Miracle MU server was hacked how to solve?

As game administrators, they all like to choose high-defense servers to run games, because the gaming industry has large traffic and fierce competition, making it easier to become a target for hackers. I often walk by the water, so how can I not get my shoes wet? What if our server is hacked? Feifei will share it with you today.

1. Disconnect all network connections

Attacks on the server all originate from the network. Therefore, when the server is attacked, the network connection must be disconnected as soon as possible. On the one hand, it can quickly cut off the source of the attack, and on the other hand, it can also protect other hosts on the network where the server is located.

2. Find the attacking IP through the system log/monitoring software

To know the attacker's IP, you can analyze the system log or monitoring software to find suspicious information for investigation. After finding the attacking IP, you can block it. However, blocking the IP may not be effective when the amount of attacks is large.

3. Analyze system vulnerabilities through system logs/monitoring software

The reason why an attacker can launch an attack must be by exploiting a system vulnerability or a certain service port. By analyzing system logs and monitoring software, we can analyze how the attacker intruded. For example, if the game gateway port is used, it is recommended to change to an infrequently used port, and close unnecessary ports.

4. Back up system data

Regular backup Feifei has said many times that no matter what the business is, if you encounter attacks, intrusions, poisoning, etc., having backup files can reduce the risk in the worst case. If you are backing up when you encounter an attack or poisoning, be sure to check whether the backup data is mixed with the source of the attack, and delete it in time if there is.

5. Reinstall the system

If the system can be reinstalled after being attacked/intruded, it is recommended to reinstall the system because it is not completely certain how the attacker launched the attack. Reinstalling the system can completely eliminate the source of the attack.

The above are some solutions about the server being attacked. The server base camp will help you become a more professional server administrator!

Guess you like

Origin blog.csdn.net/JUFENG_FEI/article/details/132058836