|
커피향이 나는 *NIX
커피닉스
시스템/네트웍/보안을 다루는 곳
|
|
|
|
| 이전 주제 보기 :: 다음 주제 보기 |
| 글쓴이 |
메시지 |
bird72
가입: 2003년 9월 24일 올린 글: 77
|
올려짐: 2004.3.10 수, 7:15 pm 주제: [질문]portsenty 실행 시 나타나는 로그의 원인이 궁금합니다. |
|
|
안녕하세요..^^
오늘도 열심히 배우고 있는 초보관리자 입니다.
우연히 portsentry를 실행중지 후 다시 재시작을 했는데...
/var/log/message 에 아래와 같은 로그가 나오는 것을 봤습니다.
이게 무슨 원인으로 남겨지는 로그인가요???
참고로 배포한은 'redhat 7.3'이며 커널은 '2.4.25' 이고 'iptable'을 'portsentry'와 연동해서 사용하고 있습니다.
| 코드: |
Mar 10 19:11:28 xxx portsentry[12077]: adminalert: Psionic PortSentry 1.1 is starting.
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: Going into stealth listen mode on UDP port: 53
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: Going into stealth listen mode on UDP port: 138
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: Going into stealth listen mode on UDP port: 139
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: PortSentry is now active and listening.
Mar 10 19:11:29 xxx portsentry[12079]: adminalert: Psionic PortSentry 1.1 is starting.
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 21
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 21. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 22
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 22. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 25
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 25. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 80
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 80. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 110
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 110. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12081]: adminalert: Psionic PortSentry 1.1 is starting.
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 123
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 3306
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 3306. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12082]: adminalert: Going into listen mode on UDP port: 53
Mar 10 19:11:29 xxx portsentry[12082]: adminalert: Going into listen mode on UDP port: 138
Mar 10 19:11:29 xxx portsentry[12082]: adminalert: Going into listen mode on UDP port: 139
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: PortSentry is now active and listening.
Mar 10 19:11:29 xxx portsentry[12082]: adminalert: PortSentry is now active and listening.
Mar 10 19:11:29 xxx portsentry[12083]: adminalert: Psionic PortSentry 1.1 is starting.
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced mode will monitor first 1024 ports
Mar 10 19:11:29 xxx portsentry[12085]: adminalert: Psionic PortSentry 1.1 is starting.
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced mode will monitor first 1024 ports
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced mode will manually exclude port: 520
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced mode will manually exclude port: 138
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced mode will manually exclude port: 137
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced mode will manually exclude port: 67
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced Stealth scan detection mode activated. Ignored UDP port: 53
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced Stealth scan detection mode activated. Ignored UDP port: 138
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced Stealth scan detection mode activated. Ignored UDP port: 139
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced Stealth scan detection mode activated. Ignored UDP port: 520
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced Stealth scan detection mode activated. Ignored UDP port: 138
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced Stealth scan detection mode activated. Ignored UDP port: 137
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced Stealth scan detection mode activated. Ignored UDP port: 67
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: PortSentry is now active and listening.
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced mode will manually exclude port: 113
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced mode will manually exclude port: 139
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 21
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 22
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 25
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 80
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 110
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 123
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 587
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 113
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 139
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: PortSentry is now active and listening.
|
위 로그중에 보면 중간중간에 'ERROR: could not bind TCP socket: ~' 라고 나오는데 이게 무엇 때문에 발생하는 에러인가요??
궁금합니다.
고수님들 알려주시면 정말 감사하겠습니다.
그럼 수고하세요...^^ _________________ ilovesusu |
|
| 위로 |
|
 |
바라미
가입: 2003년 8월 22일 올린 글: 26 위치: 서울
|
올려짐: 2004.3.10 수, 10:37 pm 주제: Re: portsenty 실행 시 로그의 원인이 궁금합니다. |
|
|
| bird72 씀: |
| 코드: |
Mar 10 19:11:28 xxx portsentry[12077]: adminalert: Psionic PortSentry 1.1 is starting.
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: Going into stealth listen mode on UDP port: 53
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: Going into stealth listen mode on UDP port: 138
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: Going into stealth listen mode on UDP port: 139
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: PortSentry is now active and listening.
Mar 10 19:11:29 xxx portsentry[12079]: adminalert: Psionic PortSentry 1.1 is starting.
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 21
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 21. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 22
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 22. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 25
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 25. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 80
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 80. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 110
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 110. Attempting to continue
|
위 로그중에 보면 중간중간에 'ERROR: could not bind TCP socket: ~' 라고 나오는데 이게 무엇 때문에 발생하는 에러인가요??
궁금합니다.
고수님들 알려주시면 정말 감사하겠습니다.
그럼 수고하세요...^^ |
시스템에 문제가 있는 것은 아니니 걱정은 안하셔도 되겠네요.
portsentry는 포트 감시를 위해 여러 포트를 열어두거든요.
그런데 위의 에러메시지에 나온 21,22,80 등의 포트는 이미 사용중이므로 portsentry가 이 포트를 열 수 없다는 겁니다.
전혀 문제가 될 부분이 아닙니다.
위에 에러가 난 포트는 이렇습니다. 혹시 안쓰는데 열린거라면 서비스를 내리시길...
21 = FTP
22 = ssh
25 = mail
80 = web(httpd)
110 = pop3
3306 = MySQL |
|
| 위로 |
|
 |
bird72
가입: 2003년 9월 24일 올린 글: 77
|
올려짐: 2004.3.11 목, 9:36 am 주제: 답변 정말 감사합니다. |
|
|
답변 정말 감사합니다.
그런데... 에러난 포트들은 전부 사용중인 서비스 입니다.
만약 저런 로그가 나오지 않도록 하려면 어떻게 해야하는 것인가요??
서비스를 전부 내린 후에 portsetnry를 실행하고 다시 서비스를 올려야 하는 것인가요?? _________________ ilovesusu |
|
| 위로 |
|
 |
|
|
새로운 주제를 올릴 수 없습니다 답글을 올릴 수 없습니다 주제를 수정할 수 있습니다 올린 글을 삭제할 수 없습니다 투표를 할 수 없습니다
|
Powered by phpBB © 2001, 2005 phpBB Group
|