• Welcome to LiuJason's Blog!

Hetzner服务器防止Abuse内网Netscan

Linux笔记 Jason 4 years ago (2021-04-01) 683 Views 0 Comments QR code of this page

一直收到Hetzner的邮件,非常的烦!

##########################################################################
#               Netscan detected from host  IPXXXXXXX               #
##########################################################################

time                protocol src_ip src_port          dest_ip dest_port
---------------------------------------------------------------------------
Thu Apr  1 16:33:00 2021 TCP  IPXXXXXXX 55760 =>       10.0.12.7 1834 
Thu Apr  1 16:37:23 2021 TCP  IPXXXXXXX 57402 =>       10.0.12.7 1834 
Thu Apr  1 16:38:28 2021 TCP  IPXXXXXXX 57848 =>       10.0.12.7 1834 
Thu Apr  1 16:40:41 2021 TCP  IPXXXXXXX 58748 =>       10.0.12.7 1834 
Thu Apr  1 16:41:50 2021 TCP  IPXXXXXXX 59154 =>       10.0.12.7 1834 
Thu Apr  1 16:31:59 2021 TCP  IPXXXXXXX 45836 =>     10.10.1.216 1834 
Thu Apr  1 16:32:01 2021 TCP  IPXXXXXXX 45836 =>     10.10.1.216 1834 
Thu Apr  1 16:37:23 2021 TCP  IPXXXXXXX 47824 =>     10.10.1.216 1834 
Thu Apr  1 16:40:04 2021 TCP  IPXXXXXXX 45162 =>     10.10.10.33 1734 
Thu Apr  1 16:32:58 2021 TCP  IPXXXXXXX 37780 =>     10.10.10.37 1734 
Thu Apr  1 16:33:00 2021 TCP  IPXXXXXXX 37780 =>     10.10.10.37 1734 
Thu Apr  1 16:32:43 2021 TCP  IPXXXXXXX 50414 =>     10.10.19.25 1734 
Thu Apr  1 16:35:16 2021 TCP  IPXXXXXXX 45642 =>     192.168.1.2 

联系客服,他们说即使是内网扫描,也对他们的内部网络造成了影响,所以一定要阻止这个行为。
防火墙规则:

sudo ufw deny out from any to 10.0.0.0/8
sudo ufw deny out from any to 172.16.0.0/12
sudo ufw deny out from any to 192.168.0.0/16
sudo ufw deny out from any to 100.64.0.0/10

This article is under CC BY-NC-SA 4.0 license.
Please quote the original link:https://www.liujason.com/article/1165.html
Like (2)
发表我的评论
取消评论

表情 贴图 加粗 删除线 居中 斜体 签到

Hi,您需要填写昵称和邮箱!

  • 昵称 (必填)
  • 邮箱 (必填)
  • 网址