āĻ†āĻŽāĻŋ āĻ†āĻŽāĻžāĻ° āĻŸā§āĻ°ā§āĻ¯āĻžāĻĢāĻŋāĻ•ā§‡āĻ° āĻĻāĻŋāĻ•ā§‡ āĻ¤āĻžāĻ•āĻžāĻ˛āĻžāĻŽ: āĻ¤āĻŋāĻ¨āĻŋ āĻ†āĻŽāĻžāĻ° āĻ¸āĻŽā§āĻĒāĻ°ā§āĻ•ā§‡ āĻ¸āĻŦāĻ•āĻŋāĻ›ā§ āĻœāĻžāĻ¨āĻ¤ā§‡āĻ¨ (āĻŽā§āĻ¯āĻžāĻ• āĻ“āĻāĻ¸ āĻ•ā§āĻ¯āĻžāĻŸāĻžāĻ˛āĻŋāĻ¨āĻž)

āĻ†āĻŽāĻŋ āĻ†āĻŽāĻžāĻ° āĻŸā§āĻ°ā§āĻ¯āĻžāĻĢāĻŋāĻ•ā§‡āĻ° āĻĻāĻŋāĻ•ā§‡ āĻ¤āĻžāĻ•āĻžāĻ˛āĻžāĻŽ: āĻ¤āĻŋāĻ¨āĻŋ āĻ†āĻŽāĻžāĻ° āĻ¸āĻŽā§āĻĒāĻ°ā§āĻ•ā§‡ āĻ¸āĻŦāĻ•āĻŋāĻ›ā§ āĻœāĻžāĻ¨āĻ¤ā§‡āĻ¨ (āĻŽā§āĻ¯āĻžāĻ• āĻ“āĻāĻ¸ āĻ•ā§āĻ¯āĻžāĻŸāĻžāĻ˛āĻŋāĻ¨āĻž)āĻŽāĻžāĻĨāĻžāĻ¯āĻŧ āĻ•āĻžāĻ—āĻœā§‡āĻ° āĻŦā§āĻ¯āĻžāĻ— āĻ¨āĻŋāĻ¯āĻŧā§‡ āĻŽāĻžāĻ¨ā§āĻˇ

āĻ†āĻœ, 15.6 āĻĨā§‡āĻ•ā§‡ 15.7 āĻĒāĻ°ā§āĻ¯āĻ¨ā§āĻ¤ Catalina āĻ†āĻĒāĻĄā§‡āĻŸ āĻ•āĻ°āĻžāĻ° āĻĒāĻ°ā§‡, āĻ‡āĻ¨ā§āĻŸāĻžāĻ°āĻ¨ā§‡āĻŸā§‡āĻ° āĻ—āĻ¤āĻŋ āĻ•āĻŽā§‡ āĻ—ā§‡āĻ›ā§‡, āĻ•āĻŋāĻ›ā§ āĻ†āĻŽāĻžāĻ° āĻ¨ā§‡āĻŸāĻ“āĻ¯āĻŧāĻžāĻ°ā§āĻ•āĻ•ā§‡ āĻ–ā§āĻŦ āĻŦā§‡āĻļāĻŋ āĻ˛ā§‹āĻĄ āĻ•āĻ°ā§‡āĻ›ā§‡ āĻāĻŦāĻ‚ āĻ†āĻŽāĻŋ āĻ¨ā§‡āĻŸāĻ“āĻ¯āĻŧāĻžāĻ°ā§āĻ• āĻ•āĻžāĻ°ā§āĻ¯āĻ•āĻ˛āĻžāĻĒ āĻĻā§‡āĻ–āĻžāĻ° āĻ¸āĻŋāĻĻā§āĻ§āĻžāĻ¨ā§āĻ¤ āĻ¨āĻŋāĻ¯āĻŧā§‡āĻ›āĻŋāĨ¤

āĻ•āĻ¯āĻŧā§‡āĻ• āĻ˜āĻ¨ā§āĻŸāĻžāĻ° āĻœāĻ¨ā§āĻ¯ tcpdump āĻšāĻžāĻ˛āĻžāĻ¨:

sudo tcpdump -k NP > ~/log 

āĻāĻŦāĻ‚ āĻĒā§āĻ°āĻĨāĻŽ āĻœāĻŋāĻ¨āĻŋāĻ¸ āĻ¯āĻž āĻ†āĻŽāĻžāĻ° āĻ¨āĻœāĻ° āĻ•ā§‡āĻĄāĻŧā§‡āĻ›ā§‡:

16:43:42.919443 () ARP, Request who-has 192.168.1.51 tell 192.168.1.1, length 28
16:43:42.927716 () ARP, Request who-has 192.168.1.52 tell 192.168.1.1, length 28
16:43:42.934112 () ARP, Request who-has 192.168.1.53 tell 192.168.1.1, length 28
16:43:42.942328 () ARP, Request who-has 192.168.1.54 tell 192.168.1.1, length 28
16:43:43.021971 () ARP, Request who-has 192.168.1.55 tell 192.168.1.1, length 28

āĻ•ā§‡āĻ¨ āĻ¤āĻžāĻ° āĻ†āĻŽāĻžāĻ° āĻĒā§āĻ°ā§‹ āĻ¸ā§āĻĨāĻžāĻ¨ā§€āĻ¯āĻŧ āĻ¨ā§‡āĻŸāĻ“āĻ¯āĻŧāĻžāĻ°ā§āĻ•ā§‡āĻ° āĻĒā§āĻ°āĻ¯āĻŧā§‹āĻœāĻ¨? āĻāĻŸāĻŋ āĻĒā§āĻ°āĻ¤āĻŋ āĻŽāĻŋāĻ¨āĻŋāĻŸā§‡ āĻ…āĻŦāĻŋāĻ°āĻžāĻŽāĻ­āĻžāĻŦā§‡ āĻ¸ā§āĻ•ā§āĻ¯āĻžāĻ¨ āĻ•āĻ°ā§‡ 192.168.1./255, āĻ āĻŋāĻ• āĻ†āĻ›ā§‡, āĻ§āĻ°āĻž āĻ¯āĻžāĻ• āĻāĻŸāĻŋ āĻāĻ•āĻŸāĻŋ āĻ¨ā§‡āĻŸāĻ“āĻ¯āĻŧāĻžāĻ°ā§āĻ• āĻŦā§āĻ°āĻžāĻ‰āĻœāĻžāĻ° āĻĒāĻ°āĻŋāĻˇā§‡āĻŦāĻžā§ˇ

(shadowserver.org) āĻāĻ•āĻŸāĻŋ āĻ…āĻ˛āĻžāĻ­āĻœāĻ¨āĻ• āĻ¨āĻŋāĻ°āĻžāĻĒāĻ¤ā§āĻ¤āĻž āĻ¸āĻ‚āĻ¸ā§āĻĨāĻž

16:43:33.518282 () IP scan-05l.shadowserver.org.33567 > 192.168.1.150.rsync: Flags [S], seq 1527048226, win 65535, options [mss 536], length 0

āĻ†āĻ°ā§‡āĻ•āĻŸāĻŋ āĻ¸ā§āĻ¨āĻŋāĻš (scanner-12.ch1.censys-scanner.com -> censys.io):

16:44:16.254073 () IP scanner-12.ch1.censys-scanner.com.62651 > 192.168.1.150.8843: Flags [S], seq 1454862354, win 1024, options [mss 1460], length 0

āĻ āĻŋāĻ• āĻ†āĻ›ā§‡, āĻ āĻŋāĻ• āĻ†āĻ›ā§‡, āĻāĻŸāĻž āĻŦāĻŋāĻļā§‡āĻˇ āĻ•āĻŋāĻ›ā§ āĻŦāĻ˛ā§‡ āĻŽāĻ¨ā§‡ āĻšāĻšā§āĻ›ā§‡ āĻ¨āĻž: āĻŦāĻŋāĻļā§āĻ˛ā§‡āĻˇāĻŖ, āĻ¸ā§āĻĨāĻžāĻ¨ā§€āĻ¯āĻŧ āĻ¨ā§‡āĻŸāĻ“āĻ¯āĻŧāĻžāĻ°ā§āĻ• āĻ¸ā§āĻ•ā§āĻ¯āĻžāĻ¨ āĻ•āĻ°āĻž, āĻ­āĻžāĻ˛, āĻ¸ā§āĻŦāĻžāĻ­āĻžāĻŦāĻŋāĻ• āĻœāĻŋāĻ¨āĻŋāĻ¸, āĻ•āĻŋāĻ¨ā§āĻ¤ā§ āĻ¤āĻžāĻ°āĻĒāĻ° āĻāĻŸāĻŋ āĻ•āĻŋ:

16:15:56.603292 () IP 45.129.33.152.51777 > 192.168.1.150.jpegmpeg: Flags [S], seq 2349838714, win 1024, options [mss 536], length 0

āĻ†āĻĒāĻ¨āĻŋ āĻ¯āĻĻāĻŋ āĻāĻ‡ āĻ†āĻ‡āĻĒāĻŋ āĻ āĻŋāĻ•āĻžāĻ¨āĻžāĻ¯āĻŧ āĻ¯āĻžāĻ¨ http://45.129.33.152, āĻ†āĻĒāĻ¨āĻŋ āĻāĻŸāĻŋ āĻĻā§‡āĻ–āĻ¤ā§‡ āĻĒāĻžāĻ°ā§‡āĻ¨:

āĻ†āĻŽāĻŋ āĻ†āĻŽāĻžāĻ° āĻŸā§āĻ°ā§āĻ¯āĻžāĻĢāĻŋāĻ•ā§‡āĻ° āĻĻāĻŋāĻ•ā§‡ āĻ¤āĻžāĻ•āĻžāĻ˛āĻžāĻŽ: āĻ¤āĻŋāĻ¨āĻŋ āĻ†āĻŽāĻžāĻ° āĻ¸āĻŽā§āĻĒāĻ°ā§āĻ•ā§‡ āĻ¸āĻŦāĻ•āĻŋāĻ›ā§ āĻœāĻžāĻ¨āĻ¤ā§‡āĻ¨ (āĻŽā§āĻ¯āĻžāĻ• āĻ“āĻāĻ¸ āĻ•ā§āĻ¯āĻžāĻŸāĻžāĻ˛āĻŋāĻ¨āĻž)āĻĒāĻžāĻ ā§āĻ¯ āĻĢāĻžāĻ‡āĻ˛āĻ—ā§āĻ˛āĻŋāĻ¤ā§‡ āĻĒā§‹āĻ°ā§āĻŸ āĻ¸āĻš āĻ˛āĻ•ā§āĻˇ āĻ˛āĻ•ā§āĻˇ āĻ†āĻ‡āĻĒāĻŋ āĻ āĻŋāĻ•āĻžāĻ¨āĻž āĻĨāĻžāĻ•ā§‡āĨ¤

āĻŸā§‡āĻŽā§āĻĒ āĻĢāĻžāĻ‡āĻ˛ā§‡āĻ° āĻŦāĻŋāĻˇāĻ¯āĻŧāĻŦāĻ¸ā§āĻ¤ā§:

[?1h=[?25l[H[J[mtop - 21:17:26 up 31 days,  6:44,  1 use[m[39;49m[m[39;49m[K
Tasks:[m[39;49m[1m 144 [m[39;49mtotal,[m[39;49m[1m   1 [m[39;49mrunning,[m[39;49m[1m 143 [m[39;49msleep[m[39;49m[m[39;49m[K
%Cpu(s):[m[39;49m[1m  0.8 [m[39;49mus,[m[39;49m[1m  0.0 [m[39;49msy,[m[39;49m[1m  0.0 [m[39;49mni,[m[39;49m[1m 92.0[m[39;49m[m[39;49m[K
KiB Mem :[m[39;49m[1m 32681700 [m[39;49mtotal,[m[39;49m[1m 18410244 [m[39;49mfree,[m[39;49m[m[39;49m[K
KiB Swap:[m[39;49m[1m 16449532 [m[39;49mtotal,[m[39;49m[1m 16449288 [m[39;49mfree,[m[39;49m[m[39;49m[K
[K
[7m  PID USER      PR  NI    VIRT    RES [m[39;49m[K
[m    1 root      20   0  191072   3924 [m[39;49m[K
[m    2 root      20   0       0      0 [m[39;49m[K
[m    3 root      20   0       0      0 [m[39;49m[K
[m    5 root       0 -20       0      0 [m[39;49m[K
[m    7 root      rt   0       0      0 [m[39;49m[K
[m    8 root      20   0       0      0 [m[39;49m[K
[m    9 root      20   0       0      0 [m[39;49m[K
[m   10 root      rt   0       0      0 [m[39;49m[K
[m   11 root      rt   0       0      0 [m[39;49m[K
[m   12 root      rt   0       0      0 [m[39;49m[K
[m   13 root      20   0       0      0 [m[39;49m[K
[m   15 root       0 -20       0      0 [m[39;49m[K
[m   16 root      rt   0       0      0 [m[39;49m[K[H[mtop - 21:17:29 up 31 days,  6:44,  1 use[m[39;49m[m[39;49m[K

%Cpu(s):[m[39;49m[1m  0.0 [m[39;49mus,[m[39;49m[1m  0.0 [m[39;49msy,[m[39;49m[1m  0.0 [m[39;49mni,[m[39;49m[1m100.0[m[39;49m[m[39;49m[K
KiB Mem :[m[39;49m[1m 32681700 [m[39;49mtotal,[m[39;49m[1m 18409876 [m[39;49mfree,[m[39;49m[m[39;49m[K

[K

āĻāĻŦāĻ‚ āĻ…āĻŦāĻļā§‡āĻˇā§‡, āĻāĻ•āĻ—ā§āĻšā§āĻ› āĻ…āĻœāĻžāĻ¨āĻž āĻ…āĻ¨ā§āĻ°ā§‹āĻ§:

16:16:07.022910 () IP 059148253194.ctinets.com.58703 > 192.168.1.150.4244: Flags [S], seq 2829545743, win 1024, options [mss 536], length 0
16:15:57.133836 () IP 45.129.33.2.55914 > 192.168.1.150.39686: Flags [S], seq 700814637, win 1024, options [mss 536], length 0
16:15:56.603292 () IP 45.129.33.152.51777 > 192.168.1.150.jpegmpeg: Flags [S], seq 2349838714, win 1024, options [mss 536], length 0
16:16:15.083755 () IP 45.129.33.154.55846 > 192.168.1.150.7063: Flags [S], seq 4079154719, win 1024, options [mss 536], length 0
16:15:43.251305 () IP 192.168.1.150.60314 > one.one.one.one.domain: 3798+ PTR? 237.171.154.149.in-addr.arpa. (46)
16:16:24.386628 () IP 45.141.84.30.50763 > 192.168.1.150.12158: Flags [S], seq 572523718, win 1024, options [mss 536], length 0
16:16:44.817035 () IP 92.63.197.66.58219 > 192.168.1.150.15077: Flags [S], seq 4012437618, win 1024, options [mss 536], length 0
16:15:43.172042 () IP 45.129.33.46.51641 > 192.168.1.150.bnetgame: Flags [S], seq 362771723, win 1024, options [mss 536], length 0
16:17:02.120063 () IP 45.129.33.23.42275 > 192.168.1.150.11556: Flags [S], seq 3354007029, win 1024, options [mss 536], length 0
16:16:00.589816 () IP 45.129.33.3.56005 > 192.168.1.150.40688: Flags [S], seq 2710391040, win 1024, options [mss 536], length 0

āĻ¯āĻĻāĻŋ āĻ†āĻŽāĻŋ āĻšā§‹āĻ¸ā§āĻŸ āĻĢāĻžāĻ‡āĻ˛ā§‡ āĻāĻ‡ āĻĄā§‹āĻŽā§‡āĻ‡āĻ¨ āĻāĻŦāĻ‚ āĻ†āĻ‡āĻĒāĻŋ āĻ āĻŋāĻ•āĻžāĻ¨āĻžāĻ—ā§āĻ˛āĻŋāĻ•ā§‡ āĻŦā§āĻ˛āĻ• āĻ•āĻ°āĻŋ, āĻ¤āĻžāĻšāĻ˛ā§‡ āĻĒāĻ°āĻŦāĻ°ā§āĻ¤ā§€ āĻĄāĻžāĻŽā§āĻĒā§‡ āĻāĻ•āĻ‡ āĻ†āĻ‡āĻĒāĻŋ āĻ¸āĻžāĻŦāĻ¨ā§‡āĻŸ āĻĨāĻžāĻ•āĻŦā§‡, āĻ¤āĻŦā§‡ āĻŦāĻŋāĻ­āĻŋāĻ¨ā§āĻ¨ āĻĒā§āĻ°āĻžāĻ¨ā§āĻ¤ā§‡āĻ° āĻ āĻŋāĻ•āĻžāĻ¨āĻž āĻ¸āĻš, āĻāĻŦāĻ‚ āĻĄā§‹āĻŽā§‡āĻ¨āĻ—ā§āĻ˛āĻŋ āĻ¸āĻžāĻŦāĻĄā§‹āĻŽā§‡āĻ¨ āĻĒāĻ°āĻŋāĻŦāĻ°ā§āĻ¤āĻ¨ āĻ•āĻ°ā§‡āĨ¤

āĻŽā§āĻ¯āĻžāĻ• āĻšā§‹āĻ¸ā§āĻŸ *.example.com āĻĢāĻžāĻ‡āĻ˛ā§‡ āĻŽāĻžāĻ¸ā§āĻ• āĻŦā§‹āĻā§‡ āĻ¨āĻž

āĻ•ā§€āĻ­āĻžāĻŦā§‡ āĻĒā§āĻ¯āĻžāĻ•ā§‡āĻŸāĻ—ā§āĻ˛āĻŋ āĻĒā§āĻ°ā§‡āĻ°āĻŖ āĻ•āĻ°āĻž āĻšāĻšā§āĻ›ā§‡ āĻāĻŦāĻ‚ āĻ•ā§€ āĻĒā§āĻ°āĻ•ā§āĻ°āĻŋāĻ¯āĻŧāĻž āĻŦāĻž āĻĄā§‡āĻŽāĻ¨āĻ—ā§āĻ˛āĻŋ āĻāĻ‡ āĻ¸āĻ‚āĻ¯ā§‹āĻ—āĻ—ā§āĻ˛āĻŋ āĻ˜āĻŸāĻžāĻšā§āĻ›ā§‡ āĻ¤āĻž āĻ†āĻŽāĻŋ āĻāĻ–āĻ¨āĻ“ āĻ–ā§āĻāĻœā§‡ āĻĒāĻžāĻ‡āĻ¨āĻŋ (āĻ†āĻŽāĻžāĻ° āĻŦā§‡āĻļ āĻ•āĻ¯āĻŧā§‡āĻ• āĻĻāĻŋāĻ¨ āĻ§āĻ°ā§‡ āĻĒā§‹āĻ¸ā§āĻ¤ āĻ†āĻ›ā§‡), āĻ¤āĻŦā§‡ āĻ‡āĻ¤āĻŋāĻŽāĻ§ā§āĻ¯ā§‡ āĻŽāĻœāĻž!

āĻ‰āĻ¤ā§āĻ¸: www.habr.com