HTTP spam from my server.

TEGBO

New Member
Jul 9, 2024
1
0
1
Hallo Team,

ich habe ein Problem mit meinem Proxmox Server.
Hetzner 2 IPv4 Adressen
1x Proxmox
1x OpenSense

Fehler: Der Proxmox Server Spam andere Server zu.

Code:
##############################################################################
#      DDoS-Attack detected from host THISISTHESERVER                          #
##############################################################################


TIME                                 SRC           SRC-PORT  ->  DST       
    DST-PORT  SIZE  PROT
----------------------------------------------------------------------------------------------------------
2024-07-08 10:38:41.630633753 +0200  THISISTHESERVER    10777  -> 
154.37.153.59       80  1076   TCP
2024-07-08 10:38:41.794812365 +0200  THISISTHESERVER    43227  -> 
154.37.153.59       80  1076   TCP
2024-07-08 10:38:42.041842274 +0200  THISISTHESERVER     1165  -> 
154.37.153.59       80  1076   TCP
2024-07-08 10:38:42.463792854 +0200  THISISTHESERVER    36660  -> 
154.37.153.59       80  1076   TCP
2024-07-08 10:38:42.528240527 +0200  THISISTHESERVER     1749  ->

Befehl: tcpdump -n host THISISTHESERVER


Darauf wurde der Sever natürlich durch den Anbieter gesperrt.


/var/log/rkhunter.log

Code:
Warning: Suspicious file types found in /dev:
[22:26:51]          /dev/shm/qb-1158-1265-10-HTJH9r/qb-request-pve2-header: data
[22:26:51]          /dev/shm/qb-1158-1265-10-HTJH9r/qb-request-pve2-data: data
[22:26:51]          /dev/shm/qb-1158-1265-10-HTJH9r/qb-response-pve2-header: data
[22:26:51]          /dev/shm/qb-1158-1265-10-HTJH9r/qb-response-pve2-data: Matlab v4 mat-file (little endian) \273p, numeric, rows 3503345872, columns 1
[22:26:51]          /dev/shm/qb-1158-1265-10-HTJH9r/qb-event-pve2-header: data
[22:26:51]          /dev/shm/qb-1158-1265-10-HTJH9r/qb-event-pve2-data: data
[22:26:51]          /dev/shm/qb-1158-1268-15-H84W5B/qb-request-pve2-header: data
[22:26:51]          /dev/shm/qb-1158-1268-15-H84W5B/qb-request-pve2-data: data
[22:26:51]          /dev/shm/qb-1158-1268-15-H84W5B/qb-response-pve2-header: data
[22:26:51]          /dev/shm/qb-1158-1268-15-H84W5B/qb-response-pve2-data: Matlab v4 mat-file (little endian) \273p, numeric, rows 3503345872, columns 1
[22:26:51]          /dev/shm/qb-1158-1268-15-H84W5B/qb-event-pve2-header: data
[22:26:51]          /dev/shm/qb-1158-1268-15-H84W5B/qb-event-pve2-data: data
[22:26:51]          /dev/shm/qb-1158-1260-16-NmnZr7/qb-request-pve2-header: data
[22:26:51]          /dev/shm/qb-1158-1260-16-NmnZr7/qb-request-pve2-data: data
[22:26:51]          /dev/shm/qb-1158-1260-16-NmnZr7/qb-response-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1260-16-NmnZr7/qb-response-pve2-data: Matlab v4 mat-file (little endian) \273p, numeric, rows 3503345872, columns 1
[22:26:52]          /dev/shm/qb-1158-1260-16-NmnZr7/qb-event-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1260-16-NmnZr7/qb-event-pve2-data: data
[22:26:52]          /dev/shm/qb-1158-1324-17-2BEXqR/qb-request-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1324-17-2BEXqR/qb-request-pve2-data: Matlab v4 mat-file (little endian) \247\, numeric, rows 3503345872, columns 1
[22:26:52]          /dev/shm/qb-1158-1324-17-2BEXqR/qb-response-pve2-header: 370 XA sysV executable not stripped
[22:26:52]          /dev/shm/qb-1158-1324-17-2BEXqR/qb-response-pve2-data: Matlab v4 mat-file (little endian) \273p, numeric, rows 3503345872, columns 1
[22:26:52]          /dev/shm/qb-1158-1324-17-2BEXqR/qb-event-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1324-17-2BEXqR/qb-event-pve2-data: data
[22:26:52]          /dev/shm/qb-1158-1331-18-5WvUJI/qb-request-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1331-18-5WvUJI/qb-request-pve2-data: data
[22:26:52]          /dev/shm/qb-1158-1331-18-5WvUJI/qb-response-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1331-18-5WvUJI/qb-response-pve2-data: Matlab v4 mat-file (little endian) \273p, numeric, rows 3503345872, columns 1
[22:26:52]          /dev/shm/qb-1158-1331-18-5WvUJI/qb-event-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1331-18-5WvUJI/qb-event-pve2-data: data
[22:26:52]          /dev/shm/qb-1158-1336-19-gtr0gn/qb-request-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1336-19-gtr0gn/qb-request-pve2-data: Matlab v4 mat-file (little endian) sb, numeric, rows 3503345872, columns 1
[22:26:52]          /dev/shm/qb-1158-1336-19-gtr0gn/qb-response-pve2-header: 370 XA sysV executable not stripped
[22:26:52]          /dev/shm/qb-1158-1336-19-gtr0gn/qb-response-pve2-data: Matlab v4 mat-file (little endian) \273p, numeric, rows 3503345872, columns 1
[22:26:52]          /dev/shm/qb-1158-1336-19-gtr0gn/qb-event-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1336-19-gtr0gn/qb-event-pve2-data: data
[22:26:52]          /dev/shm/qb-1158-1340-20-kxNePh/qb-request-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1340-20-kxNePh/qb-request-pve2-data: data
[22:26:52]          /dev/shm/qb-1158-1340-20-kxNePh/qb-response-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1340-20-kxNePh/qb-response-pve2-data: Matlab v4 mat-file (little endian) \273p, numeric, rows 3503345872, columns 1
[22:26:52]          /dev/shm/qb-1158-1340-20-kxNePh/qb-event-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1340-20-kxNePh/qb-event-pve2-data: data
[22:26:52]          /dev/shm/qb-1158-1273-23-BZAW1U/qb-request-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1273-23-BZAW1U/qb-request-pve2-data: data
[22:26:52]          /dev/shm/qb-1158-1273-23-BZAW1U/qb-response-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1273-23-BZAW1U/qb-response-pve2-data: Matlab v4 mat-file (little endian) \273p, numeric, rows 3503345872, columns 1
[22:26:52]          /dev/shm/qb-1158-1273-23-BZAW1U/qb-event-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1273-23-BZAW1U/qb-event-pve2-data: data
[22:26:52]          /dev/shm/qb-1158-1846-21-u82cY7/qb-request-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1846-21-u82cY7/qb-request-pve2-data: Matlab v4 mat-file (little endian) \302Y, numeric, rows 3503345872, columns 1
[22:26:52]          /dev/shm/qb-1158-1846-21-u82cY7/qb-response-pve2-header: 6 1970, not stripped, version 11618
[22:26:52]          /dev/shm/qb-1158-1846-21-u82cY7/qb-response-pve2-data: Matlab v4 mat-file (little endian) \273p, numeric, rows 3503345872, columns 1
[22:26:52]          /dev/shm/qb-1158-1846-21-u82cY7/qb-event-pve2-header: data
[22:26:52]          /dev/shm/qb-1158-1846-21-u82cY7/qb-event-pve2-data: data

  • ls -l /dev/shm


  • Ich bin mir nur nich Sicher was darf ich jetzt löschen oder gibt es einen Renew Befehl der die Datein neu erstellt oder kann mir einer genauer helfen?

 
Ich bin mir nicht ganz sicher, was du meinst aber es hört sich so an, als wäre dein Server kompromittiert. Falls er auf einem Network mit anderen Maschinen ist schneid ihm lieber die Verbindung ab. Was die Files angeht versuch sie zu isolieren.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!