Vps saya mengirim flood ke server lain

Discussion in 'Site & Server Administration' started by Byens, Jun 19, 2015.

  1. Byens

    Byens Member

    Joined:
    May 25, 2014
    Messages:
    222
    Likes Received:
    11
    Trophy Points:
    18
    Code:
    Reported-From: abuse-team@blocklist.de
    Category: abuse
    Report-Type: login-attack
    Service: bruteforcelogin
    Version: 0.2
    User-Agent: Fail2BanFeedBackScript blocklist.de V0.2
    Date: Wed, 17 Jun 2015 18:18:43 +0200
    *Timezone: +0200
    *Time: Wed, 17 Jun 2015 18:18:43 +0200
    *Destination-Port: 80
    Source-Type: ip-address
    Source: 128.199.166.232
    Port: 80
    Report-ID: 690308585@blocklist.de
    Schema-URL: http://www.x-arf.org/schema/abuse_login-attack_0.1.2.json
    Attachment: text/plain
    
    Lines containing IP128.199.166.232:
    NOT SORTED (from many different Machines)!
    DESTINATION-IP: 80.67.17.221,2a00:1158:0:300:5f7e::1/64,80.67.17.15,fe80::216:3eff:fe01:89f2/64,46.252.18.32,fe80::216:3eff:fe00:3244/64,
    DESTINATION-IPs: 80.67.17.221,2a00:1158:0:300:5f7e::1/64,80.67.17.15,fe80::216:3eff:fe01:89f2/64,46.252.18.32,fe80::216:3eff:fe00:3244/64,
    
    128.199.166.232 - - [17/Jun/2015:18:18:43 +0200] "POST wp-login.php HTTP/1.0" 200 12107 "-" "-"
    128.199.166.232 - - [17/Jun/2015:18:18:54 +0200] "POST wp-login.php HTTP/1.0" 200 12107 "-" "-"
    128.199.166.232 - - [17/Jun/2015:18:19:01 +0200] "POST wp-login.php HTTP/1.0" 200 12107 "-" "-"
    128.199.166.232 - - [17/Jun/2015:18:19:03 +0200] "POST wp-login.php HTTP/1.0" 200 12107 "-" "-"
    128.199.166.232 - - [17/Jun/2015:18:19:04 +0200] "POST wp-login.php HTTP/1.0" 200 12107 "-" "-"
    12
    Itu adalah sebagian log file saya copas kesini. Apa Yang menjadi penyebab saya juga kurang jelas. Bisa juga plugin2 wordpress Yang belon diupdate. Kalau root akses kayanya ngga kebobolan sih.

    Tadi pagi Sudah saya pindah ke server baru semua datanya.

    Pertanyaan saya apakah ada temen Yang mengalami spt ini, kalo iya apa ada solusi? Selain pindah server tentunya.
     
    Last edited by a moderator: Jun 19, 2015
  2. Ardilas

    Ardilas Super Level

    Joined:
    Feb 18, 2013
    Messages:
    4,243
    Likes Received:
    317
    Trophy Points:
    83
    Google+:
    Sepertinya ada yang coba untuk meng-hack situs nya.
     
  3. KangAndre

    KangAndre Member

    Joined:
    Jan 25, 2014
    Messages:
    10,244
    Likes Received:
    2,714
    Trophy Points:
    413
    Biasanya ada UDP flood script terpasang di server. Coba periksa file-file aneh yang ada di server. Biasanya dibuat nama yang nggak buat curiga adminnya mis: wp-log.php (wp asli nggak ada)
     
  4. Tantowi

    Tantowi Active Member

    Joined:
    May 9, 2015
    Messages:
    635
    Likes Received:
    24
    Trophy Points:
    48
    makasih kang andre, membantu pekerjaan saya juga nie hh. untuk kang byens semoga cepet selesai masalahnya yh
     
  5. Byens

    Byens Member

    Joined:
    May 25, 2014
    Messages:
    222
    Likes Received:
    11
    Trophy Points:
    18
    Sepertinya sih ngga ada kang, tapi saya curiga ada 1 wordpress yang banyak plugin minta update, dan tampilan depan banyak berubah. Sehingga saya perlu betulkan dulu. Dan diupdate2 semua plugin2nya. Sepertinya harus auto update wordpressnya

    apakah dengan menambahkan line
    Code:
    define( 'AUTOMATIC_UPDATER_DISABLED', false );
    pada wp-config.php bisa langsung autoupdate?
     
  6. KangAndre

    KangAndre Member

    Joined:
    Jan 25, 2014
    Messages:
    10,244
    Likes Received:
    2,714
    Trophy Points:
    413
  7. Byens

    Byens Member

    Joined:
    May 25, 2014
    Messages:
    222
    Likes Received:
    11
    Trophy Points:
    18
    Sebetulnya saya ingin menghindari plugin sebisa mungkin @KangAndre .

    Kalau saya tambahkan di wp-config spt ini?

    Code:
    define('WP_AUTO_UPDATE_CORE', true);
    add_filter( 'auto_update_plugin', '__return_true' );
    add_filter( 'auto_update_theme', '__return_true' );
    apakah bisa?
     
Loading...

Share This Page