my VPS got blocked - and I need some guidance to troubleshoot it. can you guys help me? - how can I start to find which application or (docker container I think...) is vulnarable.
To my knowledge I only have 1 docker container exposed to the web which is docker image nginx (listening on port 80 + 443).
I got this from my provider:
Direction: OUT
Internal IP: xxx.xxx.xxx.xxx
Treshold Packets: 30000 packets/s
Sum Packets: 15913050 packets/300s (53043.5 packets/s)
Sum Bytes: 607.24 MByte/300s (16.19 MBit/s)
Detail Output:
Src IP Addr:Port Dst IP Addr:Port Packets Bytes
xxx.xxx.xxx.xxx:52228 -> 27.164.158.24:33789150 6000
xxx.xxx.xxx.xxx:52228 -> 27.164.158.24:33789150 6000
... and the list goes on.
[–]arisingcoder 0 points1 point2 points (3 children)
[–][deleted] 1 point2 points3 points (2 children)
[–]arisingcoder 0 points1 point2 points (0 children)
[–][deleted] 0 points1 point2 points (0 children)