You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

VPS环境下MySQL意外关闭及疑似暴力登录攻击问题求助

VPS环境下MySQL意外关闭及疑似暴力登录攻击问题求助

大家好,我遇到了一个棘手的问题,想请各位帮忙分析一下。我的VPS配置是40GB SSD、2GB内存、2核CPU,只部署了一个基于LAMP栈的网站,之前为了适配业务需要的大查询,调整过一些MySQL参数。但最近MySQL出现了意外关闭的情况,同时日志里还出现了大量可疑的登录记录,具体情况如下:

一、环境信息

  • VPS配置:40GB SSD,2GB内存,2 vCPU
  • 操作系统:Ubuntu 18.04
  • MySQL版本:5.7.40-0ubuntu0.18.04.1(来自phpMyAdmin显示)
  • 架构:LAMP栈,仅托管单个网站

二、问题现象

  1. MySQL突发意外关闭,重启时多次失败,之后又自行恢复了服务
  2. 日志中出现大量Access denied for user 'root'@'[IP]'的记录,每分钟大概有40-80条,怀疑是暴力登录攻击

三、关键日志片段

1. MySQL启动时的崩溃恢复与表损坏报错

2023-01-07T15:44:25.668222Z 0 [Note] /usr/sbin/mysqld (mysqld 5.7.40-0ubuntu0.18.04.1) starting as process 2611 ...
...
2023-01-07T15:44:25.847647Z 0 [Note] InnoDB: Starting crash recovery.
...
2023-01-07T15:44:26.769828Z 0 [ERROR] /usr/sbin/mysqld: Table './mysql/user' is marked as crashed and should be repaired
2023-01-07T15:44:26.770359Z 0 [Warning] Checking table:   './mysql/user'
2023-01-07T15:44:26.770390Z 0 [ERROR] 1 client is using or hasn't closed the table properly
2023-01-07T15:44:26.770941Z 0 [ERROR] /usr/sbin/mysqld: Table './mysql/db' is marked as crashed and should be repaired
2023-01-07T15:44:26.771079Z 0 [Warning] Checking table:   './mysql/db'
2023-01-07T15:44:26.771090Z 0 [ERROR] 1 client is using or hasn't closed the table properly
...
2023-01-07T15:44:26.807455Z 0 [Note] /usr/sbin/mysqld: ready for connections.

2. MySQL启动失败(内存不足)的报错

2023-01-07T15:44:41.349236Z 0 [Note] InnoDB: Initializing buffer pool, total size = 512M, instances = 1, chunk size = 128M
2023-01-07T15:44:41.363054Z 0 [ERROR] InnoDB: mmap(137428992 bytes) failed; errno 12
2023-01-07T15:44:41.365838Z 0 [ERROR] InnoDB: Cannot allocate memory for the buffer pool
2023-01-07T15:44:41.365882Z 0 [ERROR] InnoDB: Plugin initialization aborted with error Generic error
2023-01-07T15:44:41.365902Z 0 [ERROR] Plugin 'InnoDB' init function returned error.
2023-01-07T15:44:41.365914Z 0 [ERROR] Plugin 'InnoDB' registration as a STORAGE ENGINE failed.
2023-01-07T15:44:41.365925Z 0 [ERROR] Failed to initialize builtin plugins.
2023-01-07T15:44:41.365932Z 0 [ERROR] Aborting
...

类似的启动失败日志重复了多次,直到15:47左右才成功完成启动。

3. 疑似暴力攻击的登录日志

2023-01-07T17:57:09.387532Z 469 [Note] Access denied for user 'root'@'185.159.162.210' (using password: NO)
2023-01-07T17:57:09.532129Z 470 [Note] Access denied for user 'root'@'185.159.162.210' (using password: YES)

这类记录每分钟会出现40-80条左右。

四、当前MySQL配置(/etc/mysql/mysql.conf.d/mysqld.cnf)

key_buffer_size         = 160M
max_allowed_packet      = 160M
thread_stack            = 192K
myisam-recover-options  = BACKUP
query_cache_type=1
query_cache_limit       = 500M
query_cache_size        = 700M
innodb_buffer_pool_size = 512M

求助问题

  1. 为什么MySQL会突发意外关闭,并且出现多次启动失败的情况?表损坏和内存分配失败之间有什么关联吗?
  2. 日志里大量的Access denied记录是不是暴力登录攻击?如果是的话,该怎么防范?
  3. 针对我当前的VPS配置(2GB内存),MySQL的参数配置是否合理?有没有需要调整的地方?

备注:内容来源于stack exchange,提问作者Tom Dee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 13:37:47