แžแŸ’แž‰แžปแŸ†แž”แžถแž“แž˜แžพแž›แž…แžšแžถแž…แžšแžŽแŸแžšแž”แžŸแŸ‹แžแŸ’แž‰แžปแŸ†แŸ– แžœแžถแžŠแžนแž„แž‚แŸ’แžšแž”แŸ‹แž™แŸ‰แžถแž„แžขแŸ†แž–แžธแžแŸ’แž‰แžปแŸ† (Mac OS Catalina)

แžแŸ’แž‰แžปแŸ†แž”แžถแž“แž˜แžพแž›แž…แžšแžถแž…แžšแžŽแŸแžšแž”แžŸแŸ‹แžแŸ’แž‰แžปแŸ†แŸ– แžœแžถแžŠแžนแž„แž‚แŸ’แžšแž”แŸ‹แž™แŸ‰แžถแž„แžขแŸ†แž–แžธแžแŸ’แž‰แžปแŸ† (Mac OS Catalina)แž”แžปแžšแžŸแžŠแŸ‚แž›แž˜แžถแž“แžแž„แŸ‹แž€แŸ’แžšแžŠแžถแžŸแž“แŸ…แž›แžพแž€แŸ’แž”แžถแž›แžšแž”แžŸแŸ‹แž‚แžถแžแŸ‹แŸ”

แžแŸ’แž„แŸƒแž“แŸแŸ‡ แž”แž“แŸ’แž‘แžถแž”แŸ‹แž–แžธแžขแžถแž”แŸ‹แžŠแŸแž Catalina แž–แžธ 15.6 แž‘แŸ… 15.7 แž›แŸ’แž”แžฟแž“แžขแŸŠแžธแž“แž’แžบแžŽแŸแžแž’แŸ’แž›แžถแž€แŸ‹แž…แžปแŸ‡ แžขแŸ’แžœแžธแž˜แžฝแž™แž€แŸ†แž–แžปแž„แž•แŸ’แž‘แžปแž€แž”แžŽแŸ’แžแžถแž‰แžšแž”แžŸแŸ‹แžแŸ’แž‰แžปแŸ†แž™แŸ‰แžถแž„แžแŸ’แž›แžถแŸ†แž„ แž แžพแž™แžแŸ’แž‰แžปแŸ†แž”แžถแž“แžŸแž˜แŸ’แžšแŸแž…แž…แžทแžแŸ’แžแž˜แžพแž›แžŸแž€แž˜แŸ’แž˜แž—แžถแž–แž”แžŽแŸ’แžแžถแž‰แŸ”

แžแŸ’แž‰แžปแŸ†แž”แžถแž“แžŠแŸ†แžŽแžพแžšแž€แžถแžš tcpdump แž–แžธแžšแž”แžธแž˜แŸ‰แŸ„แž„แŸ–

sudo tcpdump -k NP > ~/log 

แž แžพแž™แžšแžฟแž„แžŠแŸ†แž”แžผแž„แžŠแŸ‚แž›แž…แžถแž”แŸ‹แž—แŸ’แž“แŸ‚แž€แžแŸ’แž‰แžปแŸ†แŸ–

16:43:42.919443 () ARP, Request who-has 192.168.1.51 tell 192.168.1.1, length 28
16:43:42.927716 () ARP, Request who-has 192.168.1.52 tell 192.168.1.1, length 28
16:43:42.934112 () ARP, Request who-has 192.168.1.53 tell 192.168.1.1, length 28
16:43:42.942328 () ARP, Request who-has 192.168.1.54 tell 192.168.1.1, length 28
16:43:43.021971 () ARP, Request who-has 192.168.1.55 tell 192.168.1.1, length 28

แž แŸแžแžปแžขแŸ’แžœแžธแž”แžถแž“แž‡แžถแž‚แžถแžแŸ‹แžแŸ’แžšแžผแžœแž€แžถแžšแž”แžŽแŸ’แžแžถแž‰แž€แŸ’แž“แžปแž„แžŸแŸ’แžšแžปแž€แž‘แžถแŸ†แž„แž˜แžผแž›แžšแž”แžŸแŸ‹แžแŸ’แž‰แžปแŸ†? แžœแžถแžŸแŸ’แž€แŸ‚แž“แžœแžถแž˜แžทแž“แž…แŸแŸ‡แž…แž”แŸ‹แžšแžถแž›แŸ‹แž“แžถแž‘แžธ 192.168.1./255 แž˜แžทแž“แžขแžธแž‘แŸ แžแŸ„แŸ‡แž“แžทแž™แžถแž™แžแžถแž“แŸแŸ‡แž‚แžบแž‡แžถแžŸแŸแžœแžถแž€แž˜แŸ’แž˜แž€แž˜แŸ’แž˜แžœแžทแž’แžธแžšแžปแž€แžšแž€แžแžถแž˜แžขแŸŠแžธแž“แž’แžบแžŽแžทแžแŸ”

(shadowserver.org) - แžขแž„แŸ’แž‚แž€แžถแžšแžŸแž“แŸ’แžแžทแžŸแžปแžแž˜แžทแž“แžšแž€แž”แŸ’แžšแžถแž€แŸ‹แž…แŸ†แžŽแŸแž‰

16:43:33.518282 () IP scan-05l.shadowserver.org.33567 > 192.168.1.150.rsync: Flags [S], seq 1527048226, win 65535, options [mss 536], length 0

แžขแŸ’แž“แž€แž‚แŸ„แŸ‡แž˜แžฝแž™แž‘แŸ€แž (scanner-12.ch1.censys-scanner.com -> censys.io):

16:44:16.254073 () IP scanner-12.ch1.censys-scanner.com.62651 > 192.168.1.150.8843: Flags [S], seq 1454862354, win 1024, options [mss 1460], length 0

แž˜แžทแž“แžขแžธแž‘แŸ แž˜แžทแž“แžขแžธแž‘แŸ แžœแžถแž แžถแž€แŸ‹แž”แžธแžŠแžผแž…แž‡แžถแž‚แŸ’แž˜แžถแž“แžขแŸ’แžœแžธแž–แžทแžŸแŸแžŸแž‘แŸแŸ– แž€แžถแžšแžœแžทแž—แžถแž‚ แž€แžถแžšแžŸแŸ’แž€แŸแž“แž”แžŽแŸ’แžแžถแž‰แž˜แžผแž›แžŠแŸ’แž‹แžถแž“ แž‡แžถแž€แžถแžšแž”แŸ’แžšแžŸแžพแžšแžŽแžถแžŸแŸ‹ แž”แŸ‰แžปแž“แŸ’แžแŸ‚แž”แž“แŸ’แž‘แžถแž”แŸ‹แž˜แž€แž…แžปแŸ‡แž™แŸ‰แžถแž„แžŽแžถแž…แŸ†แž–แŸ„แŸ‡แž”แž‰แŸ’แž แžถแž“แŸแŸ‡แŸ–

16:15:56.603292 () IP 45.129.33.152.51777 > 192.168.1.150.jpegmpeg: Flags [S], seq 2349838714, win 1024, options [mss 536], length 0

แž”แŸ’แžšแžŸแžทแž“แž”แžพแžขแŸ’แž“แž€แž…แžผแž›แž‘แŸ…แž€แžถแž“แŸ‹แžขแžถแžŸแž™แžŠแŸ’แž‹แžถแž“ IP แž“แŸแŸ‡แŸ” http://45.129.33.152, แžขแŸ’แž“แž€โ€‹แžขแžถแž…โ€‹แž˜แžพแž›โ€‹แžƒแžพแž‰โ€‹แž“แŸแŸ‡โ€‹:

แžแŸ’แž‰แžปแŸ†แž”แžถแž“แž˜แžพแž›แž…แžšแžถแž…แžšแžŽแŸแžšแž”แžŸแŸ‹แžแŸ’แž‰แžปแŸ†แŸ– แžœแžถแžŠแžนแž„แž‚แŸ’แžšแž”แŸ‹แž™แŸ‰แžถแž„แžขแŸ†แž–แžธแžแŸ’แž‰แžปแŸ† (Mac OS Catalina)แžฏแž€แžŸแžถแžšแžขแžแŸ’แžแž”แž‘แž˜แžถแž“แžขแžถแžŸแž™แžŠแŸ’แž‹แžถแž“ IP แžšแžถแž”แŸ‹แž›แžถแž“แžŠแŸ‚แž›แž˜แžถแž“แž…แŸ’แžšแž€แŸ”

แž˜แžถแžแžทแž€แžถแž“แŸƒแžฏแž€แžŸแžถแžš temp:

[?1h=[?25l[H[J[mtop - 21:17:26 up 31 days,  6:44,  1 use[m[39;49m[m[39;49m[K
Tasks:[m[39;49m[1m 144 [m[39;49mtotal,[m[39;49m[1m   1 [m[39;49mrunning,[m[39;49m[1m 143 [m[39;49msleep[m[39;49m[m[39;49m[K
%Cpu(s):[m[39;49m[1m  0.8 [m[39;49mus,[m[39;49m[1m  0.0 [m[39;49msy,[m[39;49m[1m  0.0 [m[39;49mni,[m[39;49m[1m 92.0[m[39;49m[m[39;49m[K
KiB Mem :[m[39;49m[1m 32681700 [m[39;49mtotal,[m[39;49m[1m 18410244 [m[39;49mfree,[m[39;49m[m[39;49m[K
KiB Swap:[m[39;49m[1m 16449532 [m[39;49mtotal,[m[39;49m[1m 16449288 [m[39;49mfree,[m[39;49m[m[39;49m[K
[K
[7m  PID USER      PR  NI    VIRT    RES [m[39;49m[K
[m    1 root      20   0  191072   3924 [m[39;49m[K
[m    2 root      20   0       0      0 [m[39;49m[K
[m    3 root      20   0       0      0 [m[39;49m[K
[m    5 root       0 -20       0      0 [m[39;49m[K
[m    7 root      rt   0       0      0 [m[39;49m[K
[m    8 root      20   0       0      0 [m[39;49m[K
[m    9 root      20   0       0      0 [m[39;49m[K
[m   10 root      rt   0       0      0 [m[39;49m[K
[m   11 root      rt   0       0      0 [m[39;49m[K
[m   12 root      rt   0       0      0 [m[39;49m[K
[m   13 root      20   0       0      0 [m[39;49m[K
[m   15 root       0 -20       0      0 [m[39;49m[K
[m   16 root      rt   0       0      0 [m[39;49m[K[H[mtop - 21:17:29 up 31 days,  6:44,  1 use[m[39;49m[m[39;49m[K

%Cpu(s):[m[39;49m[1m  0.0 [m[39;49mus,[m[39;49m[1m  0.0 [m[39;49msy,[m[39;49m[1m  0.0 [m[39;49mni,[m[39;49m[1m100.0[m[39;49m[m[39;49m[K
KiB Mem :[m[39;49m[1m 32681700 [m[39;49mtotal,[m[39;49m[1m 18409876 [m[39;49mfree,[m[39;49m[m[39;49m[K

[K

แž แžพแž™แž…แžปแž„แž€แŸ’แžšแŸ„แž™ แžŸแŸ†แžŽแžฝแžšแžŠแŸ‚แž›แž˜แžทแž“แžŸแŸ’แž‚แžถแž›แŸ‹แž‡แžถแž…แŸ’แžšแžพแž“แŸ–

16:16:07.022910 () IP 059148253194.ctinets.com.58703 > 192.168.1.150.4244: Flags [S], seq 2829545743, win 1024, options [mss 536], length 0
16:15:57.133836 () IP 45.129.33.2.55914 > 192.168.1.150.39686: Flags [S], seq 700814637, win 1024, options [mss 536], length 0
16:15:56.603292 () IP 45.129.33.152.51777 > 192.168.1.150.jpegmpeg: Flags [S], seq 2349838714, win 1024, options [mss 536], length 0
16:16:15.083755 () IP 45.129.33.154.55846 > 192.168.1.150.7063: Flags [S], seq 4079154719, win 1024, options [mss 536], length 0
16:15:43.251305 () IP 192.168.1.150.60314 > one.one.one.one.domain: 3798+ PTR? 237.171.154.149.in-addr.arpa. (46)
16:16:24.386628 () IP 45.141.84.30.50763 > 192.168.1.150.12158: Flags [S], seq 572523718, win 1024, options [mss 536], length 0
16:16:44.817035 () IP 92.63.197.66.58219 > 192.168.1.150.15077: Flags [S], seq 4012437618, win 1024, options [mss 536], length 0
16:15:43.172042 () IP 45.129.33.46.51641 > 192.168.1.150.bnetgame: Flags [S], seq 362771723, win 1024, options [mss 536], length 0
16:17:02.120063 () IP 45.129.33.23.42275 > 192.168.1.150.11556: Flags [S], seq 3354007029, win 1024, options [mss 536], length 0
16:16:00.589816 () IP 45.129.33.3.56005 > 192.168.1.150.40688: Flags [S], seq 2710391040, win 1024, options [mss 536], length 0

แž”แŸ’แžšแžŸแžทแž“แž”แžพแžแŸ’แž‰แžปแŸ†แžšแžถแžšแžถแŸ†แž„แžŠแŸ‚แž“ แž“แžทแž„แžขแžถแžŸแž™แžŠแŸ’แž‹แžถแž“ IP แž‘แžถแŸ†แž„แž“แŸแŸ‡แž“แŸ…แž€แŸ’แž“แžปแž„แžฏแž€แžŸแžถแžšแž˜แŸ‰แžถแžŸแŸŠแžธแž“ แž“แŸ„แŸ‡แž“แŸ…แž€แŸ’แž“แžปแž„แž€แžถแžšแž”แŸ„แŸ‡แž…แŸ„แž›แž”แž“แŸ’แž‘แžถแž”แŸ‹แž“แžนแž„แž˜แžถแž“แž”แžŽแŸ’แžแžถแž‰แžšแž„ IP แžŠแžผแž…แž‚แŸ’แž“แžถ แž”แŸ‰แžปแž“แŸ’แžแŸ‚แž‡แžถแž˜แžฝแž™แž“แžนแž„แžขแžถแžŸแž™แžŠแŸ’แž‹แžถแž“แž…แžปแž„แž•แŸ’แžŸแŸแž„แž‚แŸ’แž“แžถ แž แžพแž™แžŠแŸ‚แž“แžšแž„แž“แŸƒแžŠแŸ‚แž“แž“แžนแž„แž•แŸ’แž›แžถแžŸแŸ‹แž”แŸ’แžแžผแžšแŸ”

Mac แž˜แžทแž“แž™แž›แŸ‹แž–แžธแžšแž”แžถแŸ†แž„แž“แŸ…แž€แŸ’แž“แžปแž„แžฏแž€แžŸแžถแžšแž˜แŸ‰แžถแžŸแŸŠแžธแž“ *.example.com

แžแŸ’แž‰แžปแŸ†โ€‹แž˜แžทแž“โ€‹แž”แžถแž“โ€‹แž‚แžทแžโ€‹แž–แžธโ€‹แžšแž”แŸ€แž”โ€‹แž˜แžพแž›โ€‹แž€แž‰แŸ’แž…แž”แŸ‹โ€‹แž–แŸแžแŸŒแž˜แžถแž“โ€‹แžŠแŸ‚แž›โ€‹แžแŸ’แžšแžผแžœโ€‹แž”แžถแž“โ€‹แž•แŸ’แž‘แŸแžšโ€‹ แž“แžทแž„โ€‹แžŠแŸ†แžŽแžพแžšแž€แžถแžšโ€‹แžฌโ€‹แžŠแŸแž˜แžทแž“โ€‹แžŠแŸ‚แž›โ€‹แž”แž„แŸ’แž€โ€‹แžฑแŸ’แž™โ€‹แž˜แžถแž“โ€‹แž€แžถแžšโ€‹แžแž—แŸ’แž‡แžถแž”แŸ‹โ€‹แž‘แžถแŸ†แž„โ€‹แž“แŸแŸ‡โ€‹แž‘แŸ (แžแŸ’แž‰แžปแŸ†โ€‹แž˜แžถแž“ Mac แž–แžธแžšโ€‹แž”แžธโ€‹แžแŸ’แž„แŸƒ) แž”แŸ‰แžปแž“แŸ’แžแŸ‚โ€‹แžœแžถโ€‹แžŸแž”แŸ’แž”แžถแž™โ€‹แž แžพแž™!

แž”แŸ’แžšแž—แž–: www.habr.com