langtult
03-10-2008, 02:42
Gần đây (kể từ ngày 27/9) máy mình bắt đầu báo bị tấn công DDos. Máy dùng KIS 7.0 và cứ sau 20h đêm là xuất hiện các cảnh báo của KIS như sau (mình chỉ đưa ra một số thôi):
10/3/2008 1:45:44 AM DoS.Generic.ICMPFlood! Attacker's IP address: 58.186.185.3. Protocol/service: ICMP . Time: 10/3/2008 1:45:44 AM
10/3/2008 1:45:44 AM DoS.Generic.ICMPFlood! Attacker's IP address: 222.254.193.199. Protocol/service: ICMP . Time: 10/3/2008 1:45:44 AM
10/3/2008 1:45:44 AM DoS.Generic.ICMPFlood! Attacker's IP address: 58.186.137.97. Protocol/service: ICMP . Time: 10/3/2008 1:45:44 AM
10/3/2008 1:45:58 AM DoS.Generic.ICMPFlood! Attacker's IP address: 118.68.248.178. Protocol/service: ICMP . Time: 10/3/2008 1:45:58 AM
10/3/2008 1:45:58 AM DoS.Generic.ICMPFlood! Attacker's IP address: 118.68.250.154. Protocol/service: ICMP . Time: 10/3/2008 1:45:58 AM
10/3/2008 1:45:58 AM DoS.Generic.ICMPFlood! Attacker's IP address: 118.68.250.49. Protocol/service: ICMP . Time: 10/3/2008 1:45:58 AM
10/3/2008 1:58:25 AM DoS.Generic.SYNFlood! Attacker's IP address: 118.68.240.199. Protocol/service: TCP on local port 2967. Time: 10/3/2008 1:58:25 AM
10/3/2008 2:03:14 AM DoS.Generic.ICMPFlood! Attacker's IP address: 58.186.137.76. Protocol/service: ICMP . Time: 10/3/2008 2:03:14 AM
10/3/2008 2:03:14 AM DoS.Generic.ICMPFlood! Attacker's IP address: 58.186.185.13. Protocol/service: ICMP . Time: 10/3/2008 2:03:14 AM
10/3/2008 2:06:29 AM DoS.Generic.SYNFlood! Attacker's IP address: 58.186.185.13. Protocol/service: TCP on local port 1433. Time: 10/3/2008 2:06:29 AM
10/3/2008 2:06:29 AM DoS.Generic.SYNFlood! Attacker's IP address: 58.186.137.76. Protocol/service: TCP on local port 1433. Time: 10/3/2008 2:06:29 AM
10/3/2008 2:07:03 AM DoS.Generic.SYNFlood! Attacker's IP address: 58.215.93.7. Protocol/service: TCP on local port 2967. Time: 10/3/2008 2:07:03 AM
10/3/2008 2:22:25 AM DoS.Generic.ICMPFlood! Attacker's IP address: 58.186.185.48. Protocol/service: ICMP . Time: 10/3/2008 2:22:25 AM
10/3/2008 2:22:25 AM DoS.Generic.ICMPFlood! Attacker's IP address: 58.186.74.13. Protocol/service: ICMP . Time: 10/3/2008 2:22:25 AM
10/3/2008 2:22:25 AM DoS.Generic.ICMPFlood! Attacker's IP address: 118.69.18.30. Protocol/service: ICMP . Time: 10/3/2008 2:22:25 AM
Sau khi thực hiện Whois một số IP mình thấy chúng đều được cấp bởi Asia Pacific Network Information Centre (APNIC) sau đó tiếp tục vào APNIC để kiểm tra mình có một số thông tin về các một số IP như sau:
222.254.193.199
inetnum: 222.254.144.0 - 222.254.207.255
netname: HCMPT-NET
country: vn
descr: HoChiMinh City Post and Telecom Company
admin-c: NG102-AP
tech-c: DQ79-AP
status: ALLOCATED NON-PORTABLE
changed: hm-changed@vnnic.net.vn 20070511
mnt-by: MAINT-VN-VNPT
source: APNIC
person: Nguyen Giang Do
nic-hdl: NG102-AP
e-mail: giangdo@hcmpt.com.vn
address: 125 Hai Ba Trung, Dist 1, HCMC
phone: +84-882-46476
fax-no: +84-882-46482
country: vn
changed: hm-changed@vnnic.net.vn 20061025
mnt-by: MAINT-VN-VNPT
source: APNIC
person: Duong Quoc Viet
nic-hdl: DQ79-AP
e-mail: quocviet@hcmpt.com.vn
address: 125 Hai Ba Trung, Dist1, HCMC
phone: +84-882-46480
fax-no: +84-882-46482
country: vn
changed: hm-changed@vnnic.net.vn 20061025
mnt-by: MAINT-VN-VNPT
source: APNI
58.215.93.7
inetnum: 58.208.0.0 - 58.223.255.255
netname: CHINANET-JS
descr: CHINANET jiangsu province network
descr: China Telecom
descr: A12,Xin-Jie-Kou-Wai Street
descr: Beijing 100088
country: CN
admin-c: CH93-AP
tech-c: CJ186-AP
mnt-by: APNIC-HM
mnt-lower: MAINT-CHINANET-JS
mnt-routes: MAINT-CHINANET-JS
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation's account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
status: ALLOCATED PORTABLE
changed: hm-changed@apnic.net 20050624
source: APNIC
role: CHINANET JIANGSU
address: No.268,Hanzhong Road,Nanjing 210029
country: CN
phone: +86-25-6588783
fax-no: +86-25-6588740
e-mail: ip@jsinfo.net
trouble: send anti-spam reports to spam@jsinfo.net
trouble: send abuse reports to abuse@jsinfo.net
trouble: times in GMT+8
admin-c: CH360-AP
tech-c: CS306-AP
tech-c: CN142-AP
nic-hdl: CJ186-AP
remarks: www.jsinfo.net
notify: ip@jsinfo.net
mnt-by: MAINT-CHINANET-JS
changed: dns@ptt.js.cn 20020530
changed: ip@jsinfo.net 20021213
source: APNIC
person: Chinanet Hostmaster
nic-hdl: CH93-AP
e-mail: anti-spam@ns.chinanet.cn.net
address: No.31 ,jingrong street,beijing
address: 100032
phone: +86-10-58501724
fax-no: +86-10-58501724
country: CN
changed: dingsy@cndata.com 20070416
mnt-by: MAINT-CHINANET
source: APNIC
58.186.137.76
inetnum: 58.186.128.0 - 58.186.143.255
netname: FPT-NET
country: VN
descr: IP range for FPT Broadband Service
descr: 75 Tran Hung Dao, Hoan Kiem, Ha Noi
admin-c: LPC5-AP
tech-c: LPC5-AP
status: ASSIGNED NON-PORTABLE
remarks: For spamming matters, mail to abuse@fpt.vn
changed: hm-changed@vnnic.net.vn 20051130
mnt-by: MAINT-VN-FPT
source: APNIC
person: Liem Pham Cong
nic-hdl: LPC5-AP
e-mail: liempc@fpt.net
address: FPT Telecom
address: 66-68 Vo Van Tan, Dist 3, HCMC
phone: +84-8-9301280
country: VN
changed: hm-changed@vnnic.net.vn 20080128
mnt-by: MAINT-VN-FPT
source: APNIC
58.186.185.13
inetnum: 58.186.176.0 - 58.186.191.255
netname: FPT-NET
country: VN
descr: IP range for FPT Broadband Service
descr: 75 Tran Hung Dao, Hoan Kiem, Ha Noi
admin-c: LPC5-AP
tech-c: LPC5-AP
status: ASSIGNED NON-PORTABLE
remarks: For spamming matters, mail to abuse@fpt.vn
changed: hm-changed@vnnic.net.vn 20051130
mnt-by: MAINT-VN-FPT
source: APNIC
person: Liem Pham Cong
nic-hdl: LPC5-AP
e-mail: liempc@fpt.net
address: FPT Telecom
address: 66-68 Vo Van Tan, Dist 3, HCMC
phone: +84-8-9301280
country: VN
changed: hm-changed@vnnic.net.vn 20080128
mnt-by: MAINT-VN-FPT
source: APNIC
118.68.248.178
inetnum: 118.68.0.0 - 118.68.255.255
netname: IPxDSL-NET
country: vn
descr: Dai IP dong su dung cho ket noi xDSL
admin-c: FHIG2-AP
tech-c: FHIG2-AP
status: ALLOCATED NON-PORTABLE
changed: hm-changed@vnnic.net.vn 20080411
mnt-by: MAINT-VN-FPT
source: APNIC
role: FPT HCMC IPADMIN GROUP
address: 66-68 Vo Van Tan
address: HCMC
country: VN
phone: +84-8-9301280
fax-no: +84-4-7262163
e-mail: abuse@hcm.fpt.vn
trouble: send spam reports to abuse@hcm.fpt.vn
trouble: and abuse reports to abuse@hcm.fpt.vn
admin-c: LPC5-AP
tech-c: LTVL1-AP
nic-hdl: FHIG2-AP
notify: hm-changed@vnnic.net.vn
mnt-by: MAINT-VN-FPT
changed: hm-changed@vnnic.net.vn 20080128
source: APNIC
Đây là mình mới chỉ kiểm tra một số IP. Tất cả đều liên quan tới FPT (mình xài ADSL của FPT, chỉ có một IP từ Trung Quốc). Mình ko rành lắm về vấn đề DDos, nhưng theo mình hiểu và cảnh báo của KIS thì máy mình bị DDos, vậy tại sao lại bị tấn công từ IP của FPT. Mỗi lần như vậy tốc độ net chậm hẳn lại rõ rệt. Bạn nào có thể giải thích và chỉ mình cách khắc phục được không? Xin cám ơn!
[=========> Bổ sung bài viết <=========]
hix! Sao ko thấy ai ra tay giúp hết nè?
10/3/2008 1:45:44 AM DoS.Generic.ICMPFlood! Attacker's IP address: 58.186.185.3. Protocol/service: ICMP . Time: 10/3/2008 1:45:44 AM
10/3/2008 1:45:44 AM DoS.Generic.ICMPFlood! Attacker's IP address: 222.254.193.199. Protocol/service: ICMP . Time: 10/3/2008 1:45:44 AM
10/3/2008 1:45:44 AM DoS.Generic.ICMPFlood! Attacker's IP address: 58.186.137.97. Protocol/service: ICMP . Time: 10/3/2008 1:45:44 AM
10/3/2008 1:45:58 AM DoS.Generic.ICMPFlood! Attacker's IP address: 118.68.248.178. Protocol/service: ICMP . Time: 10/3/2008 1:45:58 AM
10/3/2008 1:45:58 AM DoS.Generic.ICMPFlood! Attacker's IP address: 118.68.250.154. Protocol/service: ICMP . Time: 10/3/2008 1:45:58 AM
10/3/2008 1:45:58 AM DoS.Generic.ICMPFlood! Attacker's IP address: 118.68.250.49. Protocol/service: ICMP . Time: 10/3/2008 1:45:58 AM
10/3/2008 1:58:25 AM DoS.Generic.SYNFlood! Attacker's IP address: 118.68.240.199. Protocol/service: TCP on local port 2967. Time: 10/3/2008 1:58:25 AM
10/3/2008 2:03:14 AM DoS.Generic.ICMPFlood! Attacker's IP address: 58.186.137.76. Protocol/service: ICMP . Time: 10/3/2008 2:03:14 AM
10/3/2008 2:03:14 AM DoS.Generic.ICMPFlood! Attacker's IP address: 58.186.185.13. Protocol/service: ICMP . Time: 10/3/2008 2:03:14 AM
10/3/2008 2:06:29 AM DoS.Generic.SYNFlood! Attacker's IP address: 58.186.185.13. Protocol/service: TCP on local port 1433. Time: 10/3/2008 2:06:29 AM
10/3/2008 2:06:29 AM DoS.Generic.SYNFlood! Attacker's IP address: 58.186.137.76. Protocol/service: TCP on local port 1433. Time: 10/3/2008 2:06:29 AM
10/3/2008 2:07:03 AM DoS.Generic.SYNFlood! Attacker's IP address: 58.215.93.7. Protocol/service: TCP on local port 2967. Time: 10/3/2008 2:07:03 AM
10/3/2008 2:22:25 AM DoS.Generic.ICMPFlood! Attacker's IP address: 58.186.185.48. Protocol/service: ICMP . Time: 10/3/2008 2:22:25 AM
10/3/2008 2:22:25 AM DoS.Generic.ICMPFlood! Attacker's IP address: 58.186.74.13. Protocol/service: ICMP . Time: 10/3/2008 2:22:25 AM
10/3/2008 2:22:25 AM DoS.Generic.ICMPFlood! Attacker's IP address: 118.69.18.30. Protocol/service: ICMP . Time: 10/3/2008 2:22:25 AM
Sau khi thực hiện Whois một số IP mình thấy chúng đều được cấp bởi Asia Pacific Network Information Centre (APNIC) sau đó tiếp tục vào APNIC để kiểm tra mình có một số thông tin về các một số IP như sau:
222.254.193.199
inetnum: 222.254.144.0 - 222.254.207.255
netname: HCMPT-NET
country: vn
descr: HoChiMinh City Post and Telecom Company
admin-c: NG102-AP
tech-c: DQ79-AP
status: ALLOCATED NON-PORTABLE
changed: hm-changed@vnnic.net.vn 20070511
mnt-by: MAINT-VN-VNPT
source: APNIC
person: Nguyen Giang Do
nic-hdl: NG102-AP
e-mail: giangdo@hcmpt.com.vn
address: 125 Hai Ba Trung, Dist 1, HCMC
phone: +84-882-46476
fax-no: +84-882-46482
country: vn
changed: hm-changed@vnnic.net.vn 20061025
mnt-by: MAINT-VN-VNPT
source: APNIC
person: Duong Quoc Viet
nic-hdl: DQ79-AP
e-mail: quocviet@hcmpt.com.vn
address: 125 Hai Ba Trung, Dist1, HCMC
phone: +84-882-46480
fax-no: +84-882-46482
country: vn
changed: hm-changed@vnnic.net.vn 20061025
mnt-by: MAINT-VN-VNPT
source: APNI
58.215.93.7
inetnum: 58.208.0.0 - 58.223.255.255
netname: CHINANET-JS
descr: CHINANET jiangsu province network
descr: China Telecom
descr: A12,Xin-Jie-Kou-Wai Street
descr: Beijing 100088
country: CN
admin-c: CH93-AP
tech-c: CJ186-AP
mnt-by: APNIC-HM
mnt-lower: MAINT-CHINANET-JS
mnt-routes: MAINT-CHINANET-JS
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation's account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
status: ALLOCATED PORTABLE
changed: hm-changed@apnic.net 20050624
source: APNIC
role: CHINANET JIANGSU
address: No.268,Hanzhong Road,Nanjing 210029
country: CN
phone: +86-25-6588783
fax-no: +86-25-6588740
e-mail: ip@jsinfo.net
trouble: send anti-spam reports to spam@jsinfo.net
trouble: send abuse reports to abuse@jsinfo.net
trouble: times in GMT+8
admin-c: CH360-AP
tech-c: CS306-AP
tech-c: CN142-AP
nic-hdl: CJ186-AP
remarks: www.jsinfo.net
notify: ip@jsinfo.net
mnt-by: MAINT-CHINANET-JS
changed: dns@ptt.js.cn 20020530
changed: ip@jsinfo.net 20021213
source: APNIC
person: Chinanet Hostmaster
nic-hdl: CH93-AP
e-mail: anti-spam@ns.chinanet.cn.net
address: No.31 ,jingrong street,beijing
address: 100032
phone: +86-10-58501724
fax-no: +86-10-58501724
country: CN
changed: dingsy@cndata.com 20070416
mnt-by: MAINT-CHINANET
source: APNIC
58.186.137.76
inetnum: 58.186.128.0 - 58.186.143.255
netname: FPT-NET
country: VN
descr: IP range for FPT Broadband Service
descr: 75 Tran Hung Dao, Hoan Kiem, Ha Noi
admin-c: LPC5-AP
tech-c: LPC5-AP
status: ASSIGNED NON-PORTABLE
remarks: For spamming matters, mail to abuse@fpt.vn
changed: hm-changed@vnnic.net.vn 20051130
mnt-by: MAINT-VN-FPT
source: APNIC
person: Liem Pham Cong
nic-hdl: LPC5-AP
e-mail: liempc@fpt.net
address: FPT Telecom
address: 66-68 Vo Van Tan, Dist 3, HCMC
phone: +84-8-9301280
country: VN
changed: hm-changed@vnnic.net.vn 20080128
mnt-by: MAINT-VN-FPT
source: APNIC
58.186.185.13
inetnum: 58.186.176.0 - 58.186.191.255
netname: FPT-NET
country: VN
descr: IP range for FPT Broadband Service
descr: 75 Tran Hung Dao, Hoan Kiem, Ha Noi
admin-c: LPC5-AP
tech-c: LPC5-AP
status: ASSIGNED NON-PORTABLE
remarks: For spamming matters, mail to abuse@fpt.vn
changed: hm-changed@vnnic.net.vn 20051130
mnt-by: MAINT-VN-FPT
source: APNIC
person: Liem Pham Cong
nic-hdl: LPC5-AP
e-mail: liempc@fpt.net
address: FPT Telecom
address: 66-68 Vo Van Tan, Dist 3, HCMC
phone: +84-8-9301280
country: VN
changed: hm-changed@vnnic.net.vn 20080128
mnt-by: MAINT-VN-FPT
source: APNIC
118.68.248.178
inetnum: 118.68.0.0 - 118.68.255.255
netname: IPxDSL-NET
country: vn
descr: Dai IP dong su dung cho ket noi xDSL
admin-c: FHIG2-AP
tech-c: FHIG2-AP
status: ALLOCATED NON-PORTABLE
changed: hm-changed@vnnic.net.vn 20080411
mnt-by: MAINT-VN-FPT
source: APNIC
role: FPT HCMC IPADMIN GROUP
address: 66-68 Vo Van Tan
address: HCMC
country: VN
phone: +84-8-9301280
fax-no: +84-4-7262163
e-mail: abuse@hcm.fpt.vn
trouble: send spam reports to abuse@hcm.fpt.vn
trouble: and abuse reports to abuse@hcm.fpt.vn
admin-c: LPC5-AP
tech-c: LTVL1-AP
nic-hdl: FHIG2-AP
notify: hm-changed@vnnic.net.vn
mnt-by: MAINT-VN-FPT
changed: hm-changed@vnnic.net.vn 20080128
source: APNIC
Đây là mình mới chỉ kiểm tra một số IP. Tất cả đều liên quan tới FPT (mình xài ADSL của FPT, chỉ có một IP từ Trung Quốc). Mình ko rành lắm về vấn đề DDos, nhưng theo mình hiểu và cảnh báo của KIS thì máy mình bị DDos, vậy tại sao lại bị tấn công từ IP của FPT. Mỗi lần như vậy tốc độ net chậm hẳn lại rõ rệt. Bạn nào có thể giải thích và chỉ mình cách khắc phục được không? Xin cám ơn!
[=========> Bổ sung bài viết <=========]
hix! Sao ko thấy ai ra tay giúp hết nè?