服务器被攻击解决方案20260507
20.151.0.19836.44.216.4136.45.252.10640.73.25.126117.22.161.11936.44.222.181117.9.236.101180.163.30.…西安宽带套餐,不定期更新最新西安电信宽带、西安联通宽带、西安移动宽带资费套餐以及优惠活动等,也可关注我们公众号:【 西安宽带云光网 】
20.151.0.198
36.44.216.41
36.45.252.106
40.73.25.126
117.22.161.119
36.44.222.181
117.9.236.101
180.163.30.171
111.30.182.95
61.241.55.198
36.161.196.128
222.90.138.33
117.181.119.74
101.89.45.22
61.241.55.180
39.128.95.140
223.79.205.233
122.227.152.70
112.57.65.23
222.241.248.11
140.179.18.91
124.239.12.75
123.182.49.38
123.182.48.96
120.227.236.22
117.36.8.237
112.39.112.50
111.25.238.66
106.8.138.250
106.8.131.89
61.243.34.131
61.241.56.193
36.43.213.20
36.43.198.16
36.40.209.129
223.166.81.156
183.198.87.68
123.15.4.251
120.227.233.85
116.176.99.85
113.57.29.252
113.201.244.161
111.23.200.115
106.8.138.129
106.8.136.227
106.8.136.177
58.249.163.169
39.166.41.255
223.167.12.54
218.67.164.98
14.104.21.208
1.26.209.50
124.238.213.114
123.182.50.245
122.137.222.85
117.189.246.175
116.132.254.228
116.132.236.3
115.53.97.231
112.32.38.200
111.60.144.66
111.22.136.85
106.8.139.57
106.8.139.49
106.8.137.64
101.89.43.238
61.180.189.164
42.92.75.126
39.182.9.126
36.149.118.100
36.147.102.74
27.38.223.5
27.187.246.166
223.73.72.242
223.167.75.188
218.21.214.52
182.200.222.133
182.148.157.151
14.26.227.0
124.89.126.104
124.239.12.97
124.239.12.82
124.239.12.48
124.239.12.181
123.182.51.55
123.182.50.48
123.182.49.128
123.182.48.82
123.182.48.181
123.139.235.116
121.18.200.134
120.244.227.91
120.228.47.126
120.228.39.44
120.228.34.237
120.228.178.80
120.228.131.36
120.227.25.207
120.227.200.231
119.166.204.220
40.73.25.126
135.119.49.165
20.43.25.175
219.132.130.175
61.241.55.180
112.57.65.23
101.89.43.238
91.98.185.79
61.241.56.193
180.163.31.229
180.163.30.171
122.227.152.70
106.8.137.41
106.8.136.189
123.183.235.158
111.30.182.95
111.30.182.61
101.89.45.22
61.241.55.230
61.241.55.198
124.239.12.74
124.239.12.58
123.182.48.104
116.132.252.53
116.132.252.142
116.132.236.7
116.132.218.16
106.8.131.103
106.8.130.193
124.239.12.35
116.132.255.23
116.132.254.187
116.132.254.116
116.132.236.206
116.132.218.116
116.132.216.232
116.132.138.55
112.57.65.69
106.8.139.157
106.8.137.54
106.8.136.216
124.239.12.249
124.239.12.241
124.239.12.116
123.182.51.179
123.182.50.152
123.182.48.130
116.132.252.101
116.132.138.37
106.8.139.17
106.8.138.99
106.8.138.85
106.8.137.152
106.8.137.113
106.8.136.53
106.8.136.194
106.8.136.153
124.239.12.47
124.239.12.180
124.239.12.136
123.183.235.206
123.182.51.92
123.182.50.143
123.182.49.160
116.132.254.82
116.132.254.65
116.132.254.217
116.132.252.43
116.132.236.173
116.132.138.42
116.132.138.206
116.132.136.21
106.8.139.74
106.8.139.33
106.8.139.118
106.8.138.79
106.8.138.77
106.8.138.39
106.8.138.35
106.8.138.194
106.8.137.42
106.8.137.189
106.8.137.16
106.8.137.141
106.8.137.124
106.8.136.252
106.8.130.74
106.8.130.121
36.45.246.66
124.239.12.242
124.239.12.18
124.239.12.177
124.239.12.106
123.182.51.169
123.182.50.76
123.182.50.47
123.182.50.251
123.182.50.221
123.182.50.211
123.182.49.245
以上这些恶意导致我服务器负载变大 现在需要屏蔽IP段 麻烦帮我整理一下分析解决方案
根据您提供的IP列表,我分析了这些IP的来源和分布,发现它们主要集中在中国的特定地区和运营商。以下是分析和解决方案:
IP分布分析
地理分布:
大部分IP来自中国多个省份(北京、广东、江苏、浙江、山东等)
运营商主要是中国电信、中国移动、联通
重复出现的IP段:
106.8.x.x(河北电信) - 出现频率极高 123.182.x.x(山东联通) 124.239.x.x(河北电信) 116.132.x.x(江苏移动) 36.x.x.x(全国各地) 61.241.x.x(广东电信)
建议屏蔽方案
方案1:屏蔽高频恶意段(推荐)
以下IP段在列表中反复出现,建议优先屏蔽:
Bash# 使用iptables或防火墙规则106.8.0.0/16 # 河北电信123.182.0.0/16 # 山东联通124.239.0.0/16 # 河北电信116.132.0.0/16 # 江苏移动61.241.0.0/16 # 广东电信36.43.0.0/16 # 多地混合
方案2:精细化屏蔽(按子网)
如果担心屏蔽范围过大,可以只屏蔽出现频率最高的子网:
Bash106.8.136.0/24106.8.137.0/24 106.8.138.0/24 106.8.139.0/24 124.239.12.0/24 123.182.48.0/24 123.182.49.0/24 123.182.50.0/24 123.182.51.0/24
操作建议
防火墙配置示例(Linux):
Bashiptables -I INPUT -s 106.8.0.0/16 -j DROPiptables -I INPUT -s 124.239.0.0/16 -j DROP iptables -I INPUT -s 123.182.0.0/16 -j DROP
保存规则:
Bashiptables-save > /etc/iptables/rules.v4
监控效果:
屏蔽后观察服务器负载(
top/htop)查看连接数变化(
netstat -an | grep EST)使用
iftop或nethogs监控流量
后续建议
启用fail2ban:自动检测并屏蔽恶意IP
限制连接频率:
Bashiptables -A INPUT -p tcp --dport 80 -m connlimit --connlimit-above 50 -j DROP
考虑使用CDN:如Cloudflare,隐藏真实服务器IP
注意事项
屏蔽前确保这些IP不是正常用户(可通过日志分析)
考虑逐步屏蔽,先屏蔽最活跃的段(106.8.x.x)
定期更新屏蔽列表,因为攻击者会更换IP


