放到一个托管机房测试,发现自己的机器在.发dns查询,rkhunter查了一下没发现什么木马,而且lastlog看也没什么.异状…….
# tcpd.ump host 218.106.165.169 and not port ssh and not .port http 建材
tcpdump: verb.ose output suppressed, use -v or -vv for full. protocol decode.
listening on .eth0, link-type EN10MB (Etherne.t), capture size 96 bytes--------------彩票
tcpdump: verbose output suppres.sed,. use -v or -vv for full protocol decode学习
listening on eth0, link-type EN10M.B (Ethern.et), capture size 96 bytes虚拟主机
10:24:38.138865 arp who-has .218.106.165.254 tel.l 218.106.165.169--- 印刷
10:24:38.139278 IP 218..1.06.165.169.32768 > linedns.bta.net.cn.domain: 36174+ PTR? 254.165.106.218.in-addr.arpa. (46.) 婚庆
10:24:38.139303 arp. reply 21.8.106.165.254 is-at 00:00:0c:07:ac:67虚拟主机
10:24:38.142171 IP linedns.bta.net.cn..domai.n. > 218.106.165.169.32768: 36174 NXDomain 0/1/0 (100)<性病>
10:24:38.142248 IP 218.106..165.169.32768 .> linedns.bta.net.cn.domain: 20970+ PTR? 169.165.106.218.in-.addr.arpa. (46).
10:24:38.148690 IP linedns.bta.net.cn.domain > 218.10.6.165.169.32768: 20970 N.XDomain. 0/1/0 (100)健康
10:24:38.148769 I.P 218.106.165.169..32768 > l.inedns.bta.net.cn.domain: 42642+ PTR? 115.196.106.202.in-addr.arpa. (46).
10:24:38.150145 IP line.dns.bta.net.cn.domai.n > 218.106.165.169.32768:. 42642 1/0/0 (78)虚拟主机
10:2.5:10.29.3440 arp who-has 218.106.165.254 tell 218.106.165.169 美容
10:.25:10.293.881 arp reply 218.106.165.254 is-at 00:00:0c:07:ac:67 鲜花
10:25:24.448731 IP sonicwall.gcpower.ne.t > 218.106.165.169: icmp 72: echo r.equest .seq 14225 女人
10:25.:24.448818 IP 218.106..165.169.32768 > linedns.bta.net.cn.d.omain: 59402+ PTR? 20.60.215.216.in-addr.arpa. (44).
10:25:27.392000 IP .linedns..bta.net.cn.domain > 218.106..165.169.32768: 59402 1/0/0 (79).
10:25:42.867632 IP 222.128.70.17.32793 > 218.1..06.165.169.snmp: GetRequest(39) inte.rfaces.ifTable.ifE.ntry.ifInOctets.2 [|snmp].
10:2.5:42.867711 IP 218.106.165.169.32768 > linedns.bta.net.cn.domain: 19736+ PTR?. 17.70.128.222.in-addr.arpa. (44.)学习
10:25:42.869123 IP 218.106.165.169.snmp > 222.12.8.70.17.32793: GetResponse(39) interfac.es.ifTable.if.Entry.ifInOctets.2=5425317.78 .iso.org=[|snmp]外贸
10:25:42.869721 IP l.inedns.bta.net.cn.domain > 218.106..165.169.32768: 19736 NXDomain 0/1/0 (98.)学习
我正在查cr.ond有没有异常…….
我发现这个机房.的确有很多奇怪的流量,哪位能.给解解惑么?.
[ 本帖.最后由 iamshiyu. 于 2008-1-25 10:28 编辑 ].