>> Delete No. 48092 article
No. Portsentry 파싹하게 잘 하신분?

등록 2002-05-01 16:18:00 By localhost     조회 1
이름 로리투    

지금 해당 서버에 portsentry를 돌리고 있습니다. 그래서 test로 다른쪽
서버에서 포트스캔을 했더니 해당서버 /etc/hosts.deny파일에 ip가
정상적으로 적혀 있더군요.. ALL:211.174.***.***
 그래서 포트스캔을 한 서버에서 ssh와 ftp접속을 해봤더니.. ssh는
접속이 안됐고.. ftp는 접속이 정상적으로 되더군요..
당연히 ftp도 접속이 되지 않아야 하지 않나요?
 [root@MRTG root]# ssh root@211.174.***.***
ssh_exchange_identification: Connection closed by remote host
[root@MRTG root]# ftp 211.174.***.***
Connected to 211.174.***.*** (211.174.***.***).
220 PorFTPd Account Server ready ..
Name (211.174.***.***:root):
 그렇다면 portsentry.conf에서 어딜 더 봐줘야 하나요?
제가 설정해 놓은 부분(주석제거)은 아래와 같거든요..
 # Use these if you just want to be aware:
TCP_PORTS="21,22,25,53,80,110,3306"
UDP_PORTS="21,22,25,53,80,110,3306"
 ADVANCED_PORTS_TCP="1024"
ADVANCED_PORTS_UDP="1024"
 # Default TCP ident and NetBIOS service
ADVANCED_EXCLUDE_TCP="113,139"
# Default UDP route (RIP), NetBIOS, bootp broadcasts.
ADVANCED_EXCLUDE_UDP="520,138,137,67"
 # Hosts to ignore
IGNORE_FILE="/usr/local/psionic/portsentry/portsentry.ignore"
# Hosts that have been denied (running history)
HISTORY_FILE="/usr/local/psionic/portsentry/portsentry.history"
# Hosts that have been denied this session only (temporary until next restart)
BLOCKED_FILE="/usr/local/psionic/portsentry/portsentry.blocked"
 # Generic Linux
KILL_ROUTE="/sbin/route add -host $TARGET$ gw 333.444.555.666"
# ipchain support for Linux (no logging of denied packets)
KILL_ROUTE="/sbin/ipchains -I input -s $TARGET$ -j DENY"
................
[관리자] 패스워드를 입력 하십시오. 답장이 존재하면 함께 삭제됩니다.[ 목록 | 이전 ]
패스워드:    

Copyleft 1999-2026 by JSBoard Open Project
Theme Designed by IDOO All right reserved