Buenas tardes, tengo un prolema con un servidor vps de hetzner me ha bloqueado la ip porque indican que este sufrió un ataque de amplificación cldap.
Motivo por el cual el área de Soporte nos manifiesta que el responsable de todo es el Servicio ldap que está activo en nuestro vps, no sabemos como detectarlo y desconectarlo o pausar los servicios.
Please get in contact with your System Administrator in order to resolve this problem.
The LDAP service is still publicly available and is answering to requests.
-----------------%<-----------------
╰─❯ Ldapsearch -H ldap://65.21.249.20 -x -s base
# extended LDIF
#
# LDAPv3
# base <> (default) with scope baseObject
# filter: (objectclass=*)
# requesting: ALL
#
#
dn:
domainFunctionality: 7
forestFunctionality: 7
domainControllerFunctionality: 7
rootDomainNamingContext: DC=Tecflusac,DC=local
ldapServiceName:
Tecflusac.local:server$
@TECFLUSAC.LOCAL
isGlobalCatalogReady: TRUE
supportedSASLMechanisms: GSSAPI
Supportedsaslmechanisms: gss-spnego
supportedsaslmechanisms: external
supportedsaslmechanisms: digest-md5
supportedldapversion: 3
supportedldapversion: 2
supportedldappolicies: maxpoolthreads
supportedldappolicies: maxpercentdirsyncrequests
supportedldappolicies: maxdatagramrecv
supportedldappolicies: maxreceivebuffer
supportedldappolicies: initrecvtimeout
supportedldappolicies: maxconnections
supportedldappolicies: maxconnidletime
supportedldappolicies: maxpagesize
supportedldappolicies: maxbatchreturnmessages
supportedldappolicies: maxqueryduration
supportedldappolicies: maxdirsyncduration
supportedldappolicies: maxtemptablesize
supportedldappolicies: maxresultsetsize
supportedldappolicies: minresultsets
supportedldappolicies: maxresultsetsperconn
supportedldappolicies: maxnotificationperconn
supportedldappolicies: maxvalrange
supportedldappolicies: maxvalrangetransitive
supportedldappolicies: threadmemorylimit
supportedldappolicies: systemmemorylimitpercent
supportedcontrol: 1.2.840.113556.1.4.319
supportedControl: 1.2.840.113556.1.4.801
supportedControl: 1.2.840.113556.1.4.473
supportedControl: 1.2.840.113556.1.4.528
supportedControl: 1.2.840.113556.1.4.417
supportedControl: 1.2.840.113556.1.4.619
supportedControl: 1.2.840.113556.1.4.841
supportedControl: 1.2.840.113556.1.4.529
supportedControl: 1.2.840.113556.1.4.805
supportedControl: 1.2.840.113556.1.4.521
supportedControl: 1.2.840.113556.1.4.970
supportedControl: 1.2.840.113556.1.4.1338
supportedControl: 1.2.840.113556.1.4.474
supportedControl: 1.2.840.113556.1.4.1339
supportedControl: 1.2.840.113556.1.4.1340
supportedControl: 1.2.840.113556.1.4.1413
supportedControl: 2.16.840.1.113730.3.4.9
supportedControl: 2.16.840.1.113730.3.4.10
supportedControl: 1.2.840.113556.1.4.1504
supportedControl: 1.2.840.113556.1.4.1852
supportedControl: 1.2.840.113556.1.4.802
supportedControl: 1.2.840.113556.1.4.1907
supportedControl: 1.2.840.113556.1.4.1948
supportedControl: 1.2.840.113556.1.4.1974
supportedControl: 1.2.840.113556.1.4.1341
supportedControl: 1.2.840.113556.1.4.2026
supportedControl: 1.2.840.113556.1.4.2064
supportedControl: 1.2.840.113556.1.4.2065
supportedControl: 1.2.840.113556.1.4.2066
supportedControl: 1.2.840.113556.1.4.2090
supportedControl: 1.2.840.113556.1.4.2205
supportedControl: 1.2.840.113556.1.4.2204
supportedControl: 1.2.840.113556.1.4.2206
supportedControl: 1.2.840.113556.1.4.2211
supportedControl: 1.2.840.113556.1.4.2239
supportedControl: 1.2.840.113556.1.4.2255
supportedControl: 1.2.840.113556.1.4.2256
supportedControl: 1.2.840.113556.1.4.2309
supportedControl: 1.2.840.113556.1.4.2330
supportedControl: 1.2.840.113556.1.4.2354
supportedCapabilities: 1.2.840.113556.1.4.800
supportedCapabilities: 1.2.840.113556.1.4.1670
supportedCapabilities: 1.2.840.113556.1.4.1791
supportedCapabilities: 1.2.840.113556.1.4.1935
supportedCapabilities: 1.2.840.113556.1.4.2080
supportedCapabilities: 1.2.840.113556.1.4.2237
subschemaSubentry: CN=Aggregate,CN=Schema,CN=Configuration,DC=Tecflusac,DC=loc
al
Servername: cn=server,cn=servers,cn=default-first-site-name,cn=sites,cn=config
uration,dc=tecflusac,dc=local
schemanamingcontext: cn=schema,cn=configuration,dc=tecflusac,dc=local
namingcontexts: dc=tecflusac,dc=local
namingcontexts: cn=configuration,dc=tecflusac,dc=local
namingcontexts: cn=schema,cn=configuration,dc=tecflusac,dc=local
namingcontexts: dc=domaindnszones,dc=tecflusac,dc=local
namingcontexts: dc=forestdnszones,dc=tecflusac,dc=local
issynchronized: true
highestcommittedusn: 31482042
dsservicename: cn=ntds settings,cn=server,cn=servers,cn=default-first-site-nam
e,cn=sites,cn=configuration,dc=tecflusac,dc=local
dnshostname:
server.Tecflusac.local
defaultNamingContext: DC=Tecflusac,DC=local
currentTime: 20220613211652.0Z
configurationNamingContext: CN=Configuration,DC=Tecflusac,DC=local
Plazo de Entrega: 14 Junio, 2022