root@myhost:/home/rdr/downloads/FF# cat ~/bin/ns.sh#!/bin/bashnetstat -alp$1|grep -B10000 UNIX
root@myhost:/home/rdr/downloads/FF# ~/bin/ns.sh aActive Internet connections (servers and established)Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program nameudp 0 0 254-51-178-94.pool.:ntp *:* 1549/ntpdudp 0 0 192.168.0.1:ntp *:* 1549/ntpdudp 0 0 myhost.my.net:ntp *:* 1549/ntpdudp 0 0 *:ntp *:* 1549/ntpdudp6 0 0 fe80::202:44ff:fe3a:ntp *:* 1549/ntpdudp6 0 0 localhost:ntp *:* 1549/ntpdudp6 0 0 *:ntp *:* 1549/ntpdActive UNIX domain sockets (servers and established)
root@myhost:/home/rdr/downloads/FF# iptables -LChain INPUT (policy ACCEPT)target prot opt source destinationACCEPT tcp -- myhost.my.net myhost.my.netDROP tcp -- anywhere anywhere tcp dpts:0:1023DROP udp -- anywhere anywhere udp dpts:0:1023DROP icmp -- anywhere anywhereChain FORWARD (policy ACCEPT)target prot opt source destinationChain OUTPUT (policy ACCEPT)target prot opt source destination
root@myhost:/home/rdr/downloads/FF# ifconfig -aeth0 Link encap:Ethernet HWaddr 00:02:44:3A:D8:90 inet addr:192.168.0.1 Bcast:192.168.0.255 Mask:255.255.255.0 inet6 addr: fe80::202:44ff:fe3a:d890/64 Scope:Link UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:21094 errors:0 dropped:0 overruns:0 frame:0 TX packets:21129 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:2002577 (1.9 MiB) TX bytes:1925058 (1.8 MiB) Interrupt:11 Base address:0x4000lo Link encap:Local Loopback inet addr:127.0.0.1 Mask:255.0.0.0 inet6 addr: ::1/128 Scope:Host UP LOOPBACK RUNNING MTU:16436 Metric:1 RX packets:2 errors:0 dropped:0 overruns:0 frame:0 TX packets:2 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:100 (100.0 b) TX bytes:100 (100.0 b)ppp0 Link encap:Point-to-Point Protocol inet addr:94.178.51.254 P-t-P:195.5.5.202 Mask:255.255.255.255 UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1492 Metric:1 RX packets:21019 errors:0 dropped:0 overruns:0 frame:0 TX packets:21047 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:3 RX bytes:1535595 (1.4 MiB) TX bytes:1456905 (1.3 MiB)
root@myhost:/home/rdr/downloads/FF# iptables -LChain INPUT (policy ACCEPT)target prot opt source destinationACCEPT tcp -- myhost.my.net myhost.my.netDROP tcp -- anywhere anywhere tcp dpts:0:1023DROP udp -- anywhere anywhere udp dpts:0:1023DROP icmp -- anywhere anywhereChain FORWARD (policy ACCEPT)target prot opt source destinationChain OUTPUT (policy ACCEPT)target prot opt source destinationroot@myhost:/home/rdr/downloads/FF# ~/bin/ns.sh aActive Internet connections (servers and established)Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program nametcp 0 0 254-51-178-94.poo:40132 89.149.175.18:http ESTABLISHED2130/KWeatherServicudp 0 0 254-51-178-94.pool.:ntp *:* 1549/ntpdudp 0 0 192.168.0.1:ntp *:* 1549/ntpdudp 0 0 myhost.my.net:ntp *:* 1549/ntpdudp 0 0 *:ntp *:* 1549/ntpdudp6 0 0 fe80::202:44ff:fe3a:ntp *:* 1549/ntpdudp6 0 0 localhost:ntp *:* 1549/ntpdudp6 0 0 *:ntp *:* 1549/ntpdActive UNIX domain sockets (servers and established)root@myhost:/home/rdr/downloads/FF#
root@myhost:/home/rdr# iptrafroot@myhost:/home/rdr# pppoe-stopKilling pppd (1446)Killing pppoe-connect (1422)root@myhost:/home/rdr# pppoe-start... Connected!root@myhost:/home/rdr# ifconfig -aeth0 Link encap:Ethernet HWaddr 00:02:44:3A:D8:90 inet addr:192.168.0.1 Bcast:192.168.0.255 Mask:255.255.255.0 inet6 addr: fe80::202:44ff:fe3a:d890/64 Scope:Link UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:41360 errors:0 dropped:0 overruns:0 frame:0 TX packets:41417 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:3879336 (3.6 MiB) TX bytes:3877638 (3.6 MiB) Interrupt:11 Base address:0x4000lo Link encap:Local Loopback inet addr:127.0.0.1 Mask:255.0.0.0 inet6 addr: ::1/128 Scope:Host UP LOOPBACK RUNNING MTU:16436 Metric:1 RX packets:4 errors:0 dropped:0 overruns:0 frame:0 TX packets:4 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:200 (200.0 b) TX bytes:200 (200.0 b)ppp0 Link encap:Point-to-Point Protocol inet addr:94.178.177.175 P-t-P:195.5.5.202 Mask:255.255.255.255 UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1492 Metric:1 RX packets:11 errors:0 dropped:0 overruns:0 frame:0 TX packets:12 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:3 RX bytes:1306 (1.2 KiB) TX bytes:1070 (1.0 KiB)root@myhost:/home/rdr
ppp0 Link encap:Point-to-Point Protocol inet addr:94.178.51.254 P-t-P:195.5.5.202 Mask:255.255.255.255 UP POINTOPOINT RUNNING NOARP MULTICAST MTU:1492 Metric:1 RX packets:21019 errors:0 dropped:0 overruns:0 frame:0 TX packets:21047 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:3 RX bytes:1535595 (1.4 MiB) TX bytes:1456905 (1.3 MiB)
так а samba у вас запущена ?
http://www.linuxquestions.org/questions/linux-security-4/port-445-a-246127/там все написано.
rdr@myhost:~$ /usr/bin/xineЭто xine (графическая оболочка для X11) - свободный видеопроигрыватель v0.99.5.(c) 2000-2007 The xine Team.Ошибка сегментированияrdr@myhost:~$
Jul 2 16:03:54 myhost kernel: xine[6505]: segfault at 2e02c0a2 ip 2e02c0a2 sp bfbc6e68 error 4 in lowcase.dat[ae335000+20000]Jul 2 16:04:01 myhost kernel: xine[6521]: segfault at 402c0a3 ip 0402c0a3 sp bfc6a468 error 4 in xine[8048000+d3000]Jul 2 16:16:01 myhost kernel: xine[6905]: segfault at e702c095 ip e702c095 sp bf9a4bb8 error 5Jul 2 16:16:07 myhost kernel: xine[6921]: segfault at 3162c0a3 ip 3162c0a3 sp bfa676a8 error 4 in lowcase.dat[aebe0000+20000]Jul 2 16:41:26 myhost -- MARK --
Шукаємо lowcase.dat-root@myhost:/home/rdr/downloads# find / -xdev -name lowcase.dat/usr/lib/samba/lowcase.dat-Потім зясовуємо, що цей файл належить до samba і думаємо що робити ???(або реінсталити самбу або видалити її, якщо не потрібна)
445-й порт — то віндові сервіси — smb, по моєму.А щодо ssh — я поміняв стандартний порт на якийсь чотиризначний, тепер нехай вгадують.
nmap piktor -p1-65535
дик аКод: [Вибрати]nmap piktor -p1-65535?
дик аКод: [Вибрати]nmap piktor -p1-65535
root@pipiktorhost:/home/pipiktor/bin# iptables -LChain INPUT (policy ACCEPT)target prot opt source destinationDROP tcp -- anywhere anywhere tcp dpts:0:1023DROP udp -- anywhere anywhere udp dpts:0:1023DROP icmp -- anywhere anywhereChain FORWARD (policy ACCEPT)target prot opt source destinationChain OUTPUT (policy ACCEPT)target prot opt source destinationroot@pipiktorhost:/home/pipiktor/bin#
Код: [Вибрати]root@[glow]pipiktor[/glow]host:/home/[glow]pipiktor[/glow]/bin# iptables -L...
root@[glow]pipiktor[/glow]host:/home/[glow]pipiktor[/glow]/bin# iptables -L...