问题描述
大家好,下面这种问题怎么解决?iis日志里面出现下面这种情况,我觉得可能是服务器中了恶意流量拥塞的毒了,导致网站访问很慢,cpu占用情况正常,低于5%。内存使用也正常。日志中显示,总是持续访问某个根本不存在的文件,现在根本就没有local这个目录存在,并且客户端ip地址总换。以前某些网站文件没有设置成只读,总是被篡改网站文件,后来用备份的文件还原后,都弄成只读的,才解决了被篡改文件的问题,但是从外部访问网站的速度很慢,用360杀毒杀不出来。以下是部分日志,这样的日志很多:2012-03-1800:53:14W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-110.232.37.208Mozilla/4.0+(compatible;+MSIE+5.00;+Windows+98)404032012-03-1800:53:14W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-110.232.37.208Mozilla/4.0+(compatible;+MSIE+5.00;+Windows+98)404032012-03-1800:53:14W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-110.232.37.208Mozilla/4.0+(compatible;+MSIE+5.00;+Windows+98)404032012-03-1800:53:14W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-110.232.37.208Mozilla/4.0+(compatible;+MSIE+5.00;+Windows+98)404032012-03-1803:32:58W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:32:59W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:01W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:02W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:04W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:04W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:07W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:07W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:10W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:10W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:13W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:14W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:16W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:17W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:19W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:20W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:22W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:23W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:25W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.0404032012-03-1803:33:26W3SVC1192.168.0.5GET/local/ccxx/oa/fileManage/16000032/2007-2/7-200727114819_0.mp3-80-114.250.179.181NSPlayer/9.0.0.4509+WMFSDK/9.040403
解决方案
解决方案二:
要不你试试把WWW服务从80改成别的端口那?
解决方案三:
这是个互联网时代,网站安全防御已经很有必要了。专业的事交给专业的人,以上问题完美解决。想了解相关情况的可以和我聊聊。
解决方案四:
该回复于2012-05-30 08:35:01被版主删除
解决方案五:
该回复于2012-09-10 15:25:45被版主删除
解决方案六:
还是用硬件防火墙吧。
解决方案七:
这应该是DOS攻击吧.用验证码似乎也只能解决蛮力试探登录的.
解决方案八:
你这个肯定是被攻击,首先请求的文件是同一个,来源地址是同一个,可以用防火墙来阻挡,比如,10秒内同一个地方请求同一资源就给拒绝他的请求10分钟.
解决方案九:
回答没说完整,郁闷:比如,10秒内同一个地方请求同一资源超过20次就拒绝他的请求10分钟.
解决方案十:
该回复于2012-10-26 11:03:13被版主删除
解决方案十一:
将恶意IP添加黑名单。。。防火墙流量监控类防御软件。