所以上周,一个关于EC2的实例停止响应,我仍然不知道为什么因为我不能再进入SSH,我怀疑安装到另一个驱动器的/ tmp /目录因某些未知原因而无法访问.
我有一些非常重要的文件,我需要从这台服务器上下来…
我仍然能够在AWS控制台中提取日志,这里有一些非常相关的行(我仍然能够重启服务器):
- Welcome to CentOS release 5.4 (Final)
- Press 'I' to enter interactive startup.
- Cannot access the Hardware Clock via any known method.
- Use the --debug option to see the details of our search for an access method.
- Setting clock : Thu Dec 29 13:52:43 EST 2011 [ OK ]
- Starting udev: [ OK ]
- Setting hostname localhost.localdomain: [ OK ]
- No devices found
- Setting up Logical Volume Management: File descriptor 7 (/sys/kernel/hotplug) leaked on lvm.static invocation. Parent PID 232: /bin/bash
- [ OK ]
- Checking filesystems
- Checking all file systems.
- [/sbin/fsck.ext3 (1) -- /] fsck.ext3 -a /dev/sda1
- /dev/sda1: clean,202786/1310720 files,1428718/2621440 blocks
- [ OK ]
- Remounting root filesystem in read-write mode: [ OK ]
- Mounting local filesystems: [ OK ]
- Enabling local filesystem quotas: [ OK ]
- chown: cannot access `/tmp/.ICE-unix': No such file or directory
- Enabling /etc/fstab swaps: [ OK ]
- INIT: Entering runlevel: 4
- Entering non-interactive startup
- Starting background readahead: [ OK ]
- Bringing up loopback interface: [ OK ]
- Bringing up interface eth0:
- Determining IP information for eth0...mktemp: cannot create temp file /tmp/wnt890: No such file or directory
- /sbin/dhclient-script: line 57: $rscf: ambiguous redirect
- /sbin/dhclient-script: line 62: $rscf: ambiguous redirect
- /sbin/dhclient-script: line 69: $rscf: ambiguous redirect
- done.
- [ OK ]
- Starting getsshkey: /etc/rc4.d/S11getsshkey: line 12: /tmp/my-key: No such file or directory
- getting ssh-key...
- /etc/rc4.d/S11getsshkey: line 17: /tmp/my-key: No such file or directory
- getting ssh-key...
我确定它不是防火墙问题.这是nmap的输出
- [root@ip-xxxxxxxxx ~]# nmap -sS -P0 xxxxxxxxxxx
- Starting Nmap 4.11 ( http://www.insecure.org/nmap/ ) at 2011-12-29 16:32 EST
- Interesting ports on xxxxxx (xxxxxxxxx):
- Not shown: 1675 filtered ports
- PORT STATE SERVICE
- 22/tcp closed ssh
- 25/tcp closed smtp
- 80/tcp closed http
- 443/tcp closed https
- 8000/tcp closed http-alt
解决方法
我不认为在这里要求任何人帮助你“入侵服务器”特别有利于解答.
>创建正在运行的EC2实例的快照
>创建一个新实例.
>将快照装载为实例上的新EBS卷.
>从快照中复制数据
>终止以前的和新的虚拟机实例.
塔达!你刚刚恢复了数据,没有涉及黑客攻击.
一些工具here可能会有所帮助.