昨日下午1點13分時突然發現到我自己架設的BLOG遭受數百個IP攻擊
總計有3萬多筆紀錄 附上其中一小段
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 121.14.9.75 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 500 0 64 102749
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 118.97.44.18 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 400 0 64 83108
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 203.128.75.138 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 503 3 0 1605
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 177.43.188.67 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 500 0 64 102813
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 115.25.216.6 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 400 0 64 83093
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 179.185.5.110 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 503 3 64 699
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 213.215.118.53 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 400 0 64 83142
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 190.78.37.63 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 503 3 0 2712
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 187.20.240.60 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 200 0 64 105064
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 222.87.129.30 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 500 0 64 102744
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 116.228.55.217 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 200 0 0 104137
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 61.174.9.96 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 400 0 64 83175
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 164.77.81.130 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 503 3 0 1618
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 110.170.168.45 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 400 0 64 83084
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 115.134.2.191 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 503 3 0 1631
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 197.210.255.150 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 503 3 64 1143
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 177.184.201.9 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 400 0 64 83264
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 218.104.118.54 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 503 3 0 139
2013-12-10 13:13:24 192.168.2.XX GET / - 80 - 14.18.16.71 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.2;) - 400 0 64 83281
根據IP我用網頁開啟卻發現到幾乎都是RouterOS或是mikrotik的網頁
比方說
http://46.249.66.50/
http://189.75.100.98/
http://200.109.228.67/
http://89.77.33.126/
http://177.220.201.4/
http://85.109.120.112/
請問這是真的代表著可能有數百個設備遭受入侵而被用來攻擊
還是其他..?我真的想不到@@
在這邊也想問一下
像這種DDOS攻擊我該如何防範
環境 IIS 8 WIN SERVER




























































































