āĻŽāĻžāĻĨāĻžāĻ¯āĻŧ āĻāĻžāĻāĻā§āĻ° āĻŦā§āĻ¯āĻžāĻ āĻ¨āĻŋāĻ¯āĻŧā§ āĻŽāĻžāĻ¨ā§āĻˇ
āĻāĻ, 15.6 āĻĨā§āĻā§ 15.7 āĻĒāĻ°ā§āĻ¯āĻ¨ā§āĻ¤ Catalina āĻāĻĒāĻĄā§āĻ āĻāĻ°āĻžāĻ° āĻĒāĻ°ā§, āĻāĻ¨ā§āĻāĻžāĻ°āĻ¨ā§āĻā§āĻ° āĻāĻ¤āĻŋ āĻāĻŽā§ āĻā§āĻā§, āĻāĻŋāĻā§ āĻāĻŽāĻžāĻ° āĻ¨ā§āĻāĻāĻ¯āĻŧāĻžāĻ°ā§āĻāĻā§ āĻā§āĻŦ āĻŦā§āĻļāĻŋ āĻ˛ā§āĻĄ āĻāĻ°ā§āĻā§ āĻāĻŦāĻ āĻāĻŽāĻŋ āĻ¨ā§āĻāĻāĻ¯āĻŧāĻžāĻ°ā§āĻ āĻāĻžāĻ°ā§āĻ¯āĻāĻ˛āĻžāĻĒ āĻĻā§āĻāĻžāĻ° āĻ¸āĻŋāĻĻā§āĻ§āĻžāĻ¨ā§āĻ¤ āĻ¨āĻŋāĻ¯āĻŧā§āĻāĻŋāĨ¤
āĻāĻ¯āĻŧā§āĻ āĻāĻ¨ā§āĻāĻžāĻ° āĻāĻ¨ā§āĻ¯ tcpdump āĻāĻžāĻ˛āĻžāĻ¨:
sudo tcpdump -k NP > ~/log
āĻāĻŦāĻ āĻĒā§āĻ°āĻĨāĻŽ āĻāĻŋāĻ¨āĻŋāĻ¸ āĻ¯āĻž āĻāĻŽāĻžāĻ° āĻ¨āĻāĻ° āĻā§āĻĄāĻŧā§āĻā§:
16:43:42.919443 () ARP, Request who-has 192.168.1.51 tell 192.168.1.1, length 28
16:43:42.927716 () ARP, Request who-has 192.168.1.52 tell 192.168.1.1, length 28
16:43:42.934112 () ARP, Request who-has 192.168.1.53 tell 192.168.1.1, length 28
16:43:42.942328 () ARP, Request who-has 192.168.1.54 tell 192.168.1.1, length 28
16:43:43.021971 () ARP, Request who-has 192.168.1.55 tell 192.168.1.1, length 28
āĻā§āĻ¨ āĻ¤āĻžāĻ° āĻāĻŽāĻžāĻ° āĻĒā§āĻ°ā§ āĻ¸ā§āĻĨāĻžāĻ¨ā§āĻ¯āĻŧ āĻ¨ā§āĻāĻāĻ¯āĻŧāĻžāĻ°ā§āĻā§āĻ° āĻĒā§āĻ°āĻ¯āĻŧā§āĻāĻ¨? āĻāĻāĻŋ āĻĒā§āĻ°āĻ¤āĻŋ āĻŽāĻŋāĻ¨āĻŋāĻā§ āĻ āĻŦāĻŋāĻ°āĻžāĻŽāĻāĻžāĻŦā§ āĻ¸ā§āĻā§āĻ¯āĻžāĻ¨ āĻāĻ°ā§ 192.168.1./255, āĻ āĻŋāĻ āĻāĻā§, āĻ§āĻ°āĻž āĻ¯āĻžāĻ āĻāĻāĻŋ āĻāĻāĻāĻŋ āĻ¨ā§āĻāĻāĻ¯āĻŧāĻžāĻ°ā§āĻ āĻŦā§āĻ°āĻžāĻāĻāĻžāĻ° āĻĒāĻ°āĻŋāĻˇā§āĻŦāĻžā§ˇ
(shadowserver.org) āĻāĻāĻāĻŋ āĻ āĻ˛āĻžāĻāĻāĻ¨āĻ āĻ¨āĻŋāĻ°āĻžāĻĒāĻ¤ā§āĻ¤āĻž āĻ¸āĻāĻ¸ā§āĻĨāĻž
16:43:33.518282 () IP scan-05l.shadowserver.org.33567 > 192.168.1.150.rsync: Flags [S], seq 1527048226, win 65535, options [mss 536], length 0
āĻāĻ°ā§āĻāĻāĻŋ āĻ¸ā§āĻ¨āĻŋāĻ (scanner-12.ch1.censys-scanner.com -> censys.io):
16:44:16.254073 () IP scanner-12.ch1.censys-scanner.com.62651 > 192.168.1.150.8843: Flags [S], seq 1454862354, win 1024, options [mss 1460], length 0
āĻ āĻŋāĻ āĻāĻā§, āĻ āĻŋāĻ āĻāĻā§, āĻāĻāĻž āĻŦāĻŋāĻļā§āĻˇ āĻāĻŋāĻā§ āĻŦāĻ˛ā§ āĻŽāĻ¨ā§ āĻšāĻā§āĻā§ āĻ¨āĻž: āĻŦāĻŋāĻļā§āĻ˛ā§āĻˇāĻŖ, āĻ¸ā§āĻĨāĻžāĻ¨ā§āĻ¯āĻŧ āĻ¨ā§āĻāĻāĻ¯āĻŧāĻžāĻ°ā§āĻ āĻ¸ā§āĻā§āĻ¯āĻžāĻ¨ āĻāĻ°āĻž, āĻāĻžāĻ˛, āĻ¸ā§āĻŦāĻžāĻāĻžāĻŦāĻŋāĻ āĻāĻŋāĻ¨āĻŋāĻ¸, āĻāĻŋāĻ¨ā§āĻ¤ā§ āĻ¤āĻžāĻ°āĻĒāĻ° āĻāĻāĻŋ āĻāĻŋ:
16:15:56.603292 () IP 45.129.33.152.51777 > 192.168.1.150.jpegmpeg: Flags [S], seq 2349838714, win 1024, options [mss 536], length 0
āĻāĻĒāĻ¨āĻŋ āĻ¯āĻĻāĻŋ āĻāĻ āĻāĻāĻĒāĻŋ āĻ āĻŋāĻāĻžāĻ¨āĻžāĻ¯āĻŧ āĻ¯āĻžāĻ¨
āĻĒāĻžāĻ ā§āĻ¯ āĻĢāĻžāĻāĻ˛āĻā§āĻ˛āĻŋāĻ¤ā§ āĻĒā§āĻ°ā§āĻ āĻ¸āĻš āĻ˛āĻā§āĻˇ āĻ˛āĻā§āĻˇ āĻāĻāĻĒāĻŋ āĻ āĻŋāĻāĻžāĻ¨āĻž āĻĨāĻžāĻā§āĨ¤
āĻā§āĻŽā§āĻĒ āĻĢāĻžāĻāĻ˛ā§āĻ° āĻŦāĻŋāĻˇāĻ¯āĻŧāĻŦāĻ¸ā§āĻ¤ā§:
[?1h=[?25l[H[J[mtop - 21:17:26 up 31 days, 6:44, 1 use[m[39;49m[m[39;49m[K
Tasks:[m[39;49m[1m 144 [m[39;49mtotal,[m[39;49m[1m 1 [m[39;49mrunning,[m[39;49m[1m 143 [m[39;49msleep[m[39;49m[m[39;49m[K
%Cpu(s):[m[39;49m[1m 0.8 [m[39;49mus,[m[39;49m[1m 0.0 [m[39;49msy,[m[39;49m[1m 0.0 [m[39;49mni,[m[39;49m[1m 92.0[m[39;49m[m[39;49m[K
KiB Mem :[m[39;49m[1m 32681700 [m[39;49mtotal,[m[39;49m[1m 18410244 [m[39;49mfree,[m[39;49m[m[39;49m[K
KiB Swap:[m[39;49m[1m 16449532 [m[39;49mtotal,[m[39;49m[1m 16449288 [m[39;49mfree,[m[39;49m[m[39;49m[K
[K
[7m PID USER PR NI VIRT RES [m[39;49m[K
[m 1 root 20 0 191072 3924 [m[39;49m[K
[m 2 root 20 0 0 0 [m[39;49m[K
[m 3 root 20 0 0 0 [m[39;49m[K
[m 5 root 0 -20 0 0 [m[39;49m[K
[m 7 root rt 0 0 0 [m[39;49m[K
[m 8 root 20 0 0 0 [m[39;49m[K
[m 9 root 20 0 0 0 [m[39;49m[K
[m 10 root rt 0 0 0 [m[39;49m[K
[m 11 root rt 0 0 0 [m[39;49m[K
[m 12 root rt 0 0 0 [m[39;49m[K
[m 13 root 20 0 0 0 [m[39;49m[K
[m 15 root 0 -20 0 0 [m[39;49m[K
[m 16 root rt 0 0 0 [m[39;49m[K[H[mtop - 21:17:29 up 31 days, 6:44, 1 use[m[39;49m[m[39;49m[K
%Cpu(s):[m[39;49m[1m 0.0 [m[39;49mus,[m[39;49m[1m 0.0 [m[39;49msy,[m[39;49m[1m 0.0 [m[39;49mni,[m[39;49m[1m100.0[m[39;49m[m[39;49m[K
KiB Mem :[m[39;49m[1m 32681700 [m[39;49mtotal,[m[39;49m[1m 18409876 [m[39;49mfree,[m[39;49m[m[39;49m[K
[K
āĻāĻŦāĻ āĻ āĻŦāĻļā§āĻˇā§, āĻāĻāĻā§āĻā§āĻ āĻ āĻāĻžāĻ¨āĻž āĻ āĻ¨ā§āĻ°ā§āĻ§:
16:16:07.022910 () IP 059148253194.ctinets.com.58703 > 192.168.1.150.4244: Flags [S], seq 2829545743, win 1024, options [mss 536], length 0
16:15:57.133836 () IP 45.129.33.2.55914 > 192.168.1.150.39686: Flags [S], seq 700814637, win 1024, options [mss 536], length 0
16:15:56.603292 () IP 45.129.33.152.51777 > 192.168.1.150.jpegmpeg: Flags [S], seq 2349838714, win 1024, options [mss 536], length 0
16:16:15.083755 () IP 45.129.33.154.55846 > 192.168.1.150.7063: Flags [S], seq 4079154719, win 1024, options [mss 536], length 0
16:15:43.251305 () IP 192.168.1.150.60314 > one.one.one.one.domain: 3798+ PTR? 237.171.154.149.in-addr.arpa. (46)
16:16:24.386628 () IP 45.141.84.30.50763 > 192.168.1.150.12158: Flags [S], seq 572523718, win 1024, options [mss 536], length 0
16:16:44.817035 () IP 92.63.197.66.58219 > 192.168.1.150.15077: Flags [S], seq 4012437618, win 1024, options [mss 536], length 0
16:15:43.172042 () IP 45.129.33.46.51641 > 192.168.1.150.bnetgame: Flags [S], seq 362771723, win 1024, options [mss 536], length 0
16:17:02.120063 () IP 45.129.33.23.42275 > 192.168.1.150.11556: Flags [S], seq 3354007029, win 1024, options [mss 536], length 0
16:16:00.589816 () IP 45.129.33.3.56005 > 192.168.1.150.40688: Flags [S], seq 2710391040, win 1024, options [mss 536], length 0
āĻ¯āĻĻāĻŋ āĻāĻŽāĻŋ āĻšā§āĻ¸ā§āĻ āĻĢāĻžāĻāĻ˛ā§ āĻāĻ āĻĄā§āĻŽā§āĻāĻ¨ āĻāĻŦāĻ āĻāĻāĻĒāĻŋ āĻ āĻŋāĻāĻžāĻ¨āĻžāĻā§āĻ˛āĻŋāĻā§ āĻŦā§āĻ˛āĻ āĻāĻ°āĻŋ, āĻ¤āĻžāĻšāĻ˛ā§ āĻĒāĻ°āĻŦāĻ°ā§āĻ¤ā§ āĻĄāĻžāĻŽā§āĻĒā§ āĻāĻāĻ āĻāĻāĻĒāĻŋ āĻ¸āĻžāĻŦāĻ¨ā§āĻ āĻĨāĻžāĻāĻŦā§, āĻ¤āĻŦā§ āĻŦāĻŋāĻāĻŋāĻ¨ā§āĻ¨ āĻĒā§āĻ°āĻžāĻ¨ā§āĻ¤ā§āĻ° āĻ āĻŋāĻāĻžāĻ¨āĻž āĻ¸āĻš, āĻāĻŦāĻ āĻĄā§āĻŽā§āĻ¨āĻā§āĻ˛āĻŋ āĻ¸āĻžāĻŦāĻĄā§āĻŽā§āĻ¨ āĻĒāĻ°āĻŋāĻŦāĻ°ā§āĻ¤āĻ¨ āĻāĻ°ā§āĨ¤
āĻŽā§āĻ¯āĻžāĻ āĻšā§āĻ¸ā§āĻ *.example.com āĻĢāĻžāĻāĻ˛ā§ āĻŽāĻžāĻ¸ā§āĻ āĻŦā§āĻā§ āĻ¨āĻž
āĻā§āĻāĻžāĻŦā§ āĻĒā§āĻ¯āĻžāĻā§āĻāĻā§āĻ˛āĻŋ āĻĒā§āĻ°ā§āĻ°āĻŖ āĻāĻ°āĻž āĻšāĻā§āĻā§ āĻāĻŦāĻ āĻā§ āĻĒā§āĻ°āĻā§āĻ°āĻŋāĻ¯āĻŧāĻž āĻŦāĻž āĻĄā§āĻŽāĻ¨āĻā§āĻ˛āĻŋ āĻāĻ āĻ¸āĻāĻ¯ā§āĻāĻā§āĻ˛āĻŋ āĻāĻāĻžāĻā§āĻā§ āĻ¤āĻž āĻāĻŽāĻŋ āĻāĻāĻ¨āĻ āĻā§āĻāĻā§ āĻĒāĻžāĻāĻ¨āĻŋ (āĻāĻŽāĻžāĻ° āĻŦā§āĻļ āĻāĻ¯āĻŧā§āĻ āĻĻāĻŋāĻ¨ āĻ§āĻ°ā§ āĻĒā§āĻ¸ā§āĻ¤ āĻāĻā§), āĻ¤āĻŦā§ āĻāĻ¤āĻŋāĻŽāĻ§ā§āĻ¯ā§ āĻŽāĻāĻž!
āĻāĻ¤ā§āĻ¸: www.habr.com