|
楼主 |
发表于 2022-7-3 11:05:08
|
显示全部楼层
hostloc10086 发表于 2022-7-3 10:57
1:一键脚本被按了后门 2:VPS的root密码被人攻破了
根据链接所提供的如下提示:
我想应该是我使用了扶墙,和安装使用流媒体APP的原因?
What should be done about it?
If this is a shared server, please call your hosting company or ISP!
These listings are the result of what we believe to be a security issue that results in spam being sent from your network. To stop ongoing listings and to secure your network, devices, and data, we recommend both prevention and remediation of the issue.
We hope the following information might be of help.
Prevention
We very strongly advise securing your router/firewall to deny any outbound packets on port 25, except those coming from any email servers (if any) on your local network. Remote sending of email to servers on the Internet will still work if web-based, or configured properly using port 587 with SMTP-AUTH.
If you are not running your own mail server, you should be using your ISP's mail servers with SMTP authentication, and your router should be set to deny outbound traffic on port 25. Your ISP can help you set that up if needed.
If you are using your ISP's mail servers and they are blocking you from those servers, please call them for a resolution. Your router should also be set to deny outbound traffic on port 25. Your ISP can help with that.
If you are running your own mail server, please contact your ISP for help with getting set up on an appropriate static IP and valid DNS/rDNS for that purpose, to configure SMTP authentication on port 587, and then to limit outbound port 25 only to the use of that server.
Limiting port 25 access is a best practice. Please call your ISP or IT department for assistance with configuring your router or firewall correctly.
Remediation
The device(s) or computer(s) that caused this issue should be found and secured. The following information should address most cases, but please seek professional assistance if it is necessary:
The cause of this problem is frequently found to be coming from an phone or laptop with "free" 扶墙s, channel unlockers, streaming type apps installed.
Programs like Windows Defender, Windows Malicious Software Removal Tool (MSRT), Malwarebytes, Norton Power Eraser, CCleaner and/or McAfee Stinger can help. There is also a version of Malwarebytes for Mac/OSX. These tools are free of charge!
Update your enterprise anti-virus/anti-malware programs, and run full scans on every device that is available
If you have a CMS or website, ensure it is up to date. All plug-ins, extensions & patches for it should be updated and maintained
We can only see what's coming from the NAT (public) IP; anything inside your network is visible only to you. Packet capture is the best way to identify which devices are generating unwanted traffic. In general, only mailservers are supposed to generate traffic to port 25, as mail clients rely on the dedicated ports 587 or 465.
If this IP address is a NAT gateway, firewall or router: in some cases, the compromised device can also be the router/firewall itself. Please consult the documentation of your device regarding how to make sure its software is up to date, and how to ensure that the device is properly secured. |
|