xuser@mh:~$ ftp 95.135.251.169ftp: connect: Connection refusedftp> quitxuser@mh:~$xuser@mh:~$ ftp 192.168.1.2Connected to 192.168.1.2.220 Writable Aliskin public FTP service.Name (192.168.1.2:xuser): ftp331 Please specify the password.Password:230 Login successful.Remote system type is UNIX.Using binary mode to transfer files.ftp> ls200 PORT command successful. Consider using PASV.150 Here comes the directory listing.drwxr-xr-x 2 115 0 16 Mar 09 21:43 write226 Directory send OK.ftp> quit221 Goodbye.xuser@mh:~$...Wed Mar 9 22:54:21 2016 [pid 7200] CONNECT: Client "192.168.1.2"Wed Mar 9 22:54:28 2016 [pid 7198] [ftp] OK LOGIN: Client "192.168.1.2", anon password "ftp@"
root@mh:/home/xuser# iptables -LChain INPUT (policy ACCEPT)target prot opt source destination Chain FORWARD (policy ACCEPT)target prot opt source destination Chain OUTPUT (policy ACCEPT)target prot opt source destination root@mh:/home/xuser#
root@mh:/home/xuser# nmap 192.168.1.2Starting Nmap 6.40 ( http://nmap.org ) at 2016-03-09 22:58 EETNmap scan report for 192.168.1.2Host is up (0.000013s latency).Not shown: 997 closed portsPORT STATE SERVICE21/tcp open ftp139/tcp open netbios-ssn445/tcp open microsoft-dsNmap done: 1 IP address (1 host up) scanned in 1.66 secondsroot@mh:/home/xuser#
root@mh:/home/xuser# nmap 95.135.251.169Starting Nmap 6.40 ( http://nmap.org ) at 2016-03-09 22:58 EETNmap scan report for 169-251-135-95.pool.ukrtel.net (95.135.251.169)Host is up (0.0036s latency).Not shown: 998 closed portsPORT STATE SERVICE23/tcp open telnet80/tcp open httpNmap done: 1 IP address (1 host up) scanned in 3.31 secondsroot@mh:/home/xuser#
Wed Mar 9 22:54:28 2016 [pid 7198] [ftp] OK LOGIN: Client "192.168.1.2", anon password "ftp@"Wed Mar 9 23:45:52 2016 [pid 2032] CONNECT: Client "127.0.0.1"Wed Mar 9 23:45:53 2016 [pid 2031] [ftp] OK LOGIN: Client "127.0.0.1", anon password "mozilla@example.com"Fri Mar 11 22:28:24 2016 [pid 26503] CONNECT: Client "195.154.180.82"Fri Mar 11 22:36:39 2016 [pid 6418] CONNECT: Client "127.0.0.1"Fri Mar 11 22:36:53 2016 [pid 6417] [ftp] OK LOGIN: Client "127.0.0.1", anon password "ftp@"Fri Mar 11 22:39:03 2016 [pid 6420] [ftp] OK UPLOAD: Client "127.0.0.1", "/write/tree.all", 5117437 bytes, 135492.27Kbyte/secFri Mar 11 22:42:36 2016 [pid 14511] CONNECT: Client "192.168.1.2"
xuser@mh:~$ sudo nmap 95.135.251.169[sudo] password for xuser: Starting Nmap 6.40 ( http://nmap.org ) at 2016-03-11 23:39 EETNmap scan report for 169-251-135-95.pool.ukrtel.net (95.135.251.169)Host is up (0.069s latency).Not shown: 998 closed portsPORT STATE SERVICE23/tcp open telnet80/tcp open httpNmap done: 1 IP address (1 host up) scanned in 29.14 secondsxuser@mh:~$
nmap -P0 -F 95.135.251.169 Starting Nmap 7.01 ( https://nmap.org ) at 2016-03-12 03:08 EETNmap scan report for 169-251-135-95.pool.ukrtel.net (95.135.251.169)Host is up (0.030s latency).Not shown: 99 filtered portsPORT STATE SERVICE21/tcp open ftpNmap done: 1 IP address (1 host up) scanned in 4.25 seconds
Цитатаnmap -P0 -F 95.135.251.169 Starting Nmap 7.01 ( https://nmap.org ) at 2016-03-12 03:08 EETNmap scan report for 169-251-135-95.pool.ukrtel.net (95.135.251.169)Host is up (0.030s latency).Not shown: 99 filtered portsPORT STATE SERVICE21/tcp open ftpNmap done: 1 IP address (1 host up) scanned in 4.25 secondsТримайте. І не питайтесь чого до вас сервер LOU в гості заходив
root@mh:/home/xuser# nmap -P0 -F 95.135.251.169 Starting Nmap 6.40 ( http://nmap.org ) at 2016-03-12 12:17 EETNmap scan report for 169-251-135-95.pool.ukrtel.net (95.135.251.169)Host is up (0.034s latency).Not shown: 98 closed portsPORT STATE SERVICE23/tcp open telnet80/tcp open httpNmap done: 1 IP address (1 host up) scanned in 1.49 secondsroot@mh:/home/xuser#
tail -f -n3 /var/log/vsftpd.log Sat Mar 12 02:04:56 2016 [pid 3493] [ftp] FAIL DOWNLOAD: Client "127.0.0.1", "/write/tren.ods", 0.00Kbyte/secSat Mar 12 02:05:53 2016 [pid 3493] [ftp] OK DOWNLOAD: Client "127.0.0.1", "/50kpyMjwWBk.jpg", 901195 bytes, 72042.67Kbyte/cSat Mar 12 02:16:05 2016 [pid 14752] CONNECT: Client "195.154.180.82"Sat Mar 12 02:17:04 2016 [pid 15661] CONNECT: Client "195.154.180.82"Sat Mar 12 02:29:20 2016 [pid 30946] CONNECT: Client "192.168.1.2"Sat Mar 12 02:29:29 2016 [pid 30944] [ftp] OK LOGIN: Client "192.168.1.2", anon password "ftp@"Sat Mar 12 02:31:40 2016 [pid 534] CONNECT: Client "192.168.1.2"Sat Mar 12 02:31:47 2016 [pid 530] [ftp] OK LOGIN: Client "192.168.1.2", anon password "ftp-@"Sat Mar 12 02:32:05 2016 [pid 828] [ftp] OK DOWNLOAD: Client "192.168.1.2", "/208.jpg", 46602 bytes, 85384.18Kbyte/secSat Mar 12 02:32:27 2016 [pid 828] [ftp] OK UPLOAD: Client "192.168.1.2", "/write/208.jpg", 46602 bytes, 73879.49Kbyte/secSat Mar 12 12:02:53 2016 [pid 19245] CONNECT: Client "195.154.180.82"Sat Mar 12 12:02:57 2016 [pid 19512] CONNECT: Client "195.154.180.82"Sat Mar 12 12:02:57 2016 [pid 19514] CONNECT: Client "195.154.180.82"Sat Mar 12 12:02:59 2016 [pid 19517] CONNECT: Client "195.154.180.82"
grep 91.200.42.82 /var/log/kern.log Mar 9 19:15:39 mh kernel: [ 6067.661326] [UFW ALLOW] IN= OUT=eth1 SRC=192.168.1.2 DST=91.200.42.82 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=41098 DF PROTO=TCP SPT=45186 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 Mar 9 19:15:39 mh kernel: [ 6067.661378] [UFW ALLOW] IN= OUT=eth1 SRC=192.168.1.2 DST=91.200.42.82 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=63259 DF PROTO=TCP SPT=45188 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 Mar 9 19:15:39 mh kernel: [ 6067.661427] [UFW ALLOW] IN= OUT=eth1 SRC=192.168.1.2 DST=91.200.42.82 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=47734 DF PROTO=TCP SPT=45190 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 Mar 9 19:15:39 mh kernel: [ 6067.661457] [UFW ALLOW] IN= OUT=eth1 SRC=192.168.1.2 DST=91.200.42.82 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=1399 DF PROTO=TCP SPT=45192 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 Mar 9 19:15:39 mh kernel: [ 6067.661488] [UFW ALLOW] IN= OUT=eth1 SRC=192.168.1.2 DST=91.200.42.82 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=11044 DF PROTO=TCP SPT=45194 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 Mar 9 19:15:59 mh kernel: [ 6087.569760] [UFW ALLOW] IN= OUT=eth1 SRC=192.168.1.2 DST=91.200.42.82 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=48782 DF PROTO=TCP SPT=45240 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 Mar 9 19:15:59 mh kernel: [ 6087.574248] [UFW ALLOW] IN= OUT=eth1 SRC=192.168.1.2 DST=91.200.42.82 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=16531 DF PROTO=TCP SPT=45242 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 Mar 9 19:16:08 mh kernel: [ 6096.971005] [UFW ALLOW] IN= OUT=eth1 SRC=192.168.1.2 DST=91.200.42.82 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=11736 DF PROTO=TCP SPT=45264 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 Mar 9 19:16:08 mh kernel: [ 6096.975259] [UFW ALLOW] IN= OUT=eth1 SRC=192.168.1.2 DST=91.200.42.82 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=54792 DF PROTO=TCP SPT=45266 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0 Mar 9 19:16:08 mh kernel: [ 6096.980549] [UFW ALLOW] IN= OUT=eth1 SRC=192.168.1.2 DST=91.200.42.82 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=13748 DF PROTO=TCP SPT=45268 DPT=80 WINDOW=29200 RES=0x00 SYN URGP=0
Тримайте. І не питайтесь чого до вас сервер LOU в гості заходив