ΠŸΠΎΠ³Π»Π΅Π΄Π½Π°Ρ… Ρ‚Ρ€Π°Ρ„ΠΈΠΊΠ° си: Ρ‚ΠΎΠΉ знаСшС всичко Π·Π° ΠΌΠ΅Π½ (Mac OS Catalina)

ΠŸΠΎΠ³Π»Π΅Π΄Π½Π°Ρ… Ρ‚Ρ€Π°Ρ„ΠΈΠΊΠ° си: Ρ‚ΠΎΠΉ знаСшС всичко Π·Π° ΠΌΠ΅Π½ (Mac OS Catalina)мъТ с Ρ…Π°Ρ€Ρ‚ΠΈΠ΅Π½Π° Ρ‚ΠΎΡ€Π±Π° Π½Π° Π³Π»Π°Π²Π°Ρ‚Π°

ДнСс, слСд ΡŠΠΏΠ΄Π΅ΠΉΡ‚ Π½Π° Catalina ΠΎΡ‚ 15.6 Π½Π° 15.7, скоростта Π½Π° ΠΈΠ½Ρ‚Π΅Ρ€Π½Π΅Ρ‚Π° ΠΏΠ°Π΄Π½Π°, Π½Π΅Ρ‰ΠΎ ΠΌΠ½ΠΎΠ³ΠΎ ΠΌΠΈ Π½Π°Ρ‚ΠΎΠ²Π°Ρ€Π²Π°ΡˆΠ΅ ΠΌΡ€Π΅ΠΆΠ°Ρ‚Π° ΠΈ Ρ€Π΅ΡˆΠΈΡ… Π΄Π° ΠΏΠΎΠ³Π»Π΅Π΄Π½Π° ΠΌΡ€Π΅ΠΆΠΎΠ²Π°Ρ‚Π° активност.

ΠŸΡƒΡΠΊΠ°Ρ… tcpdump Π·Π° няколко часа:

sudo tcpdump -k NP > ~/log 

И ΠΏΡŠΡ€Π²ΠΎΡ‚ΠΎ Π½Π΅Ρ‰ΠΎ, ΠΊΠΎΠ΅Ρ‚ΠΎ ΠΌΠΈ Ρ…Π²Π°Π½Π° ΠΎΠΊΠΎΡ‚ΠΎ:

16:43:42.919443 () ARP, Request who-has 192.168.1.51 tell 192.168.1.1, length 28
16:43:42.927716 () ARP, Request who-has 192.168.1.52 tell 192.168.1.1, length 28
16:43:42.934112 () ARP, Request who-has 192.168.1.53 tell 192.168.1.1, length 28
16:43:42.942328 () ARP, Request who-has 192.168.1.54 tell 192.168.1.1, length 28
16:43:43.021971 () ARP, Request who-has 192.168.1.55 tell 192.168.1.1, length 28

Π—Π°Ρ‰ΠΎ ΠΌΡƒ трябва цялата ΠΌΠΈ Π»ΠΎΠΊΠ°Π»Π½Π° ΠΌΡ€Π΅ΠΆΠ°? Π’ΠΎΠΉ Π³ΠΎ сканира Π±Π΅Π·ΠΊΡ€Π°ΠΉΠ½ΠΎ всяка ΠΌΠΈΠ½ΡƒΡ‚Π° 192.168.1./255, Π΄ΠΎΠ±Ρ€Π΅, Π΄Π° ΠΊΠ°ΠΆΠ΅ΠΌ, Ρ‡Π΅ Ρ‚ΠΎΠ²Π° Π΅ услуга Π·Π° ΠΌΡ€Π΅ΠΆΠΎΠ² Π±Ρ€Π°ΡƒΠ·ΡŠΡ€.

(shadowserver.org) β€” организация Π·Π° сигурност с нСстопанска Ρ†Π΅Π»

16:43:33.518282 () IP scan-05l.shadowserver.org.33567 > 192.168.1.150.rsync: Flags [S], seq 1527048226, win 65535, options [mss 536], length 0

Π”Ρ€ΡƒΠ³ΠΎ Ρ‡ΡƒΠΊΠ°Π»ΠΎ (scanner-12.ch1.censys-scanner.com -> censys.io):

16:44:16.254073 () IP scanner-12.ch1.censys-scanner.com.62651 > 192.168.1.150.8843: Flags [S], seq 1454862354, win 1024, options [mss 1460], length 0

Π”ΠΎΠ±Ρ€Π΅, Π΄ΠΎΠ±Ρ€Π΅, ΠΈΠ·Π³Π»Π΅ΠΆΠ΄Π° ΠΊΠ°Ρ‚ΠΎ Π½ΠΈΡ‰ΠΎ особСно: Π°Π½Π°Π»ΠΈΠ·ΠΈ, сканиранС Π½Π° Π»ΠΎΠΊΠ°Π»Π½Π°Ρ‚Π° ΠΌΡ€Π΅ΠΆΠ°, Π΄ΠΎΠ±Ρ€Π΅, ΠΎΠ±ΠΈΡ‡Π°ΠΉΠ½ΠΎΡ‚ΠΎ Π½Π΅Ρ‰ΠΎ, Π½ΠΎ ΠΊΠ°ΠΊΠ²ΠΎ Ρ‰Π΅ ΠΊΠ°ΠΆΠ΅Ρ‚Π΅ Π·Π° Ρ‚ΠΎΠ²Π°:

16:15:56.603292 () IP 45.129.33.152.51777 > 192.168.1.150.jpegmpeg: Flags [S], seq 2349838714, win 1024, options [mss 536], length 0

Ако ΠΎΡ‚ΠΈΠ΄Π΅Ρ‚Π΅ Π½Π° Ρ‚ΠΎΠ·ΠΈ IP адрСс http://45.129.33.152, ΠΌΠΎΠΆΠ΅Ρ‚Π΅ Π΄Π° Π²ΠΈΠ΄ΠΈΡ‚Π΅ Ρ‚ΠΎΠ²Π°:

ΠŸΠΎΠ³Π»Π΅Π΄Π½Π°Ρ… Ρ‚Ρ€Π°Ρ„ΠΈΠΊΠ° си: Ρ‚ΠΎΠΉ знаСшС всичко Π·Π° ΠΌΠ΅Π½ (Mac OS Catalina)ВСкстовитС Ρ„Π°ΠΉΠ»ΠΎΠ²Π΅ ΡΡŠΠ΄ΡŠΡ€ΠΆΠ°Ρ‚ ΠΌΠΈΠ»ΠΈΠΎΠ½ΠΈ IP адрСси с ΠΏΠΎΡ€Ρ‚ΠΎΠ²Π΅.

Π‘ΡŠΠ΄ΡŠΡ€ΠΆΠ°Π½ΠΈΠ΅ Π½Π° врСмСнния Ρ„Π°ΠΉΠ»:

[?1h=[?25l[H[J[mtop - 21:17:26 up 31 days,  6:44,  1 use[m[39;49m[m[39;49m[K
Tasks:[m[39;49m[1m 144 [m[39;49mtotal,[m[39;49m[1m   1 [m[39;49mrunning,[m[39;49m[1m 143 [m[39;49msleep[m[39;49m[m[39;49m[K
%Cpu(s):[m[39;49m[1m  0.8 [m[39;49mus,[m[39;49m[1m  0.0 [m[39;49msy,[m[39;49m[1m  0.0 [m[39;49mni,[m[39;49m[1m 92.0[m[39;49m[m[39;49m[K
KiB Mem :[m[39;49m[1m 32681700 [m[39;49mtotal,[m[39;49m[1m 18410244 [m[39;49mfree,[m[39;49m[m[39;49m[K
KiB Swap:[m[39;49m[1m 16449532 [m[39;49mtotal,[m[39;49m[1m 16449288 [m[39;49mfree,[m[39;49m[m[39;49m[K
[K
[7m  PID USER      PR  NI    VIRT    RES [m[39;49m[K
[m    1 root      20   0  191072   3924 [m[39;49m[K
[m    2 root      20   0       0      0 [m[39;49m[K
[m    3 root      20   0       0      0 [m[39;49m[K
[m    5 root       0 -20       0      0 [m[39;49m[K
[m    7 root      rt   0       0      0 [m[39;49m[K
[m    8 root      20   0       0      0 [m[39;49m[K
[m    9 root      20   0       0      0 [m[39;49m[K
[m   10 root      rt   0       0      0 [m[39;49m[K
[m   11 root      rt   0       0      0 [m[39;49m[K
[m   12 root      rt   0       0      0 [m[39;49m[K
[m   13 root      20   0       0      0 [m[39;49m[K
[m   15 root       0 -20       0      0 [m[39;49m[K
[m   16 root      rt   0       0      0 [m[39;49m[K[H[mtop - 21:17:29 up 31 days,  6:44,  1 use[m[39;49m[m[39;49m[K

%Cpu(s):[m[39;49m[1m  0.0 [m[39;49mus,[m[39;49m[1m  0.0 [m[39;49msy,[m[39;49m[1m  0.0 [m[39;49mni,[m[39;49m[1m100.0[m[39;49m[m[39;49m[K
KiB Mem :[m[39;49m[1m 32681700 [m[39;49mtotal,[m[39;49m[1m 18409876 [m[39;49mfree,[m[39;49m[m[39;49m[K

[K

И накрая, ΠΊΡƒΠΏ нСизвСстни заявки:

16:16:07.022910 () IP 059148253194.ctinets.com.58703 > 192.168.1.150.4244: Flags [S], seq 2829545743, win 1024, options [mss 536], length 0
16:15:57.133836 () IP 45.129.33.2.55914 > 192.168.1.150.39686: Flags [S], seq 700814637, win 1024, options [mss 536], length 0
16:15:56.603292 () IP 45.129.33.152.51777 > 192.168.1.150.jpegmpeg: Flags [S], seq 2349838714, win 1024, options [mss 536], length 0
16:16:15.083755 () IP 45.129.33.154.55846 > 192.168.1.150.7063: Flags [S], seq 4079154719, win 1024, options [mss 536], length 0
16:15:43.251305 () IP 192.168.1.150.60314 > one.one.one.one.domain: 3798+ PTR? 237.171.154.149.in-addr.arpa. (46)
16:16:24.386628 () IP 45.141.84.30.50763 > 192.168.1.150.12158: Flags [S], seq 572523718, win 1024, options [mss 536], length 0
16:16:44.817035 () IP 92.63.197.66.58219 > 192.168.1.150.15077: Flags [S], seq 4012437618, win 1024, options [mss 536], length 0
16:15:43.172042 () IP 45.129.33.46.51641 > 192.168.1.150.bnetgame: Flags [S], seq 362771723, win 1024, options [mss 536], length 0
16:17:02.120063 () IP 45.129.33.23.42275 > 192.168.1.150.11556: Flags [S], seq 3354007029, win 1024, options [mss 536], length 0
16:16:00.589816 () IP 45.129.33.3.56005 > 192.168.1.150.40688: Flags [S], seq 2710391040, win 1024, options [mss 536], length 0

Ако Π±Π»ΠΎΠΊΠΈΡ€Π°ΠΌ Ρ‚Π΅Π·ΠΈ Π΄ΠΎΠΌΠ΅ΠΉΠ½ΠΈ ΠΈ IP адрСси Π² хост Ρ„Π°ΠΉΠ»Π°, Ρ‚ΠΎΠ³Π°Π²Π° Π² слСдващия дъмп Ρ‰Π΅ ΠΈΠΌΠ° ΡΡŠΡ‰ΠΈΡ‚Π΅ IP ΠΏΠΎΠ΄ΠΌΡ€Π΅ΠΆΠΈ, Π½ΠΎ с Ρ€Π°Π·Π»ΠΈΡ‡Π½ΠΈ ΠΊΡ€Π°ΠΉΠ½ΠΈ адрСси ΠΈ ΠΏΠΎΠ΄Π΄ΠΎΠΌΠ΅ΠΉΠ½ΠΈΡ‚Π΅ Π½Π° Π΄ΠΎΠΌΠ΅ΠΉΠ½ΠΈΡ‚Π΅ сС промСнят.

Mac Π½Π΅ Ρ€Π°Π·Π±ΠΈΡ€Π° маската Π² хост Ρ„Π°ΠΉΠ»Π° *.example.com

НС Ρ€Π°Π·Π±Ρ€Π°Ρ… ΠΊΠ°ΠΊ Π΄Π° Π³Π»Π΅Π΄Π°ΠΌ ΠΏΠ°ΠΊΠ΅Ρ‚ΠΈΡ‚Π΅, ΠΊΠΎΠΈΡ‚ΠΎ сС ΠΏΡ€Π΅Ρ…Π²ΡŠΡ€Π»ΡΡ‚ ΠΈ ΠΊΠ°ΠΊΠ²ΠΈ процСси ΠΈΠ»ΠΈ Π΄Π΅ΠΌΠΎΠ½ΠΈ причиняват Ρ‚Π΅Π·ΠΈ Π²Ρ€ΡŠΠ·ΠΊΠΈ (ΠΈΠΌΠ°ΠΌ Mac ΠΎΡ‚ няколко Π΄Π½ΠΈ), Π½ΠΎ Π²Π΅Ρ‡Π΅ Π΅ Π·Π°Π±Π°Π²Π½ΠΎ!

Π˜Π·Ρ‚ΠΎΡ‡Π½ΠΈΠΊ: www.habr.com