一直收到Hetzner的邮件,非常的烦!
########################################################################## # Netscan detected from host IPXXXXXXX # ########################################################################## time protocol src_ip src_port dest_ip dest_port --------------------------------------------------------------------------- Thu Apr 1 16:33:00 2021 TCP IPXXXXXXX 55760 => 10.0.12.7 1834 Thu Apr 1 16:37:23 2021 TCP IPXXXXXXX 57402 => 10.0.12.7 1834 Thu Apr 1 16:38:28 2021 TCP IPXXXXXXX 57848 => 10.0.12.7 1834 Thu Apr 1 16:40:41 2021 TCP IPXXXXXXX 58748 => 10.0.12.7 1834 Thu Apr 1 16:41:50 2021 TCP IPXXXXXXX 59154 => 10.0.12.7 1834 Thu Apr 1 16:31:59 2021 TCP IPXXXXXXX 45836 => 10.10.1.216 1834 Thu Apr 1 16:32:01 2021 TCP IPXXXXXXX 45836 => 10.10.1.216 1834 Thu Apr 1 16:37:23 2021 TCP IPXXXXXXX 47824 => 10.10.1.216 1834 Thu Apr 1 16:40:04 2021 TCP IPXXXXXXX 45162 => 10.10.10.33 1734 Thu Apr 1 16:32:58 2021 TCP IPXXXXXXX 37780 => 10.10.10.37 1734 Thu Apr 1 16:33:00 2021 TCP IPXXXXXXX 37780 => 10.10.10.37 1734 Thu Apr 1 16:32:43 2021 TCP IPXXXXXXX 50414 => 10.10.19.25 1734 Thu Apr 1 16:35:16 2021 TCP IPXXXXXXX 45642 => 192.168.1.2
联系客服,他们说即使是内网扫描,也对他们的内部网络造成了影响,所以一定要阻止这个行为。
防火墙规则:
sudo ufw deny out from any to 10.0.0.0/8 sudo ufw deny out from any to 172.16.0.0/12 sudo ufw deny out from any to 192.168.0.0/16 sudo ufw deny out from any to 100.64.0.0/10