稼働中のPCやら衝動買いしたPCやら実験やら破壊やら構築やら。
情報としての価値はほぼなし。
なんていうか完全に自己満足。
要するについてくる人が居ないのでこっちに書くだけの話っていうかチラシの裏。
※あと、お仕事募集中
コンタクトはk.haramai[atmark]gmail.com まで。

2009/06/08

これはDDoS攻撃だ。

数日前から気がついた。
httpdのログを眺めていたのだが、naverというところからのアクセスが非常に多い。
非常にってどれくらい?って言われそうだけど。

6月に入ってからのWebalizerの集計によると・・・
1位 2241件 70.87% Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)
だそうだ。

何を見られているのかというと簡単な話でapacheのmanualページ。
見られてもどうって事ないというかトップページからクロールしているだけなんだろうけれど気持ち悪い。
非常に気持ちが悪い。

なんでそんなに気持ちが悪いっていうと、相手がKoreaだということ。

というわけで、ログをさらします。
(一部)
---
61.247.222.44 - - [08/Jun/2009:06:28:02 +0900] "GET /manual/ru/de/mod/beos.html HTTP/1.1" 404 309 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.47 - - [08/Jun/2009:06:28:10 +0900] "GET /manual/ru/style/css/manual.css HTTP/1.1" 200 18674 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.47 - - [08/Jun/2009:06:28:10 +0900] "GET /manual/ru/style/css/manual-loose-100pc.css HTTP/1.1" 200 3065 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.47 - - [08/Jun/2009:06:28:11 +0900] "GET /manual/ru/style/css/manual-print.css HTTP/1.1" 200 13200 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.56 - - [08/Jun/2009:06:28:35 +0900] "GET /manual/ru/es/mod/beos.html HTTP/1.1" 404 309 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.55 - - [08/Jun/2009:06:29:13 +0900] "GET /manual/ru/ko/mod/beos.html HTTP/1.1" 404 309 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.45 - - [08/Jun/2009:06:29:40 +0900] "GET /manual/ru/en/mod/mpm_netware.html HTTP/1.1" 404 316 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.45 - - [08/Jun/2009:06:30:01 +0900] "GET /manual/de/en/server-wide.html HTTP/1.1" 404 312 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.54 - - [08/Jun/2009:06:30:58 +0900] "GET /manual/fr/rewrite/rewrite_guide.html HTTP/1.1" 200 28700 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.45 - - [08/Jun/2009:06:31:18 +0900] "GET /manual/de/ko/server-wide.html HTTP/1.1" 404 312 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.54 - - [08/Jun/2009:06:31:25 +0900] "GET /manual/fr/rewrite/rewrite_guide_advanced.html HTTP/1.1" 200 46798 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.45 - - [08/Jun/2009:06:31:49 +0900] "GET /manual/en/mod/mod_authz_dbm.html HTTP/1.1" 200 11538 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.54 - - [08/Jun/2009:06:32:13 +0900] "GET /manual/en/mod/mod_cern_meta.html HTTP/1.1" 200 8386 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.50 - - [08/Jun/2009:06:32:37 +0900] "GET /manual/fr/style/css/manual.css HTTP/1.1" 200 18674 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.50 - - [08/Jun/2009:06:32:37 +0900] "GET /manual/fr/style/css/manual-loose-100pc.css HTTP/1.1" 200 3065 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.50 - - [08/Jun/2009:06:32:38 +0900] "GET /manual/fr/style/css/manual-print.css HTTP/1.1" 200 13200 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.44 - - [08/Jun/2009:06:32:39 +0900] "GET /manual/ko/en/new_features_2_2.html HTTP/1.1" 404 317 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.48 - - [08/Jun/2009:06:32:49 +0900] "GET /manual/fr/style/css/manual.css HTTP/1.1" 200 18674 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.55 - - [08/Jun/2009:06:32:50 +0900] "GET /manual/ko/ko/new_features_2_2.html HTTP/1.1" 404 317 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.47 - - [08/Jun/2009:06:32:52 +0900] "GET /manual/en/style/css/manual.css HTTP/1.1" 200 18674 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.47 - - [08/Jun/2009:06:32:53 +0900] "GET /manual/en/style/css/manual-loose-100pc.css HTTP/1.1" 200 3065 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.47 - - [08/Jun/2009:06:32:53 +0900] "GET /manual/en/style/css/manual-print.css HTTP/1.1" 200 13200 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.48 - - [08/Jun/2009:06:32:53 +0900] "GET /manual/fr/style/css/manual-loose-100pc.css HTTP/1.1" 200 3065 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.48 - - [08/Jun/2009:06:32:54 +0900] "GET /manual/fr/style/css/manual-print.css HTTP/1.1" 200 13200 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.55 - - [08/Jun/2009:06:33:09 +0900] "GET /manual/ko/pt-br/new_features_2_2.html HTTP/1.1" 404 320 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.55 - - [08/Jun/2009:06:33:28 +0900] "GET /manual/ko/programs/httxt2dbm.html HTTP/1.1" 200 5077 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.48 - - [08/Jun/2009:06:33:40 +0900] "GET /manual/en/style/css/manual.css HTTP/1.1" 200 18674 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.48 - - [08/Jun/2009:06:33:41 +0900] "GET /manual/en/style/css/manual-loose-100pc.css HTTP/1.1" 200 3065 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.48 - - [08/Jun/2009:06:33:41 +0900] "GET /manual/en/style/css/manual-print.css HTTP/1.1" 200 13200 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.54 - - [08/Jun/2009:06:34:13 +0900] "GET /manual/en/en/mod/mod_authz_dbm.html HTTP/1.1" 404 318 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.50 - - [08/Jun/2009:06:34:21 +0900] "GET /manual/ko/style/css/manual.css HTTP/1.1" 200 18674 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.50 - - [08/Jun/2009:06:34:22 +0900] "GET /manual/ko/style/css/manual-loose-100pc.css HTTP/1.1" 200 3065 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.50 - - [08/Jun/2009:06:34:22 +0900] "GET /manual/ko/style/css/manual-print.css HTTP/1.1" 200 13200 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.44 - - [08/Jun/2009:06:34:41 +0900] "GET /manual/en/ko/mod/mod_authz_dbm.html HTTP/1.1" 404 318 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.44 - - [08/Jun/2009:06:35:03 +0900] "GET /manual/en/en/mod/mod_cern_meta.html HTTP/1.1" 404 318 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.55 - - [08/Jun/2009:06:35:29 +0900] "GET /manual/en/ko/mod/mod_cern_meta.html HTTP/1.1" 404 318 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.54 - - [08/Jun/2009:06:35:41 +0900] "GET /manual/fr/en/mod/mod_speling.html HTTP/1.1" 404 316 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.44 - - [08/Jun/2009:06:36:09 +0900] "GET /manual/fr/ja/mod/mod_speling.html HTTP/1.1" 404 316 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.44 - - [08/Jun/2009:06:36:40 +0900] "GET /manual/fr/ko/mod/mod_speling.html HTTP/1.1" 404 316 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.54 - - [08/Jun/2009:06:36:55 +0900] "GET /manual/de/es/install.html HTTP/1.1" 404 308 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.54 - - [08/Jun/2009:06:37:18 +0900] "GET /manual/ko/en/faq/all_in_one.html HTTP/1.1" 404 315 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.44 - - [08/Jun/2009:06:37:44 +0900] "GET /manual/ko/ja/faq/all_in_one.html HTTP/1.1" 404 315 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.55 - - [08/Jun/2009:06:38:10 +0900] "GET /manual/ko/ko/faq/all_in_one.html HTTP/1.1" 404 315 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.56 - - [08/Jun/2009:06:38:13 +0900] "GET /manual/de/mod/mod_log_referer.html HTTP/1.1" 404 317 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.54 - - [08/Jun/2009:06:38:47 +0900] "GET /manual/ko/en/developer/ HTTP/1.1" 404 306 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
61.247.222.44 - - [08/Jun/2009:06:39:02 +0900] "GET /manual/ko/developer/thread_safety.html HTTP/1.1" 200 15961 "-" "Yeti/1.0 (NHN Corp.; http://help.naver.com/robots/)"
---

正直コレだけのIPからやられると非力なVMで動いてるサーバがかわいそうなので今後一切ご遠慮いただきたい。
そもそもKorea情報は一切無いので来ないでください。

Firewallで弾こうかとも思ったんだけど、それでもEth0までは届いてしまうのでルーターで止めた。
上記IPだけじゃ物足りないので、whoisから調べてIPレンジごと止めた。

---
inetnum: 61.247.192.0 - 61.247.223.255
netname: NHN-NET
descr: NHN
country: KR
---

朝から気持ちが悪いなぁ・・・(夕べの酒が残ってるとは言わない)

0 件のコメント: