查看: 154|回复: 19

HZ 警示邮件有收到吗

[复制链接]

112

主题

205

回帖

798

积分

高级会员

积分
798
发表于 2020-8-13 16:40:01 | 显示全部楼层 |阅读模式
本帖最后由 2019年 于 2020-8-13 16:41 编辑

Abuse Message [AbuseID:7350CD:22]

We have received a security alert from the German Federal Office for Information Security (BSI).
Please see the original report included below for details.

We are automatically forwarding this alert on to you, for your information.
You do not need to send us, or the BSI, a response.
However, we do ask that you check the alert and to resolve any potential issues.

Additional information is provided with the HOWTOs referenced in the report.
In case of further questions, please contact [email protected] and keep the ticket number of the original report [CB-Report#...] in the subject line. Do not reply to [email protected][/url]> as this is just the sender address for the reports and messages sent to this address will not be read.

Kind regards

Abuse Team

Dear Sir or Madam,
>
> the Portmapper service (portmap, rpcbind) is required for mapping RPC
> requests to a network service. The Portmapper service is needed e.g.
> for mounting network shares using the Network File System (NFS).
> The Portmapper service runs on port 111 tcp/udp.
>
> In addition to being abused for DDoS reflection attacks, the
> Portmapper service can be used by attackers to obtain information
> on the target network like available RPC services or network shares.
>
> Over the past months, systems responding to Portmapper requests from
> anywhere on the Internet have been increasingly abused DDoS reflection
> attacks against third parties.
>
> Affected systems on your network:
>
> Format: ASN | IP | Timestamp (UTC) | RPC response
>  24940 | 138.201.254.13 | 2020-08-11 07:17:14 | 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp; 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp;
>  24940 | 138.201.254.15 | 2020-08-11 08:10:57 | 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp; 100000 4 111/udp; 100000 3 111/udp; 100000 2 111/udp;
>
> We would like to ask you to check this issue and take appropriate
> steps to secure the Portmapper services on the affected systems or
> notify your customers accordingly.
>
> If you have recently solved the issue but received this notification
> again, please note the timestamp included below. You should not
> receive any further notifications with timestamps after the issue
> has been solved.
>
> Additional information on this notification, advice on how to fix
> reported issues and answers to frequently asked questions:
> ;
>
> This message is digitally signed using PGP.
> Information on the signature key is available at:
> ;
>
> Please note:
> This is an automatically generated message. Replies to the
> sender address [email protected][/url]> will NOT be read
> but silently be discarded. In case of questions, please contact
> [email protected][/url]> and keep the ticket number [CB-Report#...]
> of this message in the subject line.
>
> !! Please make sure to consult our HOWTOs and FAQ available at
> !! ; first.
>
>
>
> Mit freundlichen Gren / Kind regards
> Team CERT-Bund
>
> Bundesamt fr Sicherheit in der Informationstechnik
> Federal Office for Information Security (BSI)
> Referat OC23 - CERT-Bund
> Godesberger Allee 185-189, 53175 Bonn, Germany

没看明白他们想干啥,这是要封帐户还是干啥
回复

使用道具 举报

3

主题

162

回帖

413

积分

中级会员

积分
413
发表于 2020-8-13 17:04:50 | 显示全部楼层
意思是你开的服务有可能被用于反射,提醒你检查。。你也可以不回复。
如果是接到的投诉,一般才会让你在期限内回复。

---

We have indications that there was an attack from your server.
Please take all necessary measures to avoid this in the future and to solve the issue.

We also request that you send a short response to us. This response should contain information about how this could have happened and what you intend to do about it.
In the event that the following steps are not completed successfully, your server can be blocked at any time after the xxxx-xx-xx xx:xx:xx.

How to proceed:
- Solve the issue
- Test if the issue still exists by using the following link: http://abuse.hetzner.com/retries/?token=xxxxxxx
- After successfully testing that the issue is resolved, send us a statement by using the following link: http://abuse.hetzner.com/statements/xxxxxxxxx
回复

使用道具 举报

553

主题

4323

回帖

1万

积分

论坛元老

积分
10477
发表于 2020-8-13 16:44:03 | 显示全部楼层
这不跟明显嘛,ddos别人
回复

使用道具 举报

112

主题

205

回帖

798

积分

高级会员

积分
798
 楼主| 发表于 2020-8-13 16:44:35 | 显示全部楼层

suantong 发表于 2020-8-13 16:44

这不跟明显嘛,ddos别人

我没有啊,新开的机器就安装了CPANEL,啥也没干呀
回复

使用道具 举报

13

主题

184

回帖

481

积分

中级会员

积分
481
发表于 2020-8-13 16:44:00 | 显示全部楼层
1.你发包了。2.别人拿你机器的111做udp反射了。
回复

使用道具 举报

553

主题

4323

回帖

1万

积分

论坛元老

积分
10477
发表于 2020-8-13 16:45:50 | 显示全部楼层
端口111在干嘛?
回复

使用道具 举报

112

主题

205

回帖

798

积分

高级会员

积分
798
 楼主| 发表于 2020-8-13 16:45:59 | 显示全部楼层

ealkeq 发表于 2020-8-13 16:45

1.你发包了。2.别人拿你机器的111做udp反射了。

才新开几天的机器这么快就被黑了? 我没有发包,就搬家备份到HZ了。 现在要怎么弄哈
回复

使用道具 举报

44

主题

959

回帖

2110

积分

金牌会员

积分
2110
发表于 2020-8-13 16:47:07 | 显示全部楼层
和客服说明情况,表示你是被黑了
然后改ssh端口,并且关闭密码登录改成证书登录
回复

使用道具 举报

112

主题

205

回帖

798

积分

高级会员

积分
798
 楼主| 发表于 2020-8-13 16:45:00 | 显示全部楼层

suantong 发表于 2020-8-13 16:45

端口111在干嘛?

我那天不小心关掉了HZ自带的firewall,我没用111端口,我刚才去把firewall给打开了
回复

使用道具 举报

13

主题

184

回帖

481

积分

中级会员

积分
481
发表于 2020-8-13 16:48:48 | 显示全部楼层

2019年 发表于 2020-8-13 16:47

才新开几天的机器这么快就被黑了? 我没有发包,就搬家备份到HZ了。 现在要怎么弄哈 ...

关了111 udp端口即可
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

关注公众号

相关侵权、举报、投诉及建议等,请发 E-mail:admin@discuz.vip

Powered by Discuz! X5.0 © 2001-2026 Discuz! Team.

在本版发帖
关注公众号
返回顶部