Hallo
Ich habe einen V-Server ohne managing da ich bisher einen VPS hatte mit C-Panel lerne ich mich immer mehr in die Materie abischerung ein ,.,,mein Server hat PLesk12 aber ich habe versucht
etliches per ssh zu installieren,
Root login no, password no, rkhunter, csf firwall, chkrootkit, usw....jedoch habe ich zu zeit immer wieder Alerts per mail,,,ich muss dazu sagen daß jemand es seit Anfang an auf meiner IP abgesen hat und mir an einen Tag 919 GB über den DNS Server verursacht hatte, worauf ich BIND desinstalliert habe da ich es nicht brauche.
Heute kam folgender LOG und das sind meine Traffics heute,...wie könnte ich das System noch besser schützen ? Spam Mails und co ?
Danke ;Maurizio
Server health parameter "Services > Apache CPU usage" changed its status from "green" to "red".
Server health parameter "Services > nginx CPU usage" changed its status from "green" to "red".
Server health parameter "Services > MySQL CPU usage" changed its status from "green" to "red".
top - 11:06:43 up 5 min, 2 users, load average: 0.21, 0.51, 0.29
Tasks: 122 total, 1 running, 121 sleeping, 0 stopped, 0 zombie
%Cpu(s): 15.7 us, 9.2 sy, 0.0 ni, 66.1 id, 8.3 wa, 0.0 hi, 0.7 si, 0.1 st
KiB Mem: 8198516 total, 1532636 used, 6665880 free, 45012 buffers
KiB Swap: 1492988 total, 0 used, 1492988 free, 821428 cached
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
1 root 20 0 10648 824 692 S 0.0 0.0 0:00.45 init
2 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kthreadd
3 root 20 0 0 0 0 S 0.0 0.0 0:00.09 ksoftirqd/0
5 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kworker/u:0
6 root rt 0 0 0 0 S 0.0 0.0 0:00.10 migration/0
7 root rt 0 0 0 0 S 0.0 0.0 0:00.00 watchdog/0
8 root rt 0 0 0 0 S 0.0 0.0 0:00.10 migration/1
10 root 20 0 0 0 0 S 0.0 0.0 0:00.08 ksoftirqd/1
12 root rt 0 0 0 0 S 0.0 0.0 0:00.00 watchdog/1
13 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 cpuset
14 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 khelper
15 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kdevtmpfs
16 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 netns
17 root 20 0 0 0 0 S 0.0 0.0 0:00.00 sync_supers
18 root 20 0 0 0 0 S 0.0 0.0 0:00.00 bdi-default
19 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 kintegrityd
20 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 kblockd
21 root 20 0 0 0 0 S 0.0 0.0 0:00.06 kworker/1:1
22 root 20 0 0 0 0 S 0.0 0.0 0:00.00 khungtaskd
23 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kswapd0
24 root 25 5 0 0 0 S 0.0 0.0 0:00.00 ksmd
25 root 39 19 0 0 0 S 0.0 0.0 0:00.00 khugepaged
26 root 20 0 0 0 0 S 0.0 0.0 0:00.00 fsnotify_mark
27 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 crypto
92 root 20 0 0 0 0 S 0.0 0.0 0:00.00 khubd
97 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 ata_sff
101 root 20 0 0 0 0 S 0.0 0.0 0:00.00 scsi_eh_0
102 root 20 0 0 0 0 S 0.0 0.0 0:00.00 scsi_eh_1
103 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kworker/u:1
128 root 20 0 0 0 0 S 0.0 0.0 0:00.13 kworker/0:2
134 root 20 0 0 0 0 S 0.0 0.0 0:00.00 kworker/1:2
147 root 20 0 0 0 0 S 0.0 0.0 0:00.02 jbd2/vda2-8
148 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 ext4-dio-unwrit
291 root 20 0 21504 1528 808 S 0.0 0.0 0:00.06 udevd
413 root 20 0 21500 1188 460 S 0.0 0.0 0:00.00 udevd
414 root 20 0 21500 1164 436 S 0.0 0.0 0:00.00 udevd
428 root 20 0 0 0 0 S 0.0 0.0 0:00.00 vballoon
430 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 kpsmoused
431 root 20 0 0 0 0 S 0.0 0.0 0:00.04 kworker/0:3
1633 root 20 0 9960 2584 288 S 0.0 0.0 0:00.00 dhclient
1667 root 20 0 18972 900 644 S 0.0 0.0 0:00.00 rpcbind
1698 statd 20 0 23344 1344 884 S 0.0 0.0 0:00.00 rpc.statd
1703 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 rpciod
1705 root 0 -20 0 0 0 S 0.0 0.0 0:00.00 nfsiod
1712 root 20 0 25292 424 208 S 0.0 0.0 0:00.00 rpc.idmapd
2034 root 20 0 0 0 0 S 0.0 0.0 0:00.02 flush-254:0
2042 root 20 0 330m 9532 940 S 0.0 0.1 0:00.00 sw-engine-fpm
2087 root 20 0 52776 1560 1148 S 0.0 0.0 0:00.09 rsyslogd
2117 root 20 0 4116 652 508 S 0.0 0.0 0:00.01 acpid
2153 root 20 0 314m 44m 10m S 0.0 0.6 0:00.18 /usr/sbin/apach
2213 daemon 20 0 16672 148 0 S 0.0 0.0 0:00.00 atd
2236 root 20 0 4088 336 244 S 0.0 0.0 0:00.00 courierlogger
2238 root 20 0 11976 944 788 S 0.0 0.0 0:00.00 couriertcpd
2239 root 20 0 4088 336 244 S 0.0 0.0 0:00.00 courierlogger
2240 root 20 0 11976 944 788 S 0.0 0.0 0:00.00 couriertcpd
2277 root 20 0 4088 456 356 S 0.0 0.0 0:00.00 courierlogger
2279 root 20 0 27932 1560 1184 S 0.0 0.0 0:00.00 authdaemond
2430 root 20 0 4088 332 244 S 0.0 0.0 0:00.00 courierlogger
2431 root 20 0 11976 940 788 S 0.0 0.0 0:00.00 couriertcpd
2433 root 20 0 4088 336 244 S 0.0 0.0 0:00.00 courierlogger
2435 root 20 0 11976 940 788 S 0.0 0.0 0:00.00 couriertcpd
2469 root 20 0 27932 380 0 S 0.0 0.0 0:00.00 authdaemond
2470 root 20 0 27932 380 0 S 0.0 0.0 0:00.00 authdaemond
2471 root 20 0 27932 380 0 S 0.0 0.0 0:00.00 authdaemond
2472 root 20 0 27932 380 0 S 0.0 0.0 0:00.00 authdaemond
2473 root 20 0 27932 380 0 S 0.0 0.0 0:00.00 authdaemond
2501 messageb 20 0 29804 1104 796 S 0.0 0.0 0:00.00 dbus-daemon
2504 root 20 0 18880 964 732 S 0.0 0.0 0:00.00 cron
2548 www-data 20 0 209m 29m 676 S 0.0 0.4 0:00.02 /usr/sbin/apach
2549 clamav 20 0 51124 2648 1308 S 0.0 0.0 0:02.58 freshclam
2570 www-data 20 0 314m 36m 2440 S 0.0 0.5 0:00.20 /usr/sbin/apach
2571 www-data 20 0 314m 36m 2436 S 0.0 0.5 0:00.28 /usr/sbin/apach
2572 www-data 20 0 314m 36m 2440 S 0.0 0.5 0:00.20 /usr/sbin/apach
2573 www-data 20 0 314m 36m 2436 S 0.0 0.5 0:00.21 /usr/sbin/apach
2586 root 20 0 275m 10m 2484 S 0.0 0.1 0:01.80 fail2ban-server
2704 root 20 0 57060 14m 1804 S 0.0 0.2 0:00.25 lfd - sleeping
2819 root 20 0 33884 2392 224 S 0.0 0.0 0:00.00 nginx
2830 nginx 20 0 33888 3528 848 S 0.0 0.0 0:00.24 nginx
2851 root 20 0 4180 724 580 S 0.0 0.0 0:00.02 mysqld_safe
3180 mysql 20 0 435m 84m 7544 S 0.0 1.1 0:01.78 mysqld
3181 root 20 0 4088 624 524 S 0.0 0.0 0:00.00 logger
3230 www-data 20 0 314m 36m 2440 S 0.0 0.5 0:00.24 /usr/sbin/apach
3244 proftpd 20 0 97.8m 2064 620 S 0.0 0.0 0:00.00 proftpd
3359 root 20 0 245m 30m 6048 S 0.0 0.4 0:00.38 sw-engine
3664 root 20 0 19564 964 748 S 0.0 0.0 0:00.00 xinetd
3670 root 20 0 31244 1344 228 S 0.0 0.0 0:00.00 sw-cp-serverd
3671 sw-cp-se 20 0 31784 3232 1644 S 0.0 0.0 0:00.00 sw-cp-serverd
3805 root 20 0 115m 49m 2388 S 0.0 0.6 0:01.92 /usr/sbin/spamd
4002 popuser 20 0 115m 48m 900 S 0.0 0.6 0:00.00 spamd child
4003 popuser 20 0 115m 48m 912 S 0.0 0.6 0:00.00 spamd child
4018 root 20 0 49932 1212 600 S 0.0 0.0 0:00.00 sshd
4103 qmails 20 0 4140 596 480 S 0.0 0.0 0:00.00 qmail-send
4104 qmaill 20 0 4092 568 464 S 0.0 0.0 0:00.00 splogger
4105 root 20 0 4132 320 244 S 0.0 0.0 0:00.00 qmail-lspawn
4106 qmailr 20 0 4132 332 260 S 0.0 0.0 0:00.00 qmail-rspawn
4107 qmailq 20 0 4088 456 364 S 0.0 0.0 0:00.00 qmail-clean
4139 root 20 0 209m 2192 880 S 0.0 0.0 0:00.08 sw-collectd
4275 root 20 0 80620 21m 1668 S 0.0 0.3 0:00.01 miniserv.pl
4278 drweb 20 0 244m 239m 420 S 0.0 3.0 0:00.00 drwebd.real
4279 drweb 20 0 244m 239m 244 S 0.0 3.0 0:00.00 drwebd.real
4308 root 20 0 62852 1944 1480 S 0.0 0.0 0:00.02 login
4309 root 20 0 14756 964 800 S 0.0 0.0 0:00.00 getty
4310 root 20 0 14756 956 800 S 0.0 0.0 0:00.00 getty
4311 root 20 0 14756 956 800 S 0.0 0.0 0:00.00 getty
4312 root 20 0 14756 952 800 S 0.0 0.0 0:00.00 getty
4313 root 20 0 14756 964 800 S 0.0 0.0 0:00.00 getty
4340 www-data 20 0 314m 36m 2440 S 0.0 0.5 0:00.21 /usr/sbin/apach
4344 root 20 0 188m 3884 2800 S 0.0 0.0 0:00.04 console-kit-dae
4411 root 20 0 120m 3040 2516 S 0.0 0.0 0:00.00 polkitd
4421 root 20 0 18900 3092 1568 S 0.0 0.0 0:00.08 bash
4494 www-data 20 0 314m 36m 2436 S 0.0 0.5 0:00.20 /usr/sbin/apach
4501 www-data 20 0 314m 36m 2436 S 0.0 0.5 0:00.13 /usr/sbin/apach
4503 www-data 20 0 314m 36m 2424 S 0.0 0.5 0:00.24 /usr/sbin/apach
6475 www-data 20 0 314m 36m 2436 S 0.0 0.5 0:00.18 /usr/sbin/apach
27661 root 20 0 77724 3852 3024 S 0.0 0.0 0:00.01 sshd
27666 maurix 20 0 77724 1688 868 S 0.0 0.0 0:00.04 sshd
27667 maurix 20 0 21084 3912 1732 S 0.0 0.0 0:00.10 bash
27779 root 20 0 47808 1660 1280 S 0.0 0.0 0:00.00 su
27789 root 20 0 19408 2188 1624 S 0.0 0.0 0:00.00 bash
27802 root 20 0 13120 2172 1180 S 0.0 0.0 0:00.01 nano
27823 root 20 0 4180 576 488 S 0.0 0.0 0:00.00 sh
27824 root 20 0 21640 1308 956 R 0.0 0.0 0:00.00 top
Traffic;
0
37.120.162.151
206,86 MB
33,40 KB
206,89 MB
1
37.120.162.151
179,08 MB
48,74 KB
179,13 MB
2
37.120.162.151
207,44 MB
180,68 KB
207,62 MB
3
37.120.162.151
212,31 MB
979,02 KB
213,27 MB
4
37.120.162.151
196,91 MB
20,73 KB
196,93 MB
5
37.120.162.151
202,53 MB
20,20 KB
202,55 MB
6
37.120.162.151
206,31 MB
82,97 KB
206,39 MB
7
37.120.162.151
188,37 MB
109,11 KB
188,48 MB
8
37.120.162.151
196,36 MB
13,13 KB
196,37 MB
9
37.120.162.151
195,62 MB
87,02 KB
195,71 MB
10
37.120.162.151
187,95 MB
985,01 KB
188,91 MB
11
37.120.162.151
175,70 MB
5,78 MB
181,48 MB
Summe
2,30 GB
8,28 MB
2,31 GB
netcup Shop | netcup Wiki
netcup Kundenforum
netcup VCP - v4.1.7 - © netcup GmbH