Answer the question
In order to leave comments, you need to log in
What is the meaning of abuza?
There is a grandfather at Hetzner.
Abuses of the form periodically come:
24940 | our.ip.shn.to | 2020-07-21 05:46:00 | 100000 4 111/udp; 100000 3 111/udp; 100000 2111/udp; 100000 4 111/udp; 100000 3 111/udp; 100000 2111/udp; 100005 1 45736/udp; 100005 1 57373/udp; 100005 2 56575/udp; 100005 2 48537/udp; 100005 3 35945/udp; 100005 3 44941/udp; 100003 3 2049/udp; 100003 4 2049/udp; 100227 3 2049/udp; 100003 3 2049/udp; 100227 3 2049/udp; 100021 1 38104/udp; 100021 3 38104/udp; 100021 4 38104/udp; 100021 1 37263/udp; 100021 3 37263/udp; 100021 4 37263/udp;
Answer the question
In order to leave comments, you need to log in
You have portmapper open outside, port 111 tcp/udp
Indirectly, this is a vulnerability that allows attackers to use it for DDOS attacks.
Usually it is needed for NFS or RPD, but it is extremely rare for someone to do it directly over the Internet. Through the Internet, they often do ssh or already turn on VPN and already rummage inside.
If you do not use such services, just close the portmapper outside.
Deny all traffic at the packet level, except for what you really need.
Based on the abuse, suspicious traffic was detected - in my biased opinion, this looks like the activity of a botnet member.
Accordingly, you need to find which process on your server generates traffic that the hoster points to, and either this is a botnet process and you need to clean it up and figure out how you were hacked, or explain to the hoster that this is normal activity in your opinion, the explanation should be as detailed as possible.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question