VPS环境下MySQL意外关闭及疑似暴力登录攻击问题求助
VPS环境下MySQL意外关闭及疑似暴力登录攻击问题求助
大家好,我遇到了一个棘手的问题,想请各位帮忙分析一下。我的VPS配置是40GB SSD、2GB内存、2核CPU,只部署了一个基于LAMP栈的网站,之前为了适配业务需要的大查询,调整过一些MySQL参数。但最近MySQL出现了意外关闭的情况,同时日志里还出现了大量可疑的登录记录,具体情况如下:
一、环境信息
- VPS配置:40GB SSD,2GB内存,2 vCPU
- 操作系统:Ubuntu 18.04
- MySQL版本:5.7.40-0ubuntu0.18.04.1(来自phpMyAdmin显示)
- 架构:LAMP栈,仅托管单个网站
二、问题现象
- MySQL突发意外关闭,重启时多次失败,之后又自行恢复了服务
- 日志中出现大量
Access denied for user 'root'@'[IP]'的记录,每分钟大概有40-80条,怀疑是暴力登录攻击
三、关键日志片段
1. MySQL启动时的崩溃恢复与表损坏报错
2023-01-07T15:44:25.668222Z 0 [Note] /usr/sbin/mysqld (mysqld 5.7.40-0ubuntu0.18.04.1) starting as process 2611 ... ... 2023-01-07T15:44:25.847647Z 0 [Note] InnoDB: Starting crash recovery. ... 2023-01-07T15:44:26.769828Z 0 [ERROR] /usr/sbin/mysqld: Table './mysql/user' is marked as crashed and should be repaired 2023-01-07T15:44:26.770359Z 0 [Warning] Checking table: './mysql/user' 2023-01-07T15:44:26.770390Z 0 [ERROR] 1 client is using or hasn't closed the table properly 2023-01-07T15:44:26.770941Z 0 [ERROR] /usr/sbin/mysqld: Table './mysql/db' is marked as crashed and should be repaired 2023-01-07T15:44:26.771079Z 0 [Warning] Checking table: './mysql/db' 2023-01-07T15:44:26.771090Z 0 [ERROR] 1 client is using or hasn't closed the table properly ... 2023-01-07T15:44:26.807455Z 0 [Note] /usr/sbin/mysqld: ready for connections.
2. MySQL启动失败(内存不足)的报错
2023-01-07T15:44:41.349236Z 0 [Note] InnoDB: Initializing buffer pool, total size = 512M, instances = 1, chunk size = 128M 2023-01-07T15:44:41.363054Z 0 [ERROR] InnoDB: mmap(137428992 bytes) failed; errno 12 2023-01-07T15:44:41.365838Z 0 [ERROR] InnoDB: Cannot allocate memory for the buffer pool 2023-01-07T15:44:41.365882Z 0 [ERROR] InnoDB: Plugin initialization aborted with error Generic error 2023-01-07T15:44:41.365902Z 0 [ERROR] Plugin 'InnoDB' init function returned error. 2023-01-07T15:44:41.365914Z 0 [ERROR] Plugin 'InnoDB' registration as a STORAGE ENGINE failed. 2023-01-07T15:44:41.365925Z 0 [ERROR] Failed to initialize builtin plugins. 2023-01-07T15:44:41.365932Z 0 [ERROR] Aborting ...
类似的启动失败日志重复了多次,直到15:47左右才成功完成启动。
3. 疑似暴力攻击的登录日志
2023-01-07T17:57:09.387532Z 469 [Note] Access denied for user 'root'@'185.159.162.210' (using password: NO) 2023-01-07T17:57:09.532129Z 470 [Note] Access denied for user 'root'@'185.159.162.210' (using password: YES)
这类记录每分钟会出现40-80条左右。
四、当前MySQL配置(/etc/mysql/mysql.conf.d/mysqld.cnf)
key_buffer_size = 160M max_allowed_packet = 160M thread_stack = 192K myisam-recover-options = BACKUP query_cache_type=1 query_cache_limit = 500M query_cache_size = 700M innodb_buffer_pool_size = 512M
求助问题
- 为什么MySQL会突发意外关闭,并且出现多次启动失败的情况?表损坏和内存分配失败之间有什么关联吗?
- 日志里大量的Access denied记录是不是暴力登录攻击?如果是的话,该怎么防范?
- 针对我当前的VPS配置(2GB内存),MySQL的参数配置是否合理?有没有需要调整的地方?
备注:内容来源于stack exchange,提问作者Tom Dee
相关产品推荐
相关产品推荐

