ÀÌÀü ÁÖÁ¦ º¸±â :: ´ÙÀ½ ÁÖÁ¦ º¸±â |
±Û¾´ÀÌ |
¸Þ½ÃÁö |
bird72
°¡ÀÔ: 2003³â 9¿ù 24ÀÏ ¿Ã¸° ±Û: 77
|
¿Ã·ÁÁü: 2004.3.10 ¼ö, 7:15 pm ÁÖÁ¦: [Áú¹®]portsenty ½ÇÇà ½Ã ³ªÅ¸³ª´Â ·Î±×ÀÇ ¿øÀÎÀÌ ±Ã±ÝÇÕ´Ï´Ù. |
|
|
¾È³çÇϼ¼¿ä..^^
¿À´Ãµµ ¿½ÉÈ÷ ¹è¿ì°í ÀÖ´Â Ãʺ¸°ü¸®ÀÚ ÀÔ´Ï´Ù.
¿ì¿¬È÷ portsentry¸¦ ½ÇÇàÁßÁö ÈÄ ´Ù½Ã Àç½ÃÀÛÀ» Çߴµ¥...
/var/log/message ¿¡ ¾Æ·¡¿Í °°Àº ·Î±×°¡ ³ª¿À´Â °ÍÀ» ºÃ½À´Ï´Ù.
ÀÌ°Ô ¹«½¼ ¿øÀÎÀ¸·Î ³²°ÜÁö´Â ·Î±×Àΰ¡¿ä???
Âü°í·Î ¹èÆ÷ÇÑÀº 'redhat 7.3'À̸ç Ä¿³ÎÀº '2.4.25' À̰í 'iptable'À» 'portsentry'¿Í ¿¬µ¿Çؼ »ç¿ëÇϰí ÀÖ½À´Ï´Ù.
ÄÚµå: |
Mar 10 19:11:28 xxx portsentry[12077]: adminalert: Psionic PortSentry 1.1 is starting.
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: Going into stealth listen mode on UDP port: 53
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: Going into stealth listen mode on UDP port: 138
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: Going into stealth listen mode on UDP port: 139
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: PortSentry is now active and listening.
Mar 10 19:11:29 xxx portsentry[12079]: adminalert: Psionic PortSentry 1.1 is starting.
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 21
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 21. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 22
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 22. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 25
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 25. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 80
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 80. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 110
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 110. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12081]: adminalert: Psionic PortSentry 1.1 is starting.
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 123
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 3306
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 3306. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12082]: adminalert: Going into listen mode on UDP port: 53
Mar 10 19:11:29 xxx portsentry[12082]: adminalert: Going into listen mode on UDP port: 138
Mar 10 19:11:29 xxx portsentry[12082]: adminalert: Going into listen mode on UDP port: 139
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: PortSentry is now active and listening.
Mar 10 19:11:29 xxx portsentry[12082]: adminalert: PortSentry is now active and listening.
Mar 10 19:11:29 xxx portsentry[12083]: adminalert: Psionic PortSentry 1.1 is starting.
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced mode will monitor first 1024 ports
Mar 10 19:11:29 xxx portsentry[12085]: adminalert: Psionic PortSentry 1.1 is starting.
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced mode will monitor first 1024 ports
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced mode will manually exclude port: 520
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced mode will manually exclude port: 138
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced mode will manually exclude port: 137
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced mode will manually exclude port: 67
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced Stealth scan detection mode activated. Ignored UDP port: 53
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced Stealth scan detection mode activated. Ignored UDP port: 138
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced Stealth scan detection mode activated. Ignored UDP port: 139
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced Stealth scan detection mode activated. Ignored UDP port: 520
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced Stealth scan detection mode activated. Ignored UDP port: 138
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced Stealth scan detection mode activated. Ignored UDP port: 137
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: Advanced Stealth scan detection mode activated. Ignored UDP port: 67
Mar 10 19:11:29 xxx portsentry[12086]: adminalert: PortSentry is now active and listening.
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced mode will manually exclude port: 113
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced mode will manually exclude port: 139
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 21
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 22
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 25
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 80
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 110
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 123
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 587
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 113
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: Advanced Stealth scan detection mode activated. Ignored TCP port: 139
Mar 10 19:11:29 xxx portsentry[12084]: adminalert: PortSentry is now active and listening.
|
À§ ·Î±×Áß¿¡ º¸¸é Áß°£Áß°£¿¡ 'ERROR: could not bind TCP socket: ~' ¶ó°í ³ª¿À´Âµ¥ ÀÌ°Ô ¹«¾ù ¶§¹®¿¡ ¹ß»ýÇÏ´Â ¿¡·¯Àΰ¡¿ä??
±Ã±ÝÇÕ´Ï´Ù.
°í¼ö´Ôµé ¾Ë·ÁÁֽøé Á¤¸» °¨»çÇϰڽÀ´Ï´Ù.
±×·³ ¼ö°íÇϼ¼¿ä...^^ _________________ ilovesusu |
|
À§·Î |
|
 |
¹Ù¶ó¹Ì
°¡ÀÔ: 2003³â 8¿ù 22ÀÏ ¿Ã¸° ±Û: 26 À§Ä¡: ¼¿ï
|
¿Ã·ÁÁü: 2004.3.10 ¼ö, 10:37 pm ÁÖÁ¦: Re: portsenty ½ÇÇà ½Ã ·Î±×ÀÇ ¿øÀÎÀÌ ±Ã±ÝÇÕ´Ï´Ù. |
|
|
bird72 ¾¸: |
ÄÚµå: |
Mar 10 19:11:28 xxx portsentry[12077]: adminalert: Psionic PortSentry 1.1 is starting.
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: Going into stealth listen mode on UDP port: 53
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: Going into stealth listen mode on UDP port: 138
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: Going into stealth listen mode on UDP port: 139
Mar 10 19:11:29 xxx portsentry[12078]: adminalert: PortSentry is now active and listening.
Mar 10 19:11:29 xxx portsentry[12079]: adminalert: Psionic PortSentry 1.1 is starting.
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 21
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 21. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 22
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 22. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 25
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 25. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 80
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 80. Attempting to continue
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: Going into listen mode on TCP port: 110
Mar 10 19:11:29 xxx portsentry[12080]: adminalert: ERROR: could not bind TCP socket: 110. Attempting to continue
|
À§ ·Î±×Áß¿¡ º¸¸é Áß°£Áß°£¿¡ 'ERROR: could not bind TCP socket: ~' ¶ó°í ³ª¿À´Âµ¥ ÀÌ°Ô ¹«¾ù ¶§¹®¿¡ ¹ß»ýÇÏ´Â ¿¡·¯Àΰ¡¿ä??
±Ã±ÝÇÕ´Ï´Ù.
°í¼ö´Ôµé ¾Ë·ÁÁֽøé Á¤¸» °¨»çÇϰڽÀ´Ï´Ù.
±×·³ ¼ö°íÇϼ¼¿ä...^^ |
½Ã½ºÅÛ¿¡ ¹®Á¦°¡ ÀÖ´Â °ÍÀº ¾Æ´Ï´Ï °ÆÁ¤Àº ¾ÈÇϼŵµ µÇ°Ú³×¿ä.
portsentry´Â Æ÷Æ® °¨½Ã¸¦ À§ÇØ ¿©·¯ Æ÷Æ®¸¦ ¿¾îµÎ°Åµç¿ä.
±×·±µ¥ À§ÀÇ ¿¡·¯¸Þ½ÃÁö¿¡ ³ª¿Â 21,22,80 µîÀÇ Æ÷Æ®´Â ÀÌ¹Ì »ç¿ëÁßÀ̹ǷΠportsentry°¡ ÀÌ Æ÷Æ®¸¦ ¿ ¼ö ¾ø´Ù´Â °Ì´Ï´Ù.
ÀüÇô ¹®Á¦°¡ µÉ ºÎºÐÀÌ ¾Æ´Õ´Ï´Ù.
À§¿¡ ¿¡·¯°¡ ³ Æ÷Æ®´Â ÀÌ·¸½À´Ï´Ù. Ȥ½Ã ¾È¾²´Âµ¥ ¿¸°°Å¶ó¸é ¼ºñ½º¸¦ ³»¸®½Ã±æ...
21 = FTP
22 = ssh
25 = mail
80 = web(httpd)
110 = pop3
3306 = MySQL |
|
À§·Î |
|
 |
bird72
°¡ÀÔ: 2003³â 9¿ù 24ÀÏ ¿Ã¸° ±Û: 77
|
¿Ã·ÁÁü: 2004.3.11 ¸ñ, 9:36 am ÁÖÁ¦: ´äº¯ Á¤¸» °¨»çÇÕ´Ï´Ù. |
|
|
´äº¯ Á¤¸» °¨»çÇÕ´Ï´Ù.
±×·±µ¥... ¿¡·¯³ Æ÷Æ®µéÀº ÀüºÎ »ç¿ëÁßÀÎ ¼ºñ½º ÀÔ´Ï´Ù.
¸¸¾à Àú·± ·Î±×°¡ ³ª¿ÀÁö ¾Êµµ·Ï ÇÏ·Á¸é ¾î¶»°Ô ÇØ¾ßÇÏ´Â °ÍÀΰ¡¿ä??
¼ºñ½º¸¦ ÀüºÎ ³»¸° ÈÄ¿¡ portsetnry¸¦ ½ÇÇàÇÏ°í ´Ù½Ã ¼ºñ½º¸¦ ¿Ã·Á¾ß ÇÏ´Â °ÍÀΰ¡¿ä?? _________________ ilovesusu |
|
À§·Î |
|
 |
|