:30 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
219.132.30.82 – – [30/Sep/2010:22:15:31 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
220.191.234.194 – – [30/Sep/2010:22:15:31 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
123.121.207.246 – – [30/Sep/2010:22:15:31 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
220.191.234.194 – – [30/Sep/2010:22:15:31 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
60.161.2.109 – – [30/Sep/2010:22:15:32 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
123.5.61.4 – – [30/Sep/2010:22:15:32 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
61.136.78.130 – – [30/Sep/2010:22:15:32 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
119.32.52.165 – – [30/Sep/2010:22:15:33 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
123.150.108.102 – – [30/Sep/2010:22:15:34 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
124.200.241.45 – – [30/Sep/2010:22:15:34 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
218.58.11.153 – – [30/Sep/2010:22:15:34 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
124.200.241.45 – – [30/Sep/2010:22:15:35 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
61.150.93.133 – – [30/Sep/2010:22:15:35 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279
110.73.186.69 – – [30/Sep/2010:22:15:35 +0800] “POST /WebService/ClientService.asmx HTTP/1.1” 302 279

比较早期的解决方法:在3秒内连续刷新页面5次以上将指向本机 http://127.0.0.1

$P_S_T = $t_array[0] + $t_array[1];
$timestamp = time();

session_start();
$ll_nowtime = $timestamp ;
if (session_is_registered(‘ll_lasttime’)){
$ll_lasttime = $_SESSION[‘ll_lasttime’];
$ll_times = $_SESSION[‘ll_times’] + 1;
$_SESSION[‘ll_times’] = $ll_times;
}else{
$ll_lasttime = $ll_nowtime;
$ll_times = 1;
$_SESSION[‘ll_times’] = $ll_times;
$_SESSION[‘ll_lasttime’] = $ll_lasttime;
}
if (($ll_nowtime – $ll_lasttime)<3){
if ($ll_times>=5){
header(sprintf(“Location: %s”,’http://127.0.0.1′));
exit;
}
}else{
$ll_times = 0;
$_SESSION[‘ll_lasttime’] = $ll_nowtime;
$_SESSION[‘ll_times’] = $ll_times;
}

其它方法:
1).取消域名绑定
一般cc攻击都是针对网站的域名进行攻击,比如网站域名是“www.google.com”,那么攻击者就在攻击工具中设定攻击对象为该域名然后实施攻击。
对于这样的攻击我们的措施是在IIS上取消这个域名的绑定,让CC攻击失去目标。具体操作步骤是:打开“IIS管理器”定位到具体站点右键“属性”打开该站点的属性面板,点击IP地址右侧的“高级”按钮,选择该域名项进行编辑,将“主机头值”删除或者改为其它的值(域名)。

经过模拟测试,取消域名绑定后Web服务器的CPU马上恢复正常状态,通过IP进行访问连接一切正常。但是不足之处也很明显,取消或者更改域名对于别人的访问带来了不变,另外,对于针对IP的CC攻击它是无效的,就算更换域名攻击者发现之后,他也会对新域名实施攻击。
(2).域名欺骗解析
如果发现针对域名的CC攻击,我们可以把被攻击的域名解析到127.0.0.1这个地址上。我们知道127.0.0.1是本地回环IP是用来进行网络测试的,如果把被攻击的域名解析到这个IP上,就可以实现攻击者自己攻击自己的目的,这样他再多的肉鸡或者代理也会宕机,让其自作自受。
另外,当我们的Web服务器遭受CC攻击时把被攻击的域名解析到国家有权威的GVM网站或者是网警的网站,让其网警来收拾他们。
现在一般的Web站点都是利用类似“新网”这样的服务商提供的动态域名解析服务,大家可以登录进去之后进行设置。
(3).更改Web端口
一般情况下Web服务器通过80端口对外提供服务,因此攻击者实施攻击就以默认的80端口进行攻击,所以,我们可以修改Web端口达到防CC攻击的目的。运行IIS管理器,定位到相应站点,打开站点“属性”面板,在“网站标识”下有个TCP端口默认为80,我们修改为其他的端口就可以了。
(4).IIS屏蔽IP
我们通过命令或在查看日志发现了CC攻击的源IP,就可以在IIS中设置屏蔽该IP对Web站点的访问,从而达到防范IIS攻击的目的。在相应站点的“属性”面板中,点击“目录安全性”选项卡,点击“IP地址和域名现在”下的“编辑”按钮打开设置对话框。在此窗口中我们可以设置“授权访问”也就是“白名单”,也可以设置“拒绝访问”即“黑名单”。比如我们可以将攻击者的IP添加到“拒绝访问”列表中,就屏蔽了该IP对于Web的访问。

Leave a Reply