
求一個(gè)IIS安全策略cport超過10000以上的自動(dòng)封禁腳本各位大家好??;由于本人網(wǎng)站長(zhǎng)時(shí)間收到一些人CC和 DOOS攻擊;在網(wǎng)上也找了一些IP安全策略的方法,但是是可以實(shí)現(xiàn) 不過有時(shí)候會(huì)把正常的IP也給封禁了!郁悶至極~!、例子:#Software: Microsoft HTTP API 1.0#Version: 1.0#Date: -10-09 04:04:24#Fields: date time c-ip c-port s-ip s-port cs-version cs-method cs-uri sc-status s-siteid s-reason s-queuename-10-09 06:54:18 37.130.227.133 44382 125.102.20.128 80 HTTP/1.1 GET /forum.php?mod=viewthread&tid=859 503 894523 N/A DefaultAppPool-10-09 06:54:19 37.130.227.133 53954 125.102.20.128 80 HTTP/1.1 GET /forum.php?mod=viewthread&tid=859 503 894523 N/A DefaultAppPool-10-09 06:54:19 1.2.173.193 60990 125.102.20.128 80 HTTP/1.1 GET /forum.php?mod=viewthread&tid=859 503 894523 N/A DefaultAppPool-10-09 06:54:22 1.2.173.193 49635 125.102.20.128 80 HTTP/1.1 GET /forum.php?mod=viewthread&tid=859 503 894523 N/A DefaultAppPool-10-09 06:54:23 1.2.173.193 43659 125.102.20.128 80 HTTP/1.1 GET /forum.php?mod=viewthread&tid=859 503 894523 N/A DefaultAppPool-10-09 06:54:24 1.2.173.193 42036 125.102.20.128 80 HTTP/1.1 GET /forum.php?mod=viewthread&tid=859 503 894523 N/A DefaultAppPool-10-09 06:54:26 1.2.173.193 43702 125.102.20.128 80 HTTP/1.1 GET /forum.php?mod=viewthread&tid=859 503 894523 N/A DefaultAppPool-10-09 06:54:27 1.2.173.193 36513 125.102.20.128 80 HTTP/1.1 GET /forum.php?mod=viewthread&tid=859 503 894523 N/A DefaultAppPool-10-09 06:54:29 65.120.221.222 9489 125.102.20.128 80 HTTP/1.1 GET /forum.php?mod=viewthread&tid=859 503 894523 N/A DefaultAppPool-10-09 06:54:29 65.120.221.222 9479 125.102.20.128 80 HTTP/1.1 GET /forum.php?mod=viewthread&tid=859 503 894523 N/A DefaultAppPool-10-09 06:57:53 225.12.210.25 1157 125.102.20.128 80 HTTP/1.1 GET /forum.php - 601108812 Connection_Dropped DefaultAppPool-10-09 06:58:48 225.12.210.25 1155 125.102.20.128 80 - - - - - Timer_ConnectionIdle --10-09 07:00:53 225.12.210.25 1158 125.102.20.128 80 HTTP/1.1 GET /plugin.php?id=dsu_paulsign:sign - 601108812 Connection_Dropped DefaultAppPool-10-09 07:04:13 225.12.210.25 1161 125.102.20.128 80 HTTP/1.1 GET /forum.php - 601108812 Connection_Abandoned_By_AppPool DefaultAppPool-10-09 07:05:32 225.12.210.25 1174 125.102.20.128 80 HTTP/1.1 GET /forum.php - 601108812 Connection_Abandoned_By_AppPool DefaultAppPool說明: c-port 這一欄 是外部端口號(hào) 我的想法是它 大于 10000 的話—篩選出來—?jiǎng)h除重復(fù)IP—然后再 自動(dòng)加入屏蔽IP安全策略列表里面注意: c-port 外部端口號(hào)不是固定的!就是下面這種:
以上就是禁止外部非法IP 訪問80端口的安全策略,能全自動(dòng)的腳本處理就最好了,c-port端口號(hào)> 10000以上的 實(shí)現(xiàn)自動(dòng)封禁謝謝各位大大了!nclick="copycode($('code0'));">復(fù)制代碼
- psec static add policy name=XBLUE
- netsh ipsec static add filterlist name=denyip
- netsh ipsec static add filter filterlist=denyip srcaddr=37.130.227.133 dstaddr=Me dstport=80 protocol=TCP
- netsh ipsec static add filter filterlist=denyip srcaddr=1.2.173.193 dstaddr=Me dstport=80 protocol=TCP
- netsh ipsec static add filteraction name=denyact action=block
- netsh ipsec static add rule name=kill3389 policy=XBLUE filterlist=denyip filteraction=denyact
- netsh ipsec static set policy name=XBLUE assign=y

