我做的最愚蠢的事情
最近折腾游戏服务器。管理博客减少。
这个月暂停了镜像服务,以后也会暂停,主要是我评估了一下目前个人所处形势,认为我需要其他东西的想法更强烈。而且学校有其他的也要服务器资金支持,我会优先支持学校。
问题在于这个镜像域名,我进了后台修改了指向为我的博客,于是悲剧发生了。从那以后(开始我都不知道是从那以后),我的博客就瘫了。每天勉强SSH进后台uptime都是70+,开始以为MySQL数据库坏了,我执行检查也没看出啥。
直到前天我终于忍不住了,给KVMLA提交了ticket,老板是Kevin,真的很好的人。他给我的反馈是:
CC攻击?他当时说可能是这个。我心想我的博客怎么可能被人盯上,于是我正好去上课让他帮忙看一下。反馈是:
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 |
恭喜你 被人爱上了 [root@cicku ~]# tcpdump -n -c100 device eth0 entered promiscuous mode tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes 03:01:39.216962 IP 216.115.79.54.13569 > 108.171.206.136.http: Flags [S], seq 4049624371, win 14600, options [mss 1380,sackOK,TS val 4113361566 ecr 0,nop,wscale 6], length 0 03:01:39.216983 IP 108.171.206.136.http > 216.115.79.54.13569: Flags [R.], seq 0, ack 4049624372, win 0, length 0 03:01:39.218399 IP 12.170.20.130.26272 > 108.171.206.136.http: Flags [S], seq 3143098040, win 5840, options [mss 1460,sackOK,TS val 716293179 ecr 0,nop,wscale 7], length 0 03:01:39.218407 IP 108.171.206.136.http > 12.170.20.130.26272: Flags [R.], seq 0, ack 3143098041, win 0, length 0 03:01:39.221621 IP 64.58.22.145.52479 > 108.171.206.136.http: Flags [S], seq 2873337787, win 5840, options [mss 1460,sackOK,TS val 784593637 ecr 0,nop,wscale 7], length 0 03:01:39.221635 IP 108.171.206.136.http > 64.58.22.145.52479: Flags [R.], seq 0, ack 2873337788, win 0, length 0 03:01:39.226505 IP 216.115.79.54.5091 > 108.171.206.136.http: Flags [S], seq 1175972905, win 14600, options [mss 1380,sackOK,TS val 4113361584 ecr 0,nop,wscale 6], length 0 03:01:39.226518 IP 108.171.206.136.http > 216.115.79.54.5091: Flags [R.], seq 0, ack 1175972906, win 0, length 0 03:01:39.256995 IP 12.170.20.130.26273 > 108.171.206.136.http: Flags [S], seq 3144619427, win 5840, options [mss 1460,sackOK,TS val 716293219 ecr 0,nop,wscale 7], length 0 03:01:39.257015 IP 108.171.206.136.http > 12.170.20.130.26273: Flags [R.], seq 0, ack 3144619428, win 0, length 0 03:01:39.261619 IP 64.58.22.145.52480 > 108.171.206.136.http: Flags [S], seq 2878586565, win 5840, options [mss 1460,sackOK,TS val 784593677 ecr 0,nop,wscale 7], length 0 03:01:39.261628 IP 108.171.206.136.http > 64.58.22.145.52480: Flags [R.], seq 0, ack 2878586566, win 0, length 0 03:01:39.286864 IP 67.222.96.48.48822 > 108.171.206.136.http: Flags [S], seq 3412290615, win 14600, options [mss 1460,sackOK,TS val 1745252601 ecr 0,nop,wscale 7], length 0 03:01:39.286896 IP 108.171.206.136.http > 67.222.96.48.48822: Flags [R.], seq 0, ack 3412290616, win 0, length 0 03:01:39.291761 IP 67.222.96.48.48823 > 108.171.206.136.http: Flags [S], seq 2807331095, win 14600, options [mss 1460,sackOK,TS val 1745252606 ecr 0,nop,wscale 7], length 0 03:01:39.291771 IP 108.171.206.136.http > 67.222.96.48.48823: Flags [R.], seq 0, ack 2807331096, win 0, length 0 03:01:39.294694 IP 12.170.20.130.26274 > 108.171.206.136.http: Flags [S], seq 3149748724, win 5840, options [mss 1460,sackOK,TS val 716293257 ecr 0,nop,wscale 7], length 0 03:01:39.294703 IP 108.171.206.136.http > 12.170.20.130.26274: Flags [R.], seq 0, ack 3149748725, win 0, length 0 03:01:39.296691 IP 67.222.96.48.48824 > 108.171.206.136.http: Flags [S], seq 2619376269, win 14600, options [mss 1460,sackOK,TS val 1745252611 ecr 0,nop,wscale 7], length 0 03:01:39.296699 IP 108.171.206.136.http > 67.222.96.48.48824: Flags [R.], seq 0, ack 2619376270, win 0, length 0 03:01:39.301635 IP 64.58.22.145.52481 > 108.171.206.136.http: Flags [S], seq 2884655911, win 5840, options [mss 1460,sackOK,TS val 784593717 ecr 0,nop,wscale 7], length 0 03:01:39.301650 IP 108.171.206.136.http > 64.58.22.145.52481: Flags [R.], seq 0, ack 2884655912, win 0, length 0 03:01:39.301656 IP 67.222.96.48.48825 > 108.171.206.136.http: Flags [S], seq 3561162375, win 14600, options [mss 1460,sackOK,TS val 1745252616 ecr 0,nop,wscale 7], length 0 03:01:39.301660 IP 108.171.206.136.http > 67.222.96.48.48825: Flags [R.], seq 0, ack 3561162376, win 0, length 0 03:01:39.306615 IP 67.222.96.48.48826 > 108.171.206.136.http: Flags [S], seq 4043021164, win 14600, options [mss 1460,sackOK,TS val 1745252621 ecr 0,nop,wscale 7], length 0 03:01:39.306624 IP 108.171.206.136.http > 67.222.96.48.48826: Flags [R.], seq 0, ack 4043021165, win 0, length 0 03:01:39.308213 IP 209.133.52.66.23267 > 108.171.206.136.http: Flags [S], seq 485178541, win 65535, options [mss 1460,nop,wscale 6,sackOK,TS val 3232550690 ecr 0], length 0 03:01:39.308221 IP 108.171.206.136.http > 209.133.52.66.23267: Flags [R.], seq 0, ack 485178542, win 0, length 0 03:01:39.311613 IP 67.222.96.48.48827 > 108.171.206.136.http: Flags [S], seq 3292005470, win 14600, options [mss 1460,sackOK,TS val 1745252626 ecr 0,nop,wscale 7], length 0 03:01:39.311621 IP 108.171.206.136.http > 67.222.96.48.48827: Flags [R.], seq 0, ack 3292005471, win 0, length 0 03:01:39.316612 IP 67.222.96.48.48828 > 108.171.206.136.http: Flags [S], seq 268429752, win 14600, options [mss 1460,sackOK,TS val 1745252631 ecr 0,nop,wscale 7], length 0 03:01:39.316623 IP 108.171.206.136.http > 67.222.96.48.48828: Flags [R.], seq 0, ack 268429753, win 0, length 0 03:01:39.321603 IP 67.222.96.48.48829 > 108.171.206.136.http: Flags [S], seq 3981868761, win 14600, options [mss 1460,sackOK,TS val 1745252636 ecr 0,nop,wscale 7], length 0 03:01:39.321611 IP 108.171.206.136.http > 67.222.96.48.48829: Flags [R.], seq 0, ack 3981868762, win 0, length 0 03:01:39.326607 IP 67.222.96.48.48830 > 108.171.206.136.http: Flags [S], seq 3253163376, win 14600, options [mss 1460,sackOK,TS val 1745252641 ecr 0,nop,wscale 7], length 0 03:01:39.326616 IP 108.171.206.136.http > 67.222.96.48.48830: Flags [R.], seq 0, ack 3253163377, win 0, length 0 03:01:39.331614 IP 67.222.96.48.48831 > 108.171.206.136.http: Flags [S], seq 1571554179, win 14600, options [mss 1460,sackOK,TS val 1745252646 ecr 0,nop,wscale 7], length 0 03:01:39.331628 IP 108.171.206.136.http > 67.222.96.48.48831: Flags [R.], seq 0, ack 1571554180, win 0, length 0 03:01:39.332993 IP 12.170.20.130.26275 > 108.171.206.136.http: Flags [S], seq 3148832827, win 5840, options [mss 1460,sackOK,TS val 716293294 ecr 0,nop,wscale 7], length 0 03:01:39.333001 IP 108.171.206.136.http > 12.170.20.130.26275: Flags [R.], seq 0, ack 3148832828, win 0, length 0 03:01:39.341813 IP 64.58.22.145.52482 > 108.171.206.136.http: Flags [S], seq 2873423097, win 5840, options [mss 1460,sackOK,TS val 784593757 ecr 0,nop,wscale 7], length 0 03:01:39.341830 IP 108.171.206.136.http > 64.58.22.145.52482: Flags [R.], seq 0, ack 2873423098, win 0, length 0 03:01:39.345685 IP 50.97.161.227.39276 > 108.171.206.136.http: Flags [S], seq 3962378267, win 5840, options [mss 1460,sackOK,TS val 1892565064 ecr 0,nop,wscale 7], length 0 03:01:39.345710 IP 108.171.206.136.http > 50.97.161.227.39276: Flags [R.], seq 0, ack 3962378268, win 0, length 0 03:01:39.353163 IP 137.100.97.30.27391 > 108.171.206.136.http: Flags [S], seq 1995632884, win 32768, options [mss 1380,nop,wscale 0,nop,nop,TS val 1524334459 ecr 0,sackOK,eol], length 0 03:01:39.353190 IP 108.171.206.136.http > 137.100.97.30.27391: Flags [R.], seq 0, ack 1995632885, win 0, length 0 03:01:39.371510 IP 12.170.20.130.26276 > 108.171.206.136.http: Flags [S], seq 3155481000, win 5840, options [mss 1460,sackOK,TS val 716293333 ecr 0,nop,wscale 7], length 0 03:01:39.371530 IP 108.171.206.136.http > 12.170.20.130.26276: Flags [R.], seq 0, ack 3155481001, win 0, length 0 03:01:39.382680 IP 64.58.22.145.52483 > 108.171.206.136.http: Flags [S], seq 2888676472, win 5840, options [mss 1460,sackOK,TS val 784593798 ecr 0,nop,wscale 7], length 0 03:01:39.382699 IP 108.171.206.136.http > 64.58.22.145.52483: Flags [R.], seq 0, ack 2888676473, win 0, length 0 03:01:39.388945 IP 170.235.245.53.22720 > 108.171.206.136.http: Flags [S], seq 339514927, win 65535, options [mss 1460,sackOK,TS val 1049748588 ecr 0,wscale 0,eol], length 0 03:01:39.388965 IP 108.171.206.136.http > 170.235.245.53.22720: Flags [R.], seq 0, ack 339514928, win 0, length 0 03:01:39.403620 IP 67.222.96.48.48833 > 108.171.206.136.http: Flags [S], seq 781112182, win 14600, options [mss 1460,sackOK,TS val 1745252718 ecr 0,nop,wscale 7], length 0 03:01:39.403642 IP 108.171.206.136.http > 67.222.96.48.48833: Flags [R.], seq 0, ack 781112183, win 0, length 0 03:01:39.408579 IP 67.222.96.48.48834 > 108.171.206.136.http: Flags [S], seq 1301686677, win 14600, options [mss 1460,sackOK,TS val 1745252723 ecr 0,nop,wscale 7], length 0 03:01:39.408600 IP 108.171.206.136.http > 67.222.96.48.48834: Flags [R.], seq 0, ack 1301686678, win 0, length 0 03:01:39.409048 IP 12.170.20.130.26277 > 108.171.206.136.http: Flags [S], seq 3154526212, win 5840, options [mss 1460,sackOK,TS val 716293371 ecr 0,nop,wscale 7], length 0 03:01:39.409058 IP 108.171.206.136.http > 12.170.20.130.26277: Flags [R.], seq 0, ack 3154526213, win 0, length 0 03:01:39.501154 IP 67.222.96.48.48835 > 108.171.206.136.http: Flags [S], seq 486312508, win 14600, options [mss 1460,sackOK,TS val 1745252727 ecr 0,nop,wscale 7], length 0 03:01:39.501173 IP 108.171.206.136.http > 67.222.96.48.48835: Flags [R.], seq 0, ack 486312509, win 0, length 0 03:01:39.501179 IP 209.133.52.66.62436 > 108.171.206.136.http: Flags [S], seq 2323769018, win 65535, options [mss 1460,nop,wscale 6,sackOK,TS val 3232550802 ecr 0], length 0 03:01:39.501182 IP 108.171.206.136.http > 209.133.52.66.62436: Flags [R.], seq 0, ack 2323769019, win 0, length 0 03:01:39.501186 IP 64.58.22.145.52484 > 108.171.206.136.http: Flags [S], seq 2886502275, win 5840, options [mss 1460,sackOK,TS val 784593839 ecr 0,nop,wscale 7], length 0 03:01:39.501189 IP 108.171.206.136.http > 64.58.22.145.52484: Flags [R.], seq 0, ack 2886502276, win 0, length 0 03:01:39.501191 IP 70.168.52.194.16359 > 108.171.206.136.http: Flags [S], seq 2665727304, win 5840, options [mss 1460,sackOK,TS val 3937714858 ecr 0,nop,wscale 7], length 0 03:01:39.501194 IP 108.171.206.136.http > 70.168.52.194.16359: Flags [R.], seq 0, ack 2665727305, win 0, length 0 03:01:39.501198 IP 12.170.20.130.26278 > 108.171.206.136.http: Flags [S], seq 3153474481, win 5840, options [mss 1460,sackOK,TS val 716293409 ecr 0,nop,wscale 7], length 0 03:01:39.501201 IP 108.171.206.136.http > 12.170.20.130.26278: Flags [R.], seq 0, ack 3153474482, win 0, length 0 03:01:39.501204 IP 206.127.15.46.40810 > 108.171.206.136.http: Flags [S], seq 736164723, win 5840, options [mss 1436,sackOK,TS val 596230987 ecr 0,nop,wscale 7], length 0 03:01:39.501208 IP 108.171.206.136.http > 206.127.15.46.40810: Flags [R.], seq 0, ack 736164724, win 0, length 0 03:01:39.506535 IP 67.222.96.48.48836 > 108.171.206.136.http: Flags [S], seq 911646299, win 14600, options [mss 1460,sackOK,TS val 1745252820 ecr 0,nop,wscale 7], length 0 03:01:39.506548 IP 108.171.206.136.http > 67.222.96.48.48836: Flags [R.], seq 0, ack 911646300, win 0, length 0 03:01:39.507562 IP 66.162.133.82.22764 > 108.171.206.136.http: Flags [S], seq 1284329085, win 64240, options [mss 1460,nop,nop,sackOK], length 0 03:01:39.507570 IP 108.171.206.136.http > 66.162.133.82.22764: Flags [R.], seq 0, ack 1284329086, win 0, length 0 03:01:39.530661 IP 67.222.96.48.48837 > 108.171.206.136.http: Flags [S], seq 4083327187, win 14600, options [mss 1460,sackOK,TS val 1745252825 ecr 0,nop,wscale 7], length 0 03:01:39.530683 IP 108.171.206.136.http > 67.222.96.48.48837: Flags [R.], seq 0, ack 4083327188, win 0, length 0 03:01:39.530690 IP 70.168.52.194.11975 > 108.171.206.136.http: Flags [S], seq 4219363198, win 5840, options [mss 1460,sackOK,TS val 3937714946 ecr 0,nop,wscale 7], length 0 03:01:39.530694 IP 108.171.206.136.http > 70.168.52.194.11975: Flags [R.], seq 0, ack 4219363199, win 0, length 0 03:01:39.538745 IP 67.222.96.48.48838 > 108.171.206.136.http: Flags [S], seq 288979042, win 14600, options [mss 1460,sackOK,TS val 1745252849 ecr 0,nop,wscale 7], length 0 03:01:39.538767 IP 108.171.206.136.http > 67.222.96.48.48838: Flags [R.], seq 0, ack 288979043, win 0, length 0 03:01:39.540258 IP 12.170.20.130.26279 > 108.171.206.136.http: Flags [S], seq 3149504118, win 5840, options [mss 1460,sackOK,TS val 716293501 ecr 0,nop,wscale 7], length 0 03:01:39.540267 IP 108.171.206.136.http > 12.170.20.130.26279: Flags [R.], seq 0, ack 3149504119, win 0, length 0 03:01:39.541861 IP 64.58.22.145.52485 > 108.171.206.136.http: Flags [S], seq 2875381833, win 5840, options [mss 1460,sackOK,TS val 784593957 ecr 0,nop,wscale 7], length 0 03:01:39.541869 IP 108.171.206.136.http > 64.58.22.145.52485: Flags [R.], seq 0, ack 2875381834, win 0, length 0 03:01:39.543490 IP 67.222.96.48.48839 > 108.171.206.136.http: Flags [S], seq 1336356878, win 14600, options [mss 1460,sackOK,TS val 1745252857 ecr 0,nop,wscale 7], length 0 03:01:39.543499 IP 108.171.206.136.http > 67.222.96.48.48839: Flags [R.], seq 0, ack 1336356879, win 0, length 0 03:01:39.548493 IP 67.222.96.48.48840 > 108.171.206.136.http: Flags [S], seq 3052905919, win 14600, options [mss 1460,sackOK,TS val 1745252862 ecr 0,nop,wscale 7], length 0 03:01:39.548507 IP 108.171.206.136.http > 67.222.96.48.48840: Flags [R.], seq 0, ack 3052905920, win 0, length 0 03:01:39.553091 IP 70.168.52.194.47330 > 108.171.206.136.http: Flags [S], seq 1820703717, win 5840, options [mss 1460,sackOK,TS val 3937714977 ecr 0,nop,wscale 7], length 0 03:01:39.553106 IP 108.171.206.136.http > 70.168.52.194.47330: Flags [R.], seq 0, ack 1820703718, win 0, length 0 03:01:39.553529 IP 67.222.96.48.48841 > 108.171.206.136.http: Flags [S], seq 1697118024, win 14600, options [mss 1460,sackOK,TS val 1745252867 ecr 0,nop,wscale 7], length 0 03:01:39.553537 IP 108.171.206.136.http > 67.222.96.48.48841: Flags [R.], seq 0, ack 1697118025, win 0, length 0 03:01:39.558511 IP 67.222.96.48.48842 > 108.171.206.136.http: Flags [S], seq 1452530693, win 14600, options [mss 1460,sackOK,TS val 1745252872 ecr 0,nop,wscale 7], length 0 03:01:39.558523 IP 108.171.206.136.http > 67.222.96.48.48842: Flags [R.], seq 0, ack 1452530694, win 0, length 0 03:01:39.562125 IP 70.164.126.62.15179 > 108.171.206.136.http: Flags [S], seq 791542565, win 5840, options [mss 1380,sackOK,TS val 924724625 ecr 0,nop,wscale 7], length 0 03:01:39.562136 IP 108.171.206.136.http > 70.164.126.62.15179: Flags [R.], seq 0, ack 791542566, win 0, length 0 03:01:39.573553 IP 50.2.3.2.59937 > 108.171.206.136.http: Flags [S], seq 2248709443, win 5840, options [mss 1460,sackOK,TS val 2785888440 ecr 0,nop,wscale 7], length 0 03:01:39.573584 IP 108.171.206.136.http > 50.2.3.2.59937: Flags [R.], seq 0, ack 2248709444, win 0, length 0 03:01:39.574574 IP 70.168.52.194.17389 > 108.171.206.136.http: Flags [S], seq 4277685727, win 5840, options [mss 1460,sackOK,TS val 3937714998 ecr 0,nop,wscale 7], length 0 03:01:39.574582 IP 108.171.206.136.http > 70.168.52.194.17389: Flags [R.], seq 0, ack 4277685728, win 0, length 0 100 packets captured 100 packets received by filter 0 packets dropped by kernel device eth0 left promiscuous mode |
我一看好奇怪啊。
然后Kevin一语道破天机:
根据/var/log/httpd/access_log
日志记录全部是centos的mirror请求
我瞬间明白了些什么··················
我把一个日PV过百万的站的流量全导入我的博客了。
准备期末先到这里吧。

Mozilla/5.0 (Windows NT 5.1; rv:18.0) Gecko/20100101 Firefox/18.0
百万啊 恭喜
Mozilla/5.0 (Windows NT 5.1; rv:17.0) Gecko/20100101 Firefox/17.0
不要恭喜我啊。。那会儿我郁闷死了