宇宙主机交流论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

欧基零壹微头条IP归属甄别会员请立即修改密码
查看: 1150|回复: 4

photonvps的滥用报告,请大家帮忙分析操作方法

[复制链接]
发表于 2013-7-3 10:30:59 | 显示全部楼层 |阅读模式
以下为photonvps给我发来的滥用报告,但是我不知道是什么意思,也不晓得如何操作。我的是windows的vps  。有懂的朋友可以帮忙看一下,告知一下如何操作谢谢。

Hello,

This is an email notice to inform you that we've had abuse reports regarding
your server. It appears that your server's DNS named service (BIND) is being
exploited to leverage outgoing attacks on other networks. This is due to the
configuration allowing a feature called "recursion" to be
enabled/allowed. This is due to a setting on your server and we would like to
offer to you a quick fix to resolve this issue. This fix will prevent future
issues as well as resolve the current exploit.

First method: Attached is a script that you can upload to your server and run as
the root user. The file is called namedfix.pl.txt. You would upload it as
namedfix.pl or whatever you wish to call it. You would then either set execute
permissions on the file (chmod 700 namedfix.pl) or run it with the perl command
as: perl namedfix.pl. This should do everything automatically for you.

Second method: If you wish to apply this manually and not use the script
attached, then you would locate your named.conf file (likely at
/etc/named.conf). You should back up the file first, calling it something
unique. Example: cp -a /etc/named.conf /etc/named.conf-safebackup. Then, once
you have a safe copy of your current config file, you would open the
/etc/named.conf file using your favorite text editor (vi, nano/pico, etc.) and
within the options { } block, you would add the following two lines (ensuring
they don't exist and are set to allow recursion; if they are, this needs to be
disabled):

allow-recursion { "none"; };
recursion no;

For example, it will look similar to:

options {
listen-on port 53 { any; };
listen-on-v6 port 53 { any; };
directory "/var/named";
dump-file "/var/named/data/cache_dump.db";
statistics-file "/var/named/data/named_stats.txt";
};

Based on the above example, you would modify it to look like this:

options {
listen-on port 53 { any; };
listen-on-v6 port 53 { any; };
directory "/var/named";
dump-file "/var/named/data/cache_dump.db";
statistics-file "/var/named/data/named_stats.txt";
allow-recursion { "none"; };
recursion no;
};

You will now need to reload the named service. This can be done via: service
named reload Or service named restart for the changes to take effect. If you
experience any errors/issues, please revert your last file and restart the
service. Example: cp -af /etc/named.conf-safebackup /etc/named.conf Once you
restart the service, review the changes, ensure you didn't make any typos/syntax
errors and repeat this process. If it still fails, please ask us for assistance
and provide the appropriate login credentials where relevant and we'll take a
look.

Please note: If you find that you need recursion enabled, then it needs to be
safely listed and specifically allowed to a certain IP, network or range,
instead of to the world.

Once again, the script attached should be able to be ran on any server with
BIND/named and will auto-fix this, if that makes it easier. Thank you for your
attention on this matter. Please let us know if you have any questions or
problems.
发表于 2013-7-3 10:32:00 | 显示全部楼层
提示: 作者被禁止或删除 内容自动屏蔽
发表于 2013-7-3 10:32:14 | 显示全部楼层
 楼主| 发表于 2013-7-3 10:33:53 | 显示全部楼层
shuir 发表于 2013-7-3 10:32
百度翻译啊。

我的一个朋友看了,说这是linux系统 的操作方法,在windows内无法这样操作,可否帮忙看下是这样吗。
发表于 2013-7-3 10:34:20 | 显示全部楼层
呵呵,饭桶。。
鸡米露。

——————————我是天朝P民,我在开玩笑,生活在受高墙的干扰之下,@方滨兴,@习 近 平 快来跪舔。
——————————————扫描二维码有XX哟!
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|小黑屋|FastFib VPS论坛

GMT+8, 2024-9-21 00:37 , Processed in 0.058876 second(s), 8 queries , Gzip On, MemCache On.

Powered by Discuz! X3.4

© 2001-2023 Discuz! Team.

快速回复 返回顶部 返回列表