ΡΠ΅Π»ΠΎΠ²Π΅ΠΊ Ρ Π±ΡΠΌΠ°ΠΆΠ½ΡΠΌ ΠΏΠ°ΠΊΠ΅ΡΠΎΠΌ Π½Π° Π³ΠΎΠ»ΠΎΠ²Π΅
Π‘Π΅Π³ΠΎΠ΄Π½Ρ ΠΏΠΎΡΠ»Π΅ ΠΎΠ±Π½ΠΎΠ²Π»Π΅Π½ΠΈΡ Catalina Ρ 15.6 Π½Π° 15.7, ΠΏΡΠΎΡΠ΅Π»Π° ΡΠΊΠΎΡΠΎΡΡΡ ΠΈΠ½ΡΠ΅ΡΠ½Π΅ΡΠ°, ΡΡΠΎ-ΡΠΎ ΡΠΈΠ»ΡΠ½ΠΎ Π³ΡΡΠ·ΠΈΠ»ΠΎ ΠΌΠΎΡ ΡΠ΅ΡΡ ΠΈ Ρ ΡΠ΅ΡΠΈΠ» ΠΏΠΎΡΠΌΠΎΡΡΠ΅ΡΡ ΡΠ΅ΡΠ΅Π²ΡΡ Π°ΠΊΡΠΈΠ²Π½ΠΎΡΡΡ.
ΠΠ°ΠΏΡΡΡΠΈΠ» tcpdump Π½Π° ΠΏΠ°ΡΡ ΡΠ°ΡΠΎΠ²:
sudo tcpdump -k NP > ~/log
Π ΠΏΠ΅ΡΠ²ΠΎΠ΅, ΡΡΠΎ Π±ΡΠΎΡΠΈΠ»ΠΎΡΡ ΠΌΠ½Π΅ Π² Π³Π»Π°Π·Π°:
16:43:42.919443 () ARP, Request who-has 192.168.1.51 tell 192.168.1.1, length 28
16:43:42.927716 () ARP, Request who-has 192.168.1.52 tell 192.168.1.1, length 28
16:43:42.934112 () ARP, Request who-has 192.168.1.53 tell 192.168.1.1, length 28
16:43:42.942328 () ARP, Request who-has 192.168.1.54 tell 192.168.1.1, length 28
16:43:43.021971 () ARP, Request who-has 192.168.1.55 tell 192.168.1.1, length 28
ΠΠ°ΡΠ΅ΠΌ Π΅ΠΌΡ Π²ΡΡ ΠΌΠΎΡ Π»ΠΎΠΊΠ°Π»ΡΠ½Π°Ρ ΡΠ΅ΡΡ? ΠΠ½ Π΅Π΅ ΡΠΊΠ°Π½ΠΈΡΡΠ΅Ρ Π±Π΅Π· ΠΊΠΎΠ½ΡΠ° ΠΊΠ°ΠΆΠ΄ΡΡ ΠΌΠΈΠ½ΡΡΡ 192.168.1./255, Π»Π°Π΄Π½ΠΎ, Π΄ΠΎΠΏΡΡΡΠΈΠΌ, ΡΡΠΎ ΡΠ»ΡΠΆΠ±Π° ΡΠ΅ΡΠ΅Π²ΠΎΠ³ΠΎ ΠΎΠ±ΠΎΠ·ΡΠ΅Π²Π°ΡΠ΅Π»Ρ.
(shadowserver.org) — Π½Π΅ΠΊΠΎΠΌΠΌΠ΅ΡΡΠ΅ΡΠΊΠ°Ρ ΠΎΡΠ³Π°Π½ΠΈΠ·Π°ΡΠΈΡ ΠΏΠΎ ΠΎΠ±Π΅ΡΠΏΠ΅ΡΠ΅Π½ΠΈΡ Π±Π΅Π·ΠΎΠΏΠ°ΡΠ½ΠΎΡΡΠΈ
16:43:33.518282 () IP scan-05l.shadowserver.org.33567 > 192.168.1.150.rsync: Flags [S], seq 1527048226, win 65535, options [mss 536], length 0
ΠΡΠ΅ ΠΎΠ΄Π½Π° ΡΡΡΡΠ°Π»ΠΊΠ° (scanner-12.ch1.censys-scanner.com -> censys.io):
16:44:16.254073 () IP scanner-12.ch1.censys-scanner.com.62651 > 192.168.1.150.8843: Flags [S], seq 1454862354, win 1024, options [mss 1460], length 0
ΠΠ°Π΄Π½ΠΎ, ΠΎΠΊΠ΅ΠΉ, Π²ΡΠΎΠ΄Π΅ Π½ΠΈΡΠ΅Π³ΠΎ ΠΎΡΠΎΠ±Π΅Π½Π½ΠΎΠ³ΠΎ: Π°Π½Π°Π»ΠΈΡΠΈΠΊΠ°, ΡΠΊΠ°Π½ΠΈΡΠΎΠ²Π°Π½ΠΈΠ΅ Π»ΠΎΠΊΠ°Π»ΡΠ½ΠΎΠΉ ΡΠ΅ΡΠΈ, Π½Ρ ΠΎΠ±ΡΡΠ½ΠΎΠ΅ Π΄Π΅Π»ΠΎ, Π½ΠΎ ΡΡΠΎ ΡΠΎΠ³Π΄Π° Π²ΠΎΡ ΡΡΠΎ:
16:15:56.603292 () IP 45.129.33.152.51777 > 192.168.1.150.jpegmpeg: Flags [S], seq 2349838714, win 1024, options [mss 536], length 0
ΠΡΠ»ΠΈ ΠΏΠ΅ΡΠ΅ΠΉΡΠΈ ΠΏΠΎ ΡΡΠΎΠΌΡ ip Π°Π΄ΡΠ΅ΡΡ
Π’Π΅ΠΊΡΡΠΎΠ²ΡΠ΅ ΡΠ°ΠΉΠ»Ρ ΡΠΎΠ΄Π΅ΡΠΆΠ°Ρ ΠΌΠΈΠ»Π»ΠΈΠΎΠ½Ρ ip Π°Π΄ΡΠ΅ΡΠΎΠ² Ρ ΠΏΠΎΡΡΠ°ΠΌΠΈ.
Π‘ΠΎΠ΄Π΅ΡΠΆΠ°Π½ΠΈΠ΅ ΡΠ°ΠΉΠ»Π° temp:
[?1h=[?25l[H[J[mtop - 21:17:26 up 31 days, 6:44, 1 use[m[39;49m[m[39;49m[K
Tasks:[m[39;49m[1m 144 [m[39;49mtotal,[m[39;49m[1m 1 [m[39;49mrunning,[m[39;49m[1m 143 [m[39;49msleep[m[39;49m[m[39;49m[K
%Cpu(s):[m[39;49m[1m 0.8 [m[39;49mus,[m[39;49m[1m 0.0 [m[39;49msy,[m[39;49m[1m 0.0 [m[39;49mni,[m[39;49m[1m 92.0[m[39;49m[m[39;49m[K
KiB Mem :[m[39;49m[1m 32681700 [m[39;49mtotal,[m[39;49m[1m 18410244 [m[39;49mfree,[m[39;49m[m[39;49m[K
KiB Swap:[m[39;49m[1m 16449532 [m[39;49mtotal,[m[39;49m[1m 16449288 [m[39;49mfree,[m[39;49m[m[39;49m[K
[K
[7m PID USER PR NI VIRT RES [m[39;49m[K
[m 1 root 20 0 191072 3924 [m[39;49m[K
[m 2 root 20 0 0 0 [m[39;49m[K
[m 3 root 20 0 0 0 [m[39;49m[K
[m 5 root 0 -20 0 0 [m[39;49m[K
[m 7 root rt 0 0 0 [m[39;49m[K
[m 8 root 20 0 0 0 [m[39;49m[K
[m 9 root 20 0 0 0 [m[39;49m[K
[m 10 root rt 0 0 0 [m[39;49m[K
[m 11 root rt 0 0 0 [m[39;49m[K
[m 12 root rt 0 0 0 [m[39;49m[K
[m 13 root 20 0 0 0 [m[39;49m[K
[m 15 root 0 -20 0 0 [m[39;49m[K
[m 16 root rt 0 0 0 [m[39;49m[K[H[mtop - 21:17:29 up 31 days, 6:44, 1 use[m[39;49m[m[39;49m[K
%Cpu(s):[m[39;49m[1m 0.0 [m[39;49mus,[m[39;49m[1m 0.0 [m[39;49msy,[m[39;49m[1m 0.0 [m[39;49mni,[m[39;49m[1m100.0[m[39;49m[m[39;49m[K
KiB Mem :[m[39;49m[1m 32681700 [m[39;49mtotal,[m[39;49m[1m 18409876 [m[39;49mfree,[m[39;49m[m[39;49m[K
[K
ΠΡ ΠΈ Π½Π°ΠΏΠΎΡΠ»Π΅Π΄ΠΎΠΊ ΠΏΠ°ΡΠΊΠ° Π½Π΅ΠΈΠ·Π²Π΅ΡΡΠ½ΡΡ Π·Π°ΠΏΡΠΎΡΠΎΠ²:
16:16:07.022910 () IP 059148253194.ctinets.com.58703 > 192.168.1.150.4244: Flags [S], seq 2829545743, win 1024, options [mss 536], length 0
16:15:57.133836 () IP 45.129.33.2.55914 > 192.168.1.150.39686: Flags [S], seq 700814637, win 1024, options [mss 536], length 0
16:15:56.603292 () IP 45.129.33.152.51777 > 192.168.1.150.jpegmpeg: Flags [S], seq 2349838714, win 1024, options [mss 536], length 0
16:16:15.083755 () IP 45.129.33.154.55846 > 192.168.1.150.7063: Flags [S], seq 4079154719, win 1024, options [mss 536], length 0
16:15:43.251305 () IP 192.168.1.150.60314 > one.one.one.one.domain: 3798+ PTR? 237.171.154.149.in-addr.arpa. (46)
16:16:24.386628 () IP 45.141.84.30.50763 > 192.168.1.150.12158: Flags [S], seq 572523718, win 1024, options [mss 536], length 0
16:16:44.817035 () IP 92.63.197.66.58219 > 192.168.1.150.15077: Flags [S], seq 4012437618, win 1024, options [mss 536], length 0
16:15:43.172042 () IP 45.129.33.46.51641 > 192.168.1.150.bnetgame: Flags [S], seq 362771723, win 1024, options [mss 536], length 0
16:17:02.120063 () IP 45.129.33.23.42275 > 192.168.1.150.11556: Flags [S], seq 3354007029, win 1024, options [mss 536], length 0
16:16:00.589816 () IP 45.129.33.3.56005 > 192.168.1.150.40688: Flags [S], seq 2710391040, win 1024, options [mss 536], length 0
ΠΡΠ»ΠΈ Ρ Π±Π»ΠΎΠΊΠΈΡΡΡ ΡΡΠΈ Π΄ΠΎΠΌΠ΅Π½Ρ ΠΈ ip Π°Π΄ΡΠ΅ΡΠ° Π² ΡΠ°ΠΉΠ»Π΅ host, ΡΠΎ Π² ΡΠ»Π΅Π΄ΡΡΡΠ΅ΠΌ Π΄Π°ΠΌΠΏΠ΅ Π±ΡΠ΄ΡΡ ΡΠ΅ ΠΆΠ΅ ΠΏΠΎΠ΄ΡΠ΅ΡΠΈ ip, Π½ΠΎ Ρ Π΄ΡΡΠ³ΠΈΠΌΠΈ ΠΊΠΎΠ½Π΅ΡΠ½ΡΠΌΠΈ Π°Π΄ΡΠ΅ΡΠ°ΠΌΠΈ, ΠΈ Ρ Π΄ΠΎΠΌΠ΅Π½ΠΎΠ² ΠΌΠ΅Π½ΡΠ΅ΡΡΡ ΠΏΠΎΠ΄Π΄ΠΎΠΌΠ΅Π½.
ΠΠ°ΠΊ Π½Π΅ ΠΏΠΎΠ½ΠΈΠΌΠ°Π΅Ρ ΠΌΠ°ΡΠΊΡ Π² ΡΠ°ΠΉΠ»Π΅ host *.example.com
ΠΠ°ΠΊ ΡΠΌΠΎΡΡΠ΅ΡΡ ΠΏΠ°ΠΊΠ΅ΡΡ, ΠΊΠΎΡΠΎΡΡΠ΅ ΠΏΠ΅ΡΠ΅Π΄Π°ΡΡΡΡ ΠΈ ΠΊΠ°ΠΊΠΈΠ΅ ΠΏΡΠΎΡΠ΅ΡΡΡ ΠΈΠ»ΠΈ Π΄Π΅ΠΌΠΎΠ½Ρ Π²ΡΠ·ΡΠ²Π°ΡΡ ΡΡΠΈ ΡΠΎΠ΅Π΄ΠΈΠ½Π΅Π½ΠΈΡ, Ρ ΠΏΠΎΠΊΠ° Π½Π΅ ΠΏΠΎΠ½ΡΠ» (ΠΎΠ±Π»Π°Π΄Π°Ρ ΠΌΠ°ΠΊΠΎΠΌ Π½Π΅ΡΠΊΠΎΠ»ΡΠΊΠΎ Π΄Π½Π΅ΠΉ), Π½ΠΎ ΡΠΆΠ΅ Π²Π΅ΡΠ΅Π»ΠΎ!
ΠΡΡΠΎΡΠ½ΠΈΠΊ: habr.com