|
之前因为对外流量过大发过一贴,http://www.52.ht/thread-23308-1-2.html
后来与linode客服交流,自己用tcpdump查了一下,发现有来自aerh186.neoplus.adsl.tpnet.pl的频繁访问。
17:59:00.182412 IP aerh186.neoplus.adsl.tpnet.pl.51188 > li137-181.members.linode.com.57216: Flags [.], ack 3193021, win 65335, length 0
17:59:00.188205 IP aerh186.neoplus.adsl.tpnet.pl.51188 > li137-181.members.linode.com.57216: Flags [P.], seq 2944:2948, ack 3194481, win 65335, length 4
很奇怪怎么会有来自这里的访问,而且还是端口57216,那么就不是来自web服务的访问了?57216这个端口是干嘛用的?
linode的回复如下:
Thank you for contacting us. I looked up that host and it appears to be a customer of "NEOSTRADA-ADSL" in Poland. If this is not traffic that you want, I recommend that you block that IP using 'iptables' and then report it to [email protected].
Please let us know if you have any further questions.
自己查了一下,用”iptables -I INPUT -s aerh186.neoplus.adsl.tpnet.pl -j DROP“命令行希望能阻止它。
god bless me,希望不要继续出岔子。。。 |
|