如题,先把攻击者的攻击文件发给大家
https://github.com/tixiaohanmc/ddos/blob/main/floodprivate.zip.zip
就是被这个东西攻击的
top命令执行如下:
- top - 02:21:11 up 4:07, 1 user, load average: 80.00, 58.74, 38.42
- Tasks: 183 total, 83 running, 99 sleeping, 0 stopped, 1 zombie
- %Cpu(s): 93.8 us, 5.8 sy, 0.0 ni, 0.0 id, 0.0 wa, 0.0 hi, 0.4 si, 0.0 st
- MiB Mem : 3930.8 total, 135.7 free, 1764.4 used, 2030.7 buff/cache
- MiB Swap: 975.0 total, 972.2 free, 2.8 used. 1881.3 avail Mem
- PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
- 322320 www 20 0 95412 32148 11860 R 5.2 0.8 0:12.68 php-fpm
- 322334 www 20 0 95412 34500 12580 R 5.2 0.9 0:11.43 php-fpm
- 322337 www 20 0 95412 31968 11632 R 5.2 0.8 0:11.43 php-fpm
- 322346 www 20 0 95412 34340 12588 R 5.2 0.9 0:11.19 php-fpm
- 322347 www 20 0 95412 32080 11892 R 5.2 0.8 0:11.25 php-fpm
- 322350 www 20 0 95412 32284 11960 R 5.2 0.8 0:11.27 php-fpm
- 322353 www 20 0 95412 32212 11904 R 5.2 0.8 0:11.08 php-fpm
- 322354 www 20 0 95620 32356 11904 R 5.2 0.8 0:11.08 php-fpm
- 322357 www 20 0 95412 34492 12664 R 5.2 0.9 0:11.16 php-fpm
- 322365 www 20 0 95412 34080 12232 R 5.2 0.8 0:11.10 php-fpm
- 322366 www 20 0 95412 33744 11912 R 5.2 0.8 0:11.06 php-fpm
- 322367 www 20 0 95412 32220 11912 R 5.2 0.8 0:11.07 php-fpm
- 322371 www 20 0 95412 32224 11916 R 5.2 0.8 0:10.97 php-fpm
- 322376 www 20 0 95412 34088 12240 R 5.2 0.8 0:11.02 php-fpm
- 322378 www 20 0 95412 32340 11920 R 5.2 0.8 0:11.02 php-fpm
- 322379 www 20 0 95412 32352 11920 R 5.2 0.8 0:11.02 php-fpm
- 322381 www 20 0 95412 32232 11924 R 5.2 0.8 0:10.97 php-fpm
- 322384 www 20 0 95476 34632 12684 R 5.2 0.9 0:10.97 php-fpm
- 322390 www 20 0 95476 34460 12616 R 5.2 0.9 0:10.95 php-fpm
- 322393 www 20 0 95412 32352 11920 R 5.2 0.8 0:10.91 php-fpm
- 322395 www 20 0 95412 32344 11924 R 5.2 0.8 0:10.79 php-fpm
- 322396 www 20 0 95412 32228 11920 R 5.2 0.8 0:10.87 php-fpm
- 322312 www 20 0 95412 34436 12552 R 4.9 0.9 0:12.72 php-fpm
- 322313 www 20 0 95412 32472 11856 R 4.9 0.8 0:12.66 php-fpm
- 322314 www 20 0 95412 33716 11856 R 4.9 0.8 0:12.62 php-fpm
- 322316 www 20 0 95412 32836 12400 R 4.9 0.8 0:12.69 php-fpm
- 322317 www 20 0 95412 32200 11864 R 4.9 0.8 0:12.62 php-fpm
- 322318 www 20 0 95412 32220 11864 R 4.9 0.8 0:12.69 php-fpm
- 322321 www 20 0 95412 33184 12624 R 4.9 0.8 0:12.68 php-fpm
- 322324 www 20 0 95412 32028 11868 R 4.9 0.8 0:12.29 php-fpm
- 322325 www 20 0 95412 32416 11932 R 4.9 0.8 0:11.88 php-fpm
- 322326 www 20 0 95476 33204 12564 R 4.9 0.8 0:11.88 php-fpm
- 322327 www 20 0 95412 32372 11936 R 4.9 0.8 0:11.60 php-fpm
- 322328 www 20 0 95412 32180 11872 R 4.9 0.8 0:11.65 php-fpm
- 322329 www 20 0 95412 31988 11652 R 4.9 0.8 0:11.59 php-fpm
- 322330 www 20 0 95412 31944 11648 R 4.9 0.8 0:11.66 php-fpm
复制代码
已知nginx和php防火墙都没法防止住这个,请问有解决办法吗?
|