The OpenNET Project / Index page

[ ÎÏ×ÏÓÔÉ /+++ | ÆÏÒÕÍ | ÔÅÇÉ | ]

ÆÏÒÕÍÙ  ÐÏÍÏÝØ  ÐÏÉÓË  ÒÅÇÉÓÔÒÁÃÉÑ  ÍÁÊÌÌÉÓÔ  ×ÈÏÄ/×ÙÈÏÄ  ÓÌÅÖËÁ  RSS
"Debian iptables (ÏÔËÁÚÙ×ÁÅÔÓÑ ÏÔËÒÙ×ÁÔØ ÓÏÅÄÉÎÅÎÉÅ ÎÁ 81 ÐÏÒÔÕ)"
÷ÁÒÉÁÎÔ ÄÌÑ ÒÁÓÐÅÞÁÔËÉ  
ðÒÅÄ. ÔÅÍÁ | óÌÅÄ. ÔÅÍÁ 
æÏÒÕÍ éÎÆÏÒÍÁÃÉÏÎÎÁÑ ÂÅÚÏÐÁÓÎÏÓÔØ (Linux iptables, ipchains / Linux)
éÚÎÁÞÁÌØÎÏÅ ÓÏÏÂÝÅÎÉÅ [ ïÔÓÌÅÖÉ×ÁÔØ ]

"Debian iptables (ÏÔËÁÚÙ×ÁÅÔÓÑ ÏÔËÒÙ×ÁÔØ ÓÏÅÄÉÎÅÎÉÅ ÎÁ 81 ÐÏÒÔÕ)"  +/
óÏÏÂÝÅÎÉÅ ÏÔ _KUL (ok) on 12-ñÎ×-12, 15:06 
úÄÒÁ×ÓÔ×ÕÊÔÅ ÇÏÓÐÏÄÁ.
îÅÔ, Ñ ÎÅ ÐÏÌÎÅÊÛÉÊ ÞÁÊÎÉË, ÎÏ É ÇÕÒÕ ÓÅÂÑ ÎÁÚ×ÁÔØ ÎÅ ÍÏÇÕ (ÎÅÔ ÐÒÅÄÅÌÕ ÓÏ×ÅÒÛÅÎÓÔ×Á), ÎÏ ÕÖÅ ÇÏÌÏ×Õ ÓÌÏÍÁÌ, ÎÉËÁË ÎÅ ÍÏÇÕ ÐÏÎÑÔØ, ÞÔÏ ÎÅ ÎÒÁ×ÉÔÓÑ ...
÷ ÏÂÝÅÍ ÅÓÔØ ÛÌÀÚ, ÔÁÍ 3 ÉÎÔÅÒÆÅÊÓÁ, ppp0 (ÞÅÒÅÚ eth0), eth0, eth1 (ÌÏËÁÌËÁ), ÓÔÏÉÔ apache2 ÎÁ 81 ÐÏÒÔÕ É ÓÔÏÉÔ nginx ÎÁ 80. ðÒÉ ÐÏÐÙÔËÉ ÚÁÊÔÉ ÎÁ 192.168.0.1 (eth1) Ó 192.168.0.2 ÐÏ 80 ÐÏÒÔÕ, ×Ó£ ÏÔÌÉÞÎÏ ÏÔËÒÙ×ÁÅÔÓÑ, Á ÅÓÌÉ ÚÁÊÔÉ ÎÁ 81, ÔÏÖÅ ÏÔÌÉÞÎÏ. îï! åÓÌÉ Ó ×ÎÅÛËÉ ÚÁÊÔÉ ÎÁ 99.99.99.99:80 ÏÔËÒÏÅÔÓÑ ÓÔÒÁÎÉÞËÁ, Á ÐÒÉ ÐÏÐÙÔËÉ ÏÔËÒÙÔØ 99.99.99.99:81 "ÎÅÔ ÏÔ×ÅÔÁ". ðÏÞÅÍÕ ÔÁË ÐÒÏÉÓÈÏÄÉÔ? ðÏÞÅÍÕ ÓÉÓÔÅÍÁ ÂÌÏËÉÒÕÅÔ 81?
ìÁÄÎÏ! ðÒÅÄÐÏÌÏÖÉÌ ÞÔÏ ÔÒÁÆÉË ÂÁÎÁÌØÎÏ ÎÅ ÒÁÚÒÅÛ£Î, ÄÏÂÁ×ÉÌ:
iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT
iptables -A FORWARD -i eth0 -o ppp0 -j ACCEPT
iptables -A FORWARD -i ppp0 -o eth0 -j ACCEPT
iptables -A FORWARD -i ppp0 -o lo -j ACCEPT
iptables -A FORWARD -i lo -o ppp0 -j ACCEPT
õ×Ù, ÎÉÞÅÇÏ ÎÅ ÐÏÌÕÞÉÌÏÓØ ...
ðÏÍÏÇÉÔÅ ÍÏÖÅÔ ÈÏÔØ ÓÏ×ÅÔÏÍ × ËÁËÕÀ ÓÔÏÒÏÎÕ ÓÍÏÔÒÅÔØ :( ... é ËÓÔÁÔÉ ÄÁ, net.ipv4.ip_forward=1 ÕÓÔÁÎÏ×ÌÅÎ (ÜÔÏ × ÓÀÓÃÔÌÅ ÅÄÉÎÓÔ×ÅÎÎÏÅ ÚÎÁÞÅÎÉÅ).
óÁÍÏÅ ÓÔÒÁÛÎÏÅ, ÞÔÏ ÄÏ ÜÔÏÇÏ ÂÙÌÁ ÕÂÕÎÔÁ-ÓÅÒ×ÅÒ, ×Ó£ ÏÔÌÉÞÎÏ ÒÁÂÏÔÁÌÏ, Á ÔÕÔ ÎÅ ÈÏÞÅÔ ... ôÁË ÖÅ ÈÏÔÅÌ 5900 ÐÏÒÔ ÐÒÏÂÒÏÓÉÔØ ÄÌÑ VNC ÞÔÏÂÙ Ó ×ÎÅÛËÉ ÃÅÐÌÑÔØÓÑ ÎÁ ÓÅÒ×ÅÒ, Á ÏÎ ÎÁ eth1 192.168.0.2 ÐÅÒÅËÉÄÙ×ÁÌ É ÐÏËÁÚÙ×ÁÌ ÒÁÂÏÞÉÊ ÓÔÏÌ, ÔÏÖÅ ÎÅ ÐÏÌÕÞÉÌÏÓØ. ðÒÏÂÏ×ÁÌ ÐÏÒÔÙ ÉÇÒÙ ÐÒÏËÉÎÕÔØ, ÞÔÏÂÙ ÃÅÐÌÑÔØÓÑ Ë ÓÅÒ×ÅÒÕ, Á ÏÎ ÎÁ ÌÏËÁÌØÎÙÊ ÓÅÒ×ÁË ÉÚ ÓÅÔÉ eth0 ÐÅÒÅ×ÏÄÉÌ, ÔÁËÖÅ ÐÏÔÅÒÐÅÌ ÆÉÁÓËÏ ... ôÁËÏÅ ÏÝÕÝÅÎÉÅ, ÞÔÏ ÎÁÔ ÎÅ ÒÁÂÏÔÁÅÔ c ×ÎÅÛÎÅÇÏ ÍÉÒÁ ÎÁ ÓÅÒ×ÅÒ × ppp0. îÏ ÉÚÎÕÔÒÉ ×Ó£ ÏÔÌÉÞÎÏ ÎÁÔÉÔÓÑ. é ÓÁÍÏÅ ÎÅÐÏÎÑÔÎÏÅ, ÐÏÞÅÍÕ 81 ÐÏÒÔ ÎÅ ÏÔËÒÙ×ÁÅÔÓÑ, ×ÅÄØ ÏÎ ×ÏÏÂÝÅ ÎÅ ÄÏÌÖÅÎ ÎÁÔÉÔØÓÑ, ÐÒÏÓÔÏ ÎÁ 127.0.0.1:81 ÓÌÕÛÁÅÔÓÑ. éÚÎÕÔÒÉ ÚÁÈÏÄÉÔ ÎÁ 81, Á ÓÎÁÒÕÖÉ ÎÅÔ :( .
õ×ÁÖÁÅÍÙÅ ÚÎÁÔÏËÉ, ÐÎÉÔÅ × ÎÕÖÎÏÍ ÎÁÐÒÁ×ÌÅÎÉÉ ÐÏÖÁÌÕÊÓÔÁ :(.

÷ÏÔ ÐÒÁ×ÉÌÁ ÎÁÔÁ, ËÏÔÏÒÙÅ ÏÔÌÉÞÎÏ ÒÁÂÏÔÁÀÔ:
*nat
-A POSTROUTING -s 192.168.0.0/24 -o ppp0 -j MASQUERADE
-A POSTROUTING -s 192.168.1.0/24 -o ppp0 -j MASQUERADE
-A POSTROUTING -s 192.168.0.0/24 -d 10.0.0.0/8 -o eth0 -j MASQUERADE
-A POSTROUTING -s 192.168.1.0/24 -d 10.0.0.0/8 -o eth0 -j MASQUERADE
-A POSTROUTING -s 192.168.0.0/24 -d 194.154.82.43 -o eth0 -j MASQUERADE
-A POSTROUTING -s 192.168.0.0/24 -d 194.154.82.44 -o eth0 -j MASQUERADE
-A PREROUTING -p tcp -d 10.72.55.177 --dport 1300 -j DNAT --to-destination 192.168.0.2
-A PREROUTING -p udp -d 10.72.55.177 --dport 1300 -j DNAT --to-destination 192.168.0.2
-A PREROUTING -p udp -d 10.72.55.177 --dport 19003 -j DNAT --to-destination 192.168.0.2
COMMIT
*filter
-A INPUT -p icmp -m icmp --icmp-type echo-request -j REJECT --reject-with icmp-net-prohibited
COMMIT
*mangle
-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
COMMIT

ïÔ×ÅÔÉÔØ | ðÒÁ×ËÁ | CÏÏÂÝÉÔØ ÍÏÄÅÒÁÔÏÒÕ

ïÇÌÁ×ÌÅÎÉÅ

óÏÏÂÝÅÎÉÑ ÐÏ ÔÅÍÅ [óÏÒÔÉÒÏ×ËÁ ÐÏ ×ÒÅÍÅÎÉ | RSS]


1. "Debian iptables (ÏÔËÁÚÙ×ÁÅÔÓÑ ÏÔËÒÙ×ÁÔØ ÓÏÅÄÉÎÅÎÉÅ ÎÁ 81 ÐÏÒÔÕ)"  +/
óÏÏÂÝÅÎÉÅ ÏÔ _KUL (ok) on 12-ñÎ×-12, 15:10 
íÏÖÅÔ × ÄÅÂÉÁÎÅ ÅÓÔØ ËÁËÁÑ-ÔÏ Ó×ÏÑ ÄÏÐÏÌÎÉÔÅÌØÎÁÑ ÈÉÔÒÏÓÔØ? ÷ÒÏÄÅ ÔÏÇÏ, ËÁË ÎÁ ÃÅÎÔÏÓÅ ÃÅÐÏÞËÁ ÆÁÅÒ×ÏÌ? éÌÉ ÍÏÖÅÔ, ËÁËÏÊ-ÔÏ ÐÁÒÁÍÅÔÒ ÎÕÖÎÏ ×ËÌÀÞÉÔØ ÄÏÐÏÌÎÉÔÅÌØÎÏ?
ïÔ×ÅÔÉÔØ | ðÒÁ×ËÁ | ^ Ë ÒÏÄÉÔÅÌÀ #0 | îÁ×ÅÒÈ | CÏÏÂÝÉÔØ ÍÏÄÅÒÁÔÏÒÕ

2. "Debian iptables (ÏÔËÁÚÙ×ÁÅÔÓÑ ÏÔËÒÙ×ÁÔØ ÓÏÅÄÉÎÅÎÉÅ ÎÁ 81 ÐÏÒÔÕ)"  +/
óÏÏÂÝÅÎÉÅ ÏÔ ËÅÇÎÁ on 12-ñÎ×-12, 15:29 
>[Ï×ÅÒË×ÏÔÉÎÇ ÕÄÁÌÅÎ]
> -A PREROUTING -p tcp -d 10.72.55.177 --dport 1300 -j DNAT --to-destination 192.168.0.2
> -A PREROUTING -p udp -d 10.72.55.177 --dport 1300 -j DNAT --to-destination 192.168.0.2
> -A PREROUTING -p udp -d 10.72.55.177 --dport 19003 -j DNAT --to-destination 192.168.0.2
> COMMIT
> *filter
> -A INPUT -p icmp -m icmp --icmp-type echo-request -j REJECT --reject-with icmp-net-prohibited
> COMMIT
> *mangle
> -A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
> COMMIT

ÓÌÕÛÁÅÔÓÑ ÔÏÌØËÏ ÎÁ 127.0.0.1:81?
ÍÏÖÎÏ ÐÏÓÍÏÔÒÅÔØ ×Ù×ÏÄ sudo netstat -antup | grep 81?


ïÔ×ÅÔÉÔØ | ðÒÁ×ËÁ | ^ Ë ÒÏÄÉÔÅÌÀ #0 | îÁ×ÅÒÈ | CÏÏÂÝÉÔØ ÍÏÄÅÒÁÔÏÒÕ

3. "Debian iptables (ÏÔËÁÚÙ×ÁÅÔÓÑ ÏÔËÒÙ×ÁÔØ ÓÏÅÄÉÎÅÎÉÅ ÎÁ 81 ÐÏÒÔÕ)"  +/
óÏÏÂÝÅÎÉÅ ÏÔ _KUL (ok) on 12-ñÎ×-12, 15:53 
÷ ÁÐÁÞÅ ÄÅÌÁÀ ÔÁË
NameVirtualHost *:81
Listen 81

÷ ÏÔ×ÅÔ
# netstat -antup | grep :81
tcp        0      0 0.0.0.0:81              0.0.0.0:*               LISTEN      4909/apache2

ëÓÔÁÔÉ!
óÔÁ×ÌÀ ÁÐÁÞ ÎÁ 80 ÐÏÒÔ, ×ÉÖÕ ÓÎÁÒÕÖÕ ÐÏ ×ÎÅÛÎÅÍÕ ÉÐÕ, ÓÔÁ×ÌÀ 82 ÐÏÒÔ, ÏÐÑÔØ ÎÅ ×ÉÖÕ ... ðÏÞÅÍÕ-ÔÏ ÍÎÅ ËÁÖÅÔÓÑ, ÞÔÏ-ÇÄÅ ÔÏ × ÄÅÂÉÁÎÅ ÐÒÏÐÉÓÁÎÙ ËÁËÉÅ ÔÏ ÐÒÁ×ÉÌÁ ÄÌÑ 80, É ×ÏÚÍÏÖÎÏ ÄÒÕÇÉÈ ÐÏÒÔÏ× ...

ïÔ×ÅÔÉÔØ | ðÒÁ×ËÁ | ^ Ë ÒÏÄÉÔÅÌÀ #2 | îÁ×ÅÒÈ | CÏÏÂÝÉÔØ ÍÏÄÅÒÁÔÏÒÕ

4. "Debian iptables (ÏÔËÁÚÙ×ÁÅÔÓÑ ÏÔËÒÙ×ÁÔØ ÓÏÅÄÉÎÅÎÉÅ ÎÁ 81 ÐÏÒÔÕ)"  +/
óÏÏÂÝÅÎÉÅ ÏÔ ËÅÇÎÁ on 12-ñÎ×-12, 16:12 
>[Ï×ÅÒË×ÏÔÉÎÇ ÕÄÁÌÅÎ]
> tcp        0    
>   0 0.0.0.0:81        
>       0.0.0.0:*    
>           LISTEN
>      4909/apache2
> ëÓÔÁÔÉ!
> óÔÁ×ÌÀ ÁÐÁÞ ÎÁ 80 ÐÏÒÔ, ×ÉÖÕ ÓÎÁÒÕÖÕ ÐÏ ×ÎÅÛÎÅÍÕ ÉÐÕ, ÓÔÁ×ÌÀ 82
> ÐÏÒÔ, ÏÐÑÔØ ÎÅ ×ÉÖÕ ... ðÏÞÅÍÕ-ÔÏ ÍÎÅ ËÁÖÅÔÓÑ, ÞÔÏ-ÇÄÅ ÔÏ ×
> ÄÅÂÉÁÎÅ ÐÒÏÐÉÓÁÎÙ ËÁËÉÅ ÔÏ ÐÒÁ×ÉÌÁ ÄÌÑ 80, É ×ÏÚÍÏÖÎÏ ÄÒÕÇÉÈ ÐÏÒÔÏ×
> ...

É ÉÎÔÅÒÅÓÎÏ ÌÏËÁÌØÎÏ Ó ÓÅÒ×ÅÒÁ telnet 127.0.0.1 81 ÐÏËÁÖÅÔ ÞÔÏ ÎÉÂÕÄØ?
Á ÔÁË ÖÅ telnet ×ÎÅÛÎÉÊ_ÉÐ 81 ÔÁË ÖÅ Ó ÓÅÒ×ÅÒÁ ÐÏËÁÖÅÔ?

× ÄÅÂÉÁÎ ÎÅÔ ÐÏ ÕÍÏÌÞÁÎÉÀ ÎÉËÁËÉÈ ÃÅÐÏÞÅË ÆÁÉÒ×ÁÌÁ
ÍÏÖÎÏ ÖÅ ×ÓÅÇÄÁ ÐÏÓÍÏÔÒÅÔØ:
sudo iptables -L
sudo iptables -L -t filter

ïÔ×ÅÔÉÔØ | ðÒÁ×ËÁ | ^ Ë ÒÏÄÉÔÅÌÀ #3 | îÁ×ÅÒÈ | CÏÏÂÝÉÔØ ÍÏÄÅÒÁÔÏÒÕ

5. "Debian iptables (ÏÔËÁÚÙ×ÁÅÔÓÑ ÏÔËÒÙ×ÁÔØ ÓÏÅÄÉÎÅÎÉÅ ÎÁ 81 ÐÏÒÔÕ)"  +/
óÏÏÂÝÅÎÉÅ ÏÔ _KUL (ok) on 12-ñÎ×-12, 16:33 
÷Ó£ ÓÔÁÎÏ×ÉÔÓÑ ÅÝ£ ÉÎÔÅÒÅÓÎÅÅ ...
åÓÌÉ ÉÓÐÏÌØÚÏ×ÁÔØ Ó×ÏÂÏÄÎÙÅ ÐÏÒÔÙ ÏÔ 1 ÄÏ 1024 ÔÏ ÎÉÞÅÇÏ ÎÅ ÏÔËÒÏÅÔÓÑ, ÅÓÌÉ ÉÓÐÏÌØÚÏ×ÁÔØ ÐÏÒÔÙ ÏÔ 1025 É ×ÙÛÅ, ÔÏ ÁÐÁÞ ÏÔËÒÙ×ÁÅÔ ×Ó£. èÍ ...

iptables -nL
Chain INPUT (policy ACCEPT)
target     prot opt source               destination
REJECT     icmp --  0.0.0.0/0            0.0.0.0/0            icmptype 8 reject-with icmp-net-prohibited

Chain FORWARD (policy ACCEPT)
target     prot opt source               destination
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination


# iptables -t nat -nL
Chain PREROUTING (policy ACCEPT)
target     prot opt source               destination
DNAT       tcp  --  0.0.0.0/0            10.72.55.177         tcp dpt:1300 to:192.168.0.2
DNAT       udp  --  0.0.0.0/0            10.72.55.177         udp dpt:1300 to:192.168.0.2
DNAT       udp  --  0.0.0.0/0            10.72.55.177         udp dpt:19003 to:192.168.0.2

Chain INPUT (policy ACCEPT)
target     prot opt source               destination

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination

Chain POSTROUTING (policy ACCEPT)
target     prot opt source               destination
MASQUERADE  all  --  192.168.0.0/24       0.0.0.0/0
MASQUERADE  all  --  192.168.1.0/24       0.0.0.0/0
MASQUERADE  all  --  192.168.0.0/24       10.0.0.0/8
MASQUERADE  all  --  192.168.1.0/24       10.0.0.0/8
MASQUERADE  all  --  192.168.0.0/24       194.154.82.43
MASQUERADE  all  --  192.168.0.0/24       194.154.82.44

ïÔ 192.168.0.2 Ë 192.168.0.1 ÔÅÌÎÅÔÏÍ
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
                                                  <html><head>
                                                              <title>400 Bad Req
uest</title>
            </head><body>
                         <h1>Bad Request</h1>
                                             <p>Your browser sent a request that
this server could not understand.<br />
                                        </p>
                                            <hr>
                                                <address>Apache/2.2.21 (Debian)
Server at 127.0.1.1 Port 81</address>
                                     </body></html>
ðÏÄËÌÀÞÅÎÉÅ Ë ÕÚÌÕ ÕÔÅÒÑÎÏ.

ïÔ ×ÎÅÛÎÅÊ ÔÁÞËÉ Ë ÉÎÔÅÒÆÅÊÓÕ ppp0 ÔÅÌÎÅÔÏÍ
C:\Documents and Settings\áÄÍÉÎÉÓÔÒÁÔÏÒ>telnet 128.74.10.xx 81
ðÏÄËÌÀÞÅÎÉÅ Ë 128.74.10.xx...îÅ ÕÄÁÌÏÓØ ÏÔËÒÙÔØ ÐÏÄËÌÀÞÅÎÉÅ Ë ÜÔÏÍÕ ÕÚÌÕ, ÎÁ ÐÏÒ
Ô 81: óÂÏÊ ÐÏÄËÌÀÞÅÎÉÑ


çÒÅÛÕ ÎÁ ÕÐÒÁ×ÌÑÀÝÉÊ Ó×ÉÔÞ ÐÒÏ×ÁÊÄÅÒÁ, ËÏÔÏÒÙÊ ÎÁ ÞÅÒÄÁËÅ, ÍÏÖÅÔ ÔÁÍ ÐÏÒÔÙ ÚÁÌÏÞÉÌÉ ... îÏ ÓÔÒÁÎÎÏ, ÐÏÞÅÍÕ ÔÏÇÄÁ ÐÏ ÐÏÒÔÕ 5900 Ë VNC Ñ ÎÅ ÓÍÏÇ ÐÏÄÃÅÐÉÔØÓÑ Ó ×ÎÅÛÎÅÇÏ ÍÉÒÁ ÎÁ ÌÏËÁÌØÎÕÀ ÍÁÛÉÎÕ ÚÁ ÛÌÀÚÏÍ (ppp0 -> eth1) ...

ïÔ×ÅÔÉÔØ | ðÒÁ×ËÁ | ^ Ë ÒÏÄÉÔÅÌÀ #4 | îÁ×ÅÒÈ | CÏÏÂÝÉÔØ ÍÏÄÅÒÁÔÏÒÕ

6. "Debian iptables (ÏÔËÁÚÙ×ÁÅÔÓÑ ÏÔËÒÙ×ÁÔØ ÓÏÅÄÉÎÅÎÉÅ ÎÁ 81 ÐÏÒÔÕ)"  +/
óÏÏÂÝÅÎÉÅ ÏÔ tuxic (ok) on 12-ñÎ×-12, 16:38 
>[Ï×ÅÒË×ÏÔÉÎÇ ÕÄÁÌÅÎ]
>    </body></html>
> ðÏÄËÌÀÞÅÎÉÅ Ë ÕÚÌÕ ÕÔÅÒÑÎÏ.
> ïÔ ×ÎÅÛÎÅÊ ÔÁÞËÉ Ë ÉÎÔÅÒÆÅÊÓÕ ppp0 ÔÅÌÎÅÔÏÍ
> C:\Documents and Settings\áÄÍÉÎÉÓÔÒÁÔÏÒ>telnet 128.74.10.xx 81
> ðÏÄËÌÀÞÅÎÉÅ Ë 128.74.10.xx...îÅ ÕÄÁÌÏÓØ ÏÔËÒÙÔØ ÐÏÄËÌÀÞÅÎÉÅ Ë ÜÔÏÍÕ ÕÚÌÕ, ÎÁ ÐÏÒ
> Ô 81: óÂÏÊ ÐÏÄËÌÀÞÅÎÉÑ
> çÒÅÛÕ ÎÁ ÕÐÒÁ×ÌÑÀÝÉÊ Ó×ÉÔÞ ÐÒÏ×ÁÊÄÅÒÁ, ËÏÔÏÒÙÊ ÎÁ ÞÅÒÄÁËÅ, ÍÏÖÅÔ ÔÁÍ ÐÏÒÔÙ ÚÁÌÏÞÉÌÉ
> ... îÏ ÓÔÒÁÎÎÏ, ÐÏÞÅÍÕ ÔÏÇÄÁ ÐÏ ÐÏÒÔÕ 5900 Ë VNC Ñ
> ÎÅ ÓÍÏÇ ÐÏÄÃÅÐÉÔØÓÑ Ó ×ÎÅÛÎÅÇÏ ÍÉÒÁ ÎÁ ÌÏËÁÌØÎÕÀ ÍÁÛÉÎÕ ÚÁ ÛÌÀÚÏÍ
> (ppp0 -> eth1) ...

iptables -F INPUT
É ÐÒÏÂÕÊÔÅ ÐÏÄËÌÀÞÁÔØÓÑ.

ïÔ×ÅÔÉÔØ | ðÒÁ×ËÁ | ^ Ë ÒÏÄÉÔÅÌÀ #5 | îÁ×ÅÒÈ | CÏÏÂÝÉÔØ ÍÏÄÅÒÁÔÏÒÕ

7. "Debian iptables (ÏÔËÁÚÙ×ÁÅÔÓÑ ÏÔËÒÙ×ÁÔØ ÓÏÅÄÉÎÅÎÉÅ ÎÁ 81 ÐÏÒÔÕ)"  +/
óÏÏÂÝÅÎÉÅ ÏÔ _KUL (ok) on 12-ñÎ×-12, 16:40 
þÅÒÅÚ 2 ÍÉÎÕÔÙ ÏÓÅÎÉÌÏ!
ðÏÐÒÏÂÏ×ÁÌ É ÕÖÁÓÎÕÌÓÑ ...
ðÏÄËÌÀÞÉÌÓÑ ÎÁ 10.ÈÈ.ÈÈ.ÈÈ:81 (eth0) ÏÔ ÞÅÌÏ×ÅËÁ, ËÏÔÏÒÙÊ ÎÁÈÏÄÉÔÓÑ × ÔÏÊ-ÖÅ ÓÅÔÉ ÐÒÏ×ÁÊÄÅÒÁ, ÎÏ × ÄÒÕÇÏÍ ÓÅÇÍÅÎÔÅ. ôÏÞÎÏ ÕÂÅÖÄ£Î, ÌÉÂÏ ÅÓÔØ ÐÒÁ×ÉÌÁ, ËÏÔÏÒÙÅ pppx ÂÌÏËÉÒÕÀÔ, ÔÏÌØËÏ ÎÅÐÏÎÑÔÎÏ ÇÄÅ, ÌÉÂÏ ÐÒÏ×ÁÊÄÅÒ ÞÅÒÅÚ vpn ÓÅÒ×ÅÒ ÎÅ ×ÓÅ ÐÏÒÔÙ ÐÏ ÔÒÁÆÉËÕ ÏÔÄÁ£Ô.

p.s. á ÐÒÉÞ£Í ÃÅÐÏÞËÁ ÉÎÐÕÔ? ôÁÍ ÔÏÌØËÏ ÐÒÁ×ÉÌÏ, ÞÔÏÂÙ ÐÉÎÇÏÍ ÎÅ ÚÁÄÏÓÉÌÉ É ×Ó£. äÒÏÐÎÕÌ, ÎÅ ÐÏÍÏÇÌÏ, 81 ÎÅ ÄÏÓÔÕÐÅÎ ÐÏ ÐÒÅÖÎÅÍÕ ...

ïÔ×ÅÔÉÔØ | ðÒÁ×ËÁ | ^ Ë ÒÏÄÉÔÅÌÀ #5 | îÁ×ÅÒÈ | CÏÏÂÝÉÔØ ÍÏÄÅÒÁÔÏÒÕ

8. "Debian iptables (ÏÔËÁÚÙ×ÁÅÔÓÑ ÏÔËÒÙ×ÁÔØ ÓÏÅÄÉÎÅÎÉÅ ÎÁ 81 ÐÏÒÔÕ)"  +/
óÏÏÂÝÅÎÉÅ ÏÔ ËÅÇÎÁ on 12-ñÎ×-12, 16:40 
>[Ï×ÅÒË×ÏÔÉÎÇ ÕÄÁÌÅÎ]
>    </body></html>
> ðÏÄËÌÀÞÅÎÉÅ Ë ÕÚÌÕ ÕÔÅÒÑÎÏ.
> ïÔ ×ÎÅÛÎÅÊ ÔÁÞËÉ Ë ÉÎÔÅÒÆÅÊÓÕ ppp0 ÔÅÌÎÅÔÏÍ
> C:\Documents and Settings\áÄÍÉÎÉÓÔÒÁÔÏÒ>telnet 128.74.10.xx 81
> ðÏÄËÌÀÞÅÎÉÅ Ë 128.74.10.xx...îÅ ÕÄÁÌÏÓØ ÏÔËÒÙÔØ ÐÏÄËÌÀÞÅÎÉÅ Ë ÜÔÏÍÕ ÕÚÌÕ, ÎÁ ÐÏÒ
> Ô 81: óÂÏÊ ÐÏÄËÌÀÞÅÎÉÑ
> çÒÅÛÕ ÎÁ ÕÐÒÁ×ÌÑÀÝÉÊ Ó×ÉÔÞ ÐÒÏ×ÁÊÄÅÒÁ, ËÏÔÏÒÙÊ ÎÁ ÞÅÒÄÁËÅ, ÍÏÖÅÔ ÔÁÍ ÐÏÒÔÙ ÚÁÌÏÞÉÌÉ
> ... îÏ ÓÔÒÁÎÎÏ, ÐÏÞÅÍÕ ÔÏÇÄÁ ÐÏ ÐÏÒÔÕ 5900 Ë VNC Ñ
> ÎÅ ÓÍÏÇ ÐÏÄÃÅÐÉÔØÓÑ Ó ×ÎÅÛÎÅÇÏ ÍÉÒÁ ÎÁ ÌÏËÁÌØÎÕÀ ÍÁÛÉÎÕ ÚÁ ÛÌÀÚÏÍ
> (ppp0 -> eth1) ...

Ñ ÖÅ ÎÁÐÉÓÁÌ ÓÄÅÌÁÊÔÅ Ó ÄÅÂÉÁÎÁ (ÐÒÑÍÏ Ó ÓÅÒ×ÅÒÁ):
telnet 127.0.0.1 81
telnet 128.74.10.xx 81

ïÔ×ÅÔÉÔØ | ðÒÁ×ËÁ | ^ Ë ÒÏÄÉÔÅÌÀ #5 | îÁ×ÅÒÈ | CÏÏÂÝÉÔØ ÍÏÄÅÒÁÔÏÒÕ

9. "Debian iptables (ÏÔËÁÚÙ×ÁÅÔÓÑ ÏÔËÒÙ×ÁÔØ ÓÏÅÄÉÎÅÎÉÅ ÎÁ 81 ÐÏÒÔÕ)"  +/
óÏÏÂÝÅÎÉÅ ÏÔ _KUL (ok) on 12-ñÎ×-12, 16:44 
~# telnet 128.74.10.xx 81
Trying 128.74.10.xx...
Connected to 128.74.10.xx.
Escape character is '^]'.
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>400 Bad Request</title>
</head><body>
<h1>Bad Request</h1>
<p>Your browser sent a request that this server could not understand.<br />
</p>
<hr>
<address>Apache/2.2.21 (Debian) Server at 127.0.1.1 Port 81</address>
</body></html>
Connection closed by foreign host.

root@server-kul:~# telnet 127.0.0.1 81
Trying 127.0.0.1...
Connected to 127.0.0.1.
Escape character is '^]'.
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>400 Bad Request</title>
</head><body>
<h1>Bad Request</h1>
<p>Your browser sent a request that this server could not understand.<br />
</p>
<hr>
<address>Apache/2.2.21 (Debian) Server at 127.0.1.1 Port 81</address>
</body></html>
Connection closed by foreign host.

ú×ÏÎÉÔØ × ôð ÐÒÏ×ÁÊÄÅÒÁ É ÖÁÌÏ×ÁÔØÓÑ? :)

ïÔ×ÅÔÉÔØ | ðÒÁ×ËÁ | ^ Ë ÒÏÄÉÔÅÌÀ #8 | îÁ×ÅÒÈ | CÏÏÂÝÉÔØ ÍÏÄÅÒÁÔÏÒÕ

10. "Debian iptables (ÏÔËÁÚÙ×ÁÅÔÓÑ ÏÔËÒÙ×ÁÔØ ÓÏÅÄÉÎÅÎÉÅ ÎÁ 81 ÐÏÒÔÕ)"  +/
óÏÏÂÝÅÎÉÅ ÏÔ ËÅÇÎÁ on 12-ñÎ×-12, 16:52 
>[Ï×ÅÒË×ÏÔÉÎÇ ÕÄÁÌÅÎ]
> <title>400 Bad Request</title>
> </head><body>
> <h1>Bad Request</h1>
> <p>Your browser sent a request that this server could not understand.<br />
> </p>
> <hr>
> <address>Apache/2.2.21 (Debian) Server at 127.0.1.1 Port 81</address>
> </body></html>
> Connection closed by foreign host.
> ú×ÏÎÉÔØ × ôð ÐÒÏ×ÁÊÄÅÒÁ É ÖÁÌÏ×ÁÔØÓÑ? :)

ÐÏËÁÖÉÔÅ $ifconfig -a

ÍÏÖÎÏ ÅÝ£ ÚÁÐÕÓÔÉÔØ $sudo tcpdump -i ppp0 'tcp port 81'

ÐÏÓÔÕÞÁÔØÓÑ Ó ×ÎÅÛËÉ, ÅÓÌÉ ×Ù×ÏÄÁ ÎÅ ÂÕÄÅÔ... ÔÏ ×ÙÈÏÄÉÔ ËÏÇÏ ÔÏ ÎÁÄÏ ÂÉÔØ ÐÏ ÈÉÔÒÏÊ ÒÙÖÅÊ ÎÁÇÌÏÊ ÍÏÒÄÅ ;-)

ïÔ×ÅÔÉÔØ | ðÒÁ×ËÁ | ^ Ë ÒÏÄÉÔÅÌÀ #9 | îÁ×ÅÒÈ | CÏÏÂÝÉÔØ ÍÏÄÅÒÁÔÏÒÕ

11. "Debian iptables (ÏÔËÁÚÙ×ÁÅÔÓÑ ÏÔËÒÙ×ÁÔØ ÓÏÅÄÉÎÅÎÉÅ ÎÁ 81 ÐÏÒÔÕ)"  +/
óÏÏÂÝÅÎÉÅ ÏÔ _KUL (ok) on 12-ñÎ×-12, 17:02 
# ifconfig -a
eth0      Link encap:Ethernet  HWaddr 00:1b:11:47:29:2b
          inet addr:10.72.55.177  Bcast:10.72.55.255  Mask:255.255.248.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:1210769 errors:0 dropped:0 overruns:0 frame:0
          TX packets:2073426 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:307969920 (293.7 MiB)  TX bytes:2951001251 (2.7 GiB)
          Interrupt:21 Base address:0x2000

eth1      Link encap:Ethernet  HWaddr 00:0a:5e:65:a6:a3
          inet addr:192.168.0.1  Bcast:192.168.0.255  Mask:255.255.255.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:2075237 errors:0 dropped:0 overruns:0 frame:0
          TX packets:1208597 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:2955683038 (2.7 GiB)  TX bytes:305848474 (291.6 MiB)
          Interrupt:22

lo        Link encap:Local Loopback
          inet addr:127.0.0.1  Mask:255.0.0.0
          UP LOOPBACK RUNNING  MTU:16436  Metric:1
          RX packets:3126004 errors:0 dropped:0 overruns:0 frame:0
          TX packets:3126004 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:866741404 (826.5 MiB)  TX bytes:866741404 (826.5 MiB)

mon.wlan0 Link encap:UNSPEC  HWaddr D8-5D-4C-D6-5E-9C-00-00-00-00-00-00-00-00-00-00
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:0 errors:0 dropped:0 overruns:0 frame:0
          TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:0 (0.0 B)  TX bytes:0 (0.0 B)

ppp0      Link encap:Point-to-Point Protocol
          inet addr:128.74.10.xx  P-t-P:194.186.120.148  Mask:255.255.255.255
          UP POINTOPOINT RUNNING NOARP MULTICAST  MTU:1460  Metric:1
          RX packets:88664 errors:0 dropped:0 overruns:0 frame:0
          TX packets:57022 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:3
          RX bytes:115585384 (110.2 MiB)  TX bytes:3207272 (3.0 MiB)

wlan0     Link encap:Ethernet  HWaddr d8:5d:4c:d6:5e:9c
          inet addr:192.168.1.1  Bcast:192.168.1.255  Mask:255.255.255.0
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:0 errors:0 dropped:0 overruns:0 frame:0
          TX packets:106 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:0 (0.0 B)  TX bytes:21592 (21.0 KiB)

tcpdump -i ppp0 'tcp port 81', ÓÔÕÞÕÓØ
0 packets captured
0 packets received by filter
0 packets dropped by kernel

íÅÎÑÀ ÁÐÁÞ ÎÁ 1025, ÓÔÕÞÕÓØ
tcpdump -i ppp0 'tcp port 1025'
<vsyakaya vsyachina>
10 packets captured
10 packets received by filter
0 packets dropped by kernel

ôÏÌØËÏ ÏÄÎÏ ÍÏÖÎÏ ÓËÁÚÁÔØ - ï-þõ-íåôø!!!
óÌÏ× ÎÅÔ ...
ôÏÌØËÏ ÓÔÒÁÎÎÏ, ÐÏÞÅÍÕ ÖÅ VNC ÎÅ ÒÁÂÏÔÁÌ ÐÒÉ ÐÒÏÂÒÏÓÅ. îÁ×ÅÒÎÏ ÏÛÉÂËÁ × ÄÎÁÔ/ÓÎÁÔ ÂÙÌÁ

p.s. ËÅÇÎÁ, ÂÏÌØÛÏÅ ×ÁÍ, ÞÅÌÏ×ÅÞÅÓËÏÅ ÓÐÁÓÉÂÏ ÚÁ ÎÁ×ÏÄËÕ ÎÁ ÔÅÌÎÅÔ, ×ÒÏÄÅ ×Ó£ ÐÒÏÓÔÏ, ÎÏ ÎÅ ÍÏÇ ÓÏÏÂÒÁÚÉÔØ, ÎÅÉÚ×ÅÓÔÎÏ ÓËÏÌØËÏ ÂÙ ÍÕÞÉÌ ÅÝ£ Ó×ÏÊ Ë£ÒÎÅÌ :)

ïÔ×ÅÔÉÔØ | ðÒÁ×ËÁ | ^ Ë ÒÏÄÉÔÅÌÀ #10 | îÁ×ÅÒÈ | CÏÏÂÝÉÔØ ÍÏÄÅÒÁÔÏÒÕ

áÒÈÉ× | õÄÁÌÉÔØ

òÅËÏÍÅÎÄÏ×ÁÔØ ÄÌÑ ÐÏÍÅÝÅÎÉÑ × FAQ | éÎÄÅËÓ ÆÏÒÕÍÏ× | ôÅÍÙ | ðÒÅÄ. ÔÅÍÁ | óÌÅÄ. ÔÅÍÁ




ðÁÒÔΣÒÙ:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
èÏÓÔÉÎÇ:

úÁËÌÁÄËÉ ÎÁ ÓÁÊÔÅ
ðÒÏÓÌÅÄÉÔØ ÚÁ ÓÔÒÁÎÉÃÅÊ
Created 1996-2024 by Maxim Chirkov
äÏÂÁ×ÉÔØ, ðÏÄÄÅÒÖÁÔØ, ÷ÅÂÍÁÓÔÅÒÕ