大神求助:服务器疑是被攻击,netstat命令看到连接有很多国外IP

快乐的2 长春易申软件有限公司 技术总监  2013-07-11 10:41:14

使用命令netstat -aop | grep 62013 > ~/netstat-aop-62013.log文件

文件内容如下:

tcp 0 0 *:62013 *:* LISTEN 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 43.148.51.119.adsl-po:18121 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 104.47.48.119.adsl-po:12595 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 3.168.17.175.adsl-poo:51707 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:38611 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 238.165.17.175.adsl-p:55066 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:11475 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:13057 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:13058 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:29648 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 3.168.17.175.adsl-poo:55286 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 22.47.48.119.adsl-poo:22853 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:37340 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 146.171.17.175.adsl-p:34406 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 22.47.48.119.adsl-pool:5184 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 65.44.48.119.adsl-poo:16660 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:13577 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 14.47.48.119.adsl-poo:24665 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 165.166.17.175.adsl-p:20569 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 146.171.17.175.adsl-p:vstat ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 55.168.17.175.adsl-po:22980 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 246.171.17.17:gxs-data-port ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 165.166.17.175.adsl-p:16965 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-pool:dwf ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-po:12459 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 146.171.17.175.adsl-p:61054 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:13072 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 54.169.17.175.adsl-po:21214 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:32451 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 219.170.17.175.adsl-p:17715 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:13074 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 65.44.48.119.ads:lm-sserver ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 3.168.17.175.adsl-poo:55271 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 165.166.17.175.adsl-p:57166 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 104.47.48.119.adsl-po:29480 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 54.169.17.175.adsl-po:22224 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 246.171.17.175.adsl-p:11284 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 43.148.51.119.adsl-po:30423 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 165.166.17.175.a:tarantella ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 104.47.48.119.adsl-poo:6189 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 146.171.17.175.adsl-p:61042 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-po:11160 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 65.44.48.119.adsl-pool:9784 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 165.166.17.175.adsl-p:51319 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:13093 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 22.47.48.119.adsl-poo:18029 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-po:11676 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-poo:6812 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 51.168.17.175.:bex-webadmin ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-po:18333 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 ::ffff:124.235.120.15:53609 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-po:18334 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 165.166.17.175.adsl-p:39280 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 130.167.17.175.adsl-p:11353 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 246.171.17.175.adsl-po:6945 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 51.168.17.175.adsl-poo:6119 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:28414 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 246.171.17.175.adsl-po:7712 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 51.168.17.175.adsl-poo:6118 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-po:11153 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 22.47.48.119.adsl-poo:18789 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 51.168.17.175.adsl-poo:6117 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 104.47.48.119.adsl-po:10520 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 227.46.48.119.adsl-po:16530 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 22.47.48.119.adsl-poo:18016 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:40955 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 43.148.51.119.adsl-po:61924 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 22.47.48.119.adsl-pool.:cbt ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 104.47.48.119.ad:trellisagt ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 246.171.17.175.adsl-p:10553 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 104.47.48.119.adsl-poo:8706 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:10036 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 146.171.17.175.:tw-auth-key ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 142.45.48.119.adsl-po:47077 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 94.47.48.119.adsl-poo:12848 FIN_WAIT2 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 14.47.48.119.adsl-poo:19040 ESTABLISHED 14530/ssh off (0.00/0/0)
tcp 0 0 ::ffff:192.168.10.21:62013 65.44.48.119.adsl-pool:9773 ESTABLISHED

其中头几个IP都是国外的,而此服务器是给国内特定用户使用的.
不知道这种情况是属于被攻击中还是正常现象???
由于长度限制只贴出了前几行的网络连接信息,
62013端口的连接文本有93KB大小, 774行(连接)
请大神解释.
...全文
571 点赞 收藏 5
写回复
5 条回复
切换为时间正序
当前发帖距今超过3年,不再开放新的回复
发表回复
快乐的2 2013-07-11
这个是做外网访问的,有自己的域名,62013这个端口对应的是内网的数据库端口. 现在想知道这些国外IP是不是不是正常访问?
回复
pix77 2013-07-11
引用 3 楼 zyb134506 的回复:
端口是自己开的, 但连接的IP不对,这个是属于公司内部的应用服务器,业务只是对内部人员使用的. 不应该用那么多国外IP建立连接
如果是给内网,就在iptables上面做规则,允许内网网段
回复
快乐的2 2013-07-11
端口是自己开的, 但连接的IP不对,这个是属于公司内部的应用服务器,业务只是对内部人员使用的. 不应该用那么多国外IP建立连接
回复
pix77 2013-07-11
这台服务器上面是否需要开放这个端口呢? 如果不是,估计已经被黑了
回复
快乐的2 2013-07-11
PID:14530/SSH这个做的是端口映射,映射到内网的某台机器上.
回复
相关推荐
发帖
系统维护与使用区
创建于2007-08-27

1.9w+

社区成员

系统使用、管理、维护问题。可以是Ubuntu, Fedora, Unix等等
申请成为版主
帖子事件
创建了帖子
2013-07-11 10:41
社区公告
暂无公告