bwh1 上 Sony 黑客活动? - V2EX
V2EX = way to explore
V2EX 是一个关于分享和探索的地方
现在注册
已注册用户请  登录
tongtongqiang
V2EX    问与答

bwh1 上 Sony 黑客活动?

  •  
  •   tongtongqiang 2017-05-29 10:54:57 +08:00 2582 次点击
    这是一个创建于 3110 天前的主题,其中的信息可能已经有所发展或是发生改变。
    This service is currently suspended. There is 1 outstanding issue:
    Reason: Hacked/rooted server
    More details: We have detected hacking activity on this server
    Additional information:


    To whom it may concern,

    Pursuant to Sony Interactive Entertainment LLC ("SIE") corporate policy, the below IP addresses were blacklisted from using our services because SIE detected activity that is abusive to our network services. In our determination, the abusive activity was not related to velocity or volume (many users behind the same IP address, i.e. NAT), but matched the specific patterns of known abuse of our publicly available services. This abuse may be the result of a computer on your network that has been compromised and is participating in a botnet abuse of our services.

    The following table of IP addresses, dates and times should help you correlate the origin of the abusive activity. The time stamps are approximate from our logs. The actual timing of the events depend on the signature matched. It is very likely to have occurred both before, during and following the times listed.

    Approximate Time Range (UTC), IP Address, Reason
    2017-05-27 03:27 ~ 2017-05-27 03:57 (UTC), 138.123.178.101, Account Takeover Attempts

    It is most likely the attack traffic is directed at one of the following endpoints:

    account.sonyentertainmentnetwork.com
    auth.np.ac.playstation.net
    auth.api.sonyentertainmentnetwork.com
    auth.api.np.ac.playstation.net

    These endpoints on our network are resolved by Geo DNS, so the IP addresses they resolve to will depend on the originating IP address.

    The destination port will be TCP 443.

    Please take the necessary measures to correct the malicious activity from the above-listed IP addresses as soon as possible to avoid any further disruptions. If we were to remove any of these IP addresses from the blacklist and subsequent abusive activity is detected, the IP address will be promptly blacklisted again.


    We thank you for your prompt attention to this matter. If you require assistance or additional information please contact [email protected] and include the IP address in question.

    Thank you

    P.S. If you would prefer an individual email for each IP address on this list, please let us know.


    How to resolve: The server has been compromised. Make sure you install clean OS immediately after resuming service, otherwise the issue will repeat.
    You can unsuspend a service 3 times in one calendar year.
    Remaining unsuspensions for this server: 3

    I understand the issue and ready to resolve it right away
    By clicking the button above you agree to take all measures to prevent future TOS violations.
    You also acknowledge that after 3 suspensions this server will be disabled until January 1, 2018.
    1 条回复    2017-05-29 12:48:27 +08:00
    ARCWelder
        1
    ARCWelder  
       2017-05-29 12:48:27 +08:00 via Android
    ssh 被爆破了或者 SS 被扫出来用作代理池了,就是你的机器被用于 DDoS 索尼的服务。如果没有什么重要的东西建议重装

    还有,谷歌翻译是个好东西,如果你看不懂英语的话。
    关于     帮助文档     自助推广系统     博客     API     FAQ     Solana     4460 人在线   最高记录 6679       Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 26ms UTC 04:01 PVG 12:01 LAX 20:01 JFK 23:01
    Do have faith in what you're doing.
    ubao msn snddm index pchome yahoo rakuten mypaper meadowduck bidyahoo youbao zxmzxm asda bnvcg cvbfg dfscv mmhjk xxddc yybgb zznbn ccubao uaitu acv GXCV ET GDG YH FG BCVB FJFH CBRE CBC GDG ET54 WRWR RWER WREW WRWER RWER SDG EW SF DSFSF fbbs ubao fhd dfg ewr dg df ewwr ewwr et ruyut utut dfg fgd gdfgt etg dfgt dfgd ert4 gd fgg wr 235 wer3 we vsdf sdf gdf ert xcv sdf rwer hfd dfg cvb rwf afb dfh jgh bmn lgh rty gfds cxv xcv xcs vdas fdf fgd cv sdf tert sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf shasha9178 shasha9178 shasha9178 shasha9178 shasha9178 liflif2 liflif2 liflif2 liflif2 liflif2 liblib3 liblib3 liblib3 liblib3 liblib3 zhazha444 zhazha444 zhazha444 zhazha444 zhazha444 dende5 dende denden denden2 denden21 fenfen9 fenf619 fen619 fenfe9 fe619 sdf sdf sdf sdf sdf zhazh90 zhazh0 zhaa50 zha90 zh590 zho zhoz zhozh zhozho zhozho2 lislis lls95 lili95 lils5 liss9 sdf0ty987 sdft876 sdft9876 sdf09876 sd0t9876 sdf0ty98 sdf0976 sdf0ty986 sdf0ty96 sdf0t76 sdf0876 df0ty98 sf0t876 sd0ty76 sdy76 sdf76 sdf0t76 sdf0ty9 sdf0ty98 sdf0ty987 sdf0ty98 sdf6676 sdf876 sd876 sd876 sdf6 sdf6 sdf9876 sdf0t sdf06 sdf0ty9776 sdf0ty9776 sdf0ty76 sdf8876 sdf0t sd6 sdf06 s688876 sd688 sdf86