本帖最后由 城南旧事_2012 于 2017-12-18 02:18 编辑
首先这里说下真假蜘蛛我的理解,在http://www.so.com/help/spider_ip.html 公布的IP是真,反之是假。
近期网站被CC攻击严重,查询IIS记录,发现大量假360蜘蛛在随机通过搜索关键词访问网站,由于不断变化条件结果,IP多,CC难防。如图:
360社区
其中180.153.232.170,这个IP是真蜘蛛,大部分访问均是通过条件搜索,访问明细截图如下
360社区
假蜘蛛 42.236.10.110,这个IP不在公布列表,访问明细截图如下
360社区
大致统计了假蜘蛛
(官方公布无10段)
42.236.10.110
42.236.10.111
42.236.10.112
(官方公布无31段)
42.236.31.140
42.236.31.139
42.236.31.137
(官方公布无39段)
42.236.39.156
42.236.39.157
42.236.39.140
42.236.39.167
42.236.39.185
42.236.39.171
42.236.39.160
(官方公布无48)
42.236.48.117
42.236.48.180
42.236.48.102
42.236.48.213
42.236.48.145
42.236.48.84
42.236.48.149
42.236.48.244
42.236.48.184
42.236.48.38
42.236.48.98
42.236.48.99
42.236.48.162
42.236.48.120
(官方公布无49)
42.236.49.166
42.236.49.34
42.236.49.19
42.236.49.84
42.236.49.56
42.236.49.245
42.236.49.80
42.236.49.82
42.236.49.37
(官方公布无50)
42.236.50.18
42.236.50.44
42.236.50.48
42.236.50.108
42.236.50.180
(官方公布范围42.236.102.2~42)
42.236.102.157
42.236.102.145
42.236.102.236
42.236.102.226
42.236.102.144
42.236.102.204
42.236.102.154
42.236.102.172
42.236.102.173
42.236.102.199
42.236.102.166
42.236.102.139
42.236.102.161
42.236.102.201
42.236.102.235
有多少真蜘蛛在同一时间以同样记录形式访问网站,统计如下
180.153.236.181
180.153.236.133
180.153.236.165
180.153.236.101
180.153.236.19
180.153.236.109
180.153.236.11
180.153.236.43
180.153.236.173
180.153.236.157
180.153.236.35
180.153.236.170
180.153.236.125
180.153.234.145
180.153.236.59
180.153.236.51
180.153.236.149
180.153.236.189
180.153.236.117
180.153.232.170
结论,所有的真蜘蛛和假蜘蛛不约而同的随机访问不同的地址一次,基本上不重复。360,你还好吗?
|
|
|
|
评论
直达楼层