我经常检查netstat --tcp
ssh到我的服务器,但今天发现了一个奇怪的连字符地址格式,我没有见过:
Proto Recv Sent Local Address Foreign Address State tcp6 0 0 mydomain.com:www xxx-xxx-xxx-xxx.bng:xxxx TIME_WAIT
这就像一个IP地址,X的代表数字,但被连字符我以为它可能已经是一个域名,除了“.BNG”不是一个tld。
我所能想到的就是思科的“宽带networking网关”,或许与我的主机有什么关系?
您看到的名称是反向DNS域中的任何名称,并且不一定是有效的。 无论他/她想要什么,networking的netadmin都可以反向DNS。 如果你想知道谁连接到你的服务器,你应该用netstat --tcp --numeric
来查看IP地址。
如果您想要知道哪个组织是IP地址的持有者,您可以使用whois
,这将告诉您谁是持有者。 数据分布在不同的whois服务器上,但最近的whois客户端可能会自动确定正确的服务器(我删除了一些输出以使其更易读/易懂):
$ whois 37.77.56.75 # # ARIN WHOIS data and services are subject to the Terms of Use # available at: https://www.arin.net/whois_tou.html # NetRange: 37.0.0.0 - 37.255.255.255 CIDR: 37.0.0.0/8 OriginAS: NetName: RIPE-37 NetHandle: NET-37-0-0-0-1 Parent: NetType: Allocated to RIPE NCC Comment: These addresses have been further assigned to users in Comment: the RIPE NCC region. Contact information can be found in Comment: the RIPE database at http://www.ripe.net/whois RegDate: 2010-11-30 Updated: 2011-01-17 Ref: http://whois.arin.net/rest/net/NET-37-0-0-0-1 ReferralServer: whois://whois.ripe.net:43 % This is the RIPE Database query service. % The objects are in RPSL format. % % The RIPE Database is subject to Terms and Conditions. % See http://www.ripe.net/db/support/db-terms-conditions.pdf % Information related to '37.77.56.64 - 37.77.56.95' % Abuse contact for '37.77.56.64 - 37.77.56.95' is '[email protected]' inetnum: 37.77.56.64 - 37.77.56.95 netname: STEFFANN-OFFICE1 descr: SJM Steffann Office country: NL admin-c: SJMS-RIPE tech-c: SJMS-RIPE status: ASSIGNED PA mnt-by: STEFFANN-MNT mnt-by: STEFFANN-AUTO-MNT source: RIPE # Filtered role: SJM Steffann NOC contact address: Tienwoningenweg 46 address: 7312 DN Apeldoorn address: The Netherlands admin-c: SJMS1-RIPE tech-c: SJMS1-RIPE abuse-mailbox: [email protected] nic-hdl: SJMS-RIPE mnt-by: STEFFANN-MNT source: RIPE # Filtered % Information related to '37.77.56.0/21AS57771' route: 37.77.56.0/21 descr: SJM Steffann origin: AS57771 mnt-by: STEFFANN-MNT source: RIPE # Filtered % This query was served by the RIPE Database Query Service version 1.60.2 (WHOIS3)
所以在这里你可以看到37.77.56.75属于networkingSTEFFANN-OFFICE1,这是我的办公室。 你也可以看到你应该联系[email protected]当你看到这个networking的滥用。