Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Last login: Sat Mar 31 12:34:05 2012 from 178.122.5.232
- root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 443 -j DROP
- root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- root@90338:~# ^C
- root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 443 -j DROP
- root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 5666 -j DROP
- root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 7443 -j DROP
- root@90338:~# iptables
- iptables v1.4.4: no command specified
- Try `iptables -h' or 'iptables --help' for more information.
- root@90338:~# iptables -t filter -A INPUT -i eth1 -p tcp --dport 80 -j DROP
- root@90338:~# net.ipv4.conf.all.rp_filter = 1
- -bash: net.ipv4.conf.all.rp_filter: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# kernel.sysrq = 1
- -bash: kernel.sysrq: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.conf.default.send_redirects = 1
- -bash: net.ipv4.conf.default.send_redirects: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~#
- root@90338:~# net.ipv4.conf.all.send_redirects = 0
- -bash: net.ipv4.conf.all.send_redirects: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.ip_forward = 1
- -bash: net.ipv4.ip_forward: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.ip_dynaddr = 1
- -bash: net.ipv4.ip_dynaddr: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.ip_dynaddr = 1
- -bash: net.ipv4.ip_dynaddr: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# kernel.msgmnb = 65536
- -bash: kernel.msgmnb: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# kernel.msgmax = 65536
- -bash: kernel.msgmax: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# kernel.shmmax = 4294967295
- -bash: kernel.shmmax: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# kernel.shmall = 268435456
- -bash: kernel.shmall: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.tcp_keepalive_time = 15
- -bash: net.ipv4.tcp_keepalive_time: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.tcp_keepalive_intvl = 10
- -bash: net.ipv4.tcp_keepalive_intvl: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.tcp_keepalive_probes = 5
- -bash: net.ipv4.tcp_keepalive_probes: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.tcp_fin_timeout = 30
- -bash: net.ipv4.tcp_fin_timeout: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.tcp_window_scaling = 0
- -bash: net.ipv4.tcp_window_scaling: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.tcp_sack = 0
- -bash: net.ipv4.tcp_sack: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.tcp_timestamps = 0
- -bash: net.ipv4.tcp_timestamps: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.netfilter.ip_conntrack_max = 224000
- -bash: net.ipv4.netfilter.ip_conntrack_max: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_close = 30
- -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_close: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_time_wait = 30
- -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_time_wait: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_last_ack = 120
- -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_last_ack: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_close_wait = 30
- -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_close_wait: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_fin_wait = 60
- -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_fin_wait: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_established = 190
- -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_established: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_recv = 30
- -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_recv: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_sent = 30
- -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_sent: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# iptables -I INPUT 1 -p tcp -m tcp --dport 3724 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 15 --connlimit-mask 32 -j DROP
- iptables: No chain/target/match by that name.
- root@90338:~# iptables -I INPUT 1 -p tcp -m tcp --dport 3724 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 15 --connlimit-mask 32 -j ^C
- root@90338:~# iptables -I INPUT 1 -p tcp -m tcp --dport 3724 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 15 --connlimit-mask 32 -j REJECT
- iptables: No chain/target/match by that name.
- root@90338:~# Last login: Sat Mar 31 12:34:05 2012 from 178.122.5.232
- -bash: Last: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 443 -j DROP
- -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# root@90338:~# ^C
- -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 443 -j DROP
- -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
- root@90338:~# iptables
- iptables v1.4.4: no command specified
- -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 443 -j DROP
- -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 5666 -j DROP
- root@90338:~# net.ipv4.conf.all.rp_filter = 1
- -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 7443 -j DROP
- -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# root@90338:~# iptables
- root@90338:~# kernel.sysrq = 1
- -bash: kernel.sysrq: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# iptables v1.4.4: no command specified
- Bad argument `v1.4.4:'
- Try `iptables -h' or 'iptables --help' for more information.
- root@90338:~# Try `iptables -h' or 'iptables --help' for more information.
- > root@90338:~# iptables -t filter -A INPUT -i eth1 -p tcp --dport 80 -j DROP
- > root@90338:~# net.ipv4.conf.all.rp_filter = 1
- > -bash: net.ipv4.conf.all.rp_filter: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# kernel.sysrq = 1
- > -bash: kernel.sysrq: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.conf.default.send_redirects = 1
- > -bash: net.ipv4.conf.default.send_redirects: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~#
- > root@90338:~# net.ipv4.conf.all.send_redirects = 0
- > -bash: net.ipv4.conf.all.send_redirects: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.ip_forward = 1
- > -bash: net.ipv4.ip_forward: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.ip_dynaddr = 1
- > -bash: net.ipv4.ip_dynaddr: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.ip_dynaddr = 1
- > -bash: net.ipv4.ip_dynaddr: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# kernel.msgmnb = 65536
- > -bash: kernel.msgmnb: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# kernel.msgmax = 65536
- > -bash: kernel.msgmax: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# kernel.shmmax = 4294967295
- > -bash: kernel.shmmax: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# kernel.shmall = 268435456
- > -bash: kernel.shmall: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.tcp_keepalive_time = 15
- > -bash: net.ipv4.tcp_keepalive_time: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.tcp_keepalive_intvl = 10
- > -bash: net.ipv4.tcp_keepalive_intvl: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- root@90338:~# net.ipv4.tcp_sack = 0
- > root@90338:~# net.ipv4.tcp_keepalive_probes = 5
- > -bash: net.ipv4.tcp_keepalive_probes: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.tcp_fin_timeout = 30
- > -bash: net.ipv4.tcp_fin_timeout: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.tcp_window_scaling = 0
- > -bash: net.ipv4.tcp_window_scaling: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- -bash: net.ipv4.tcp_timestamps: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.tcp_sack = 0
- > -bash: net.ipv4.tcp_sack: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.tcp_timestamps = 0
- > -bash: net.ipv4.tcp_timestamps: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.netfilter.ip_conntrack_max = 224000
- > -bash: net.ipv4.netfilter.ip_conntrack_max: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_close = 30
- > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_close: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_time_wait = 30
- > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_time_wait: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_last_ack = 120
- > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_last_ack: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_close_wait = 30
- > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_close_wait: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_fin_wait = 60
- > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_fin_wait: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_established = 190
- > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_established: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_recv = 30
- > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_recv: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_sent = 30
- > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_sent: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
- > root@90338:~# iptables -I INPUT 1 -p tcp -m tcp --dport 3724 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 15 --connlimit-mask 32 -j DROP
- > iptables: No chain/target/match by that name.
- > root@90338:~# iptables -I INPUT 1 -p tcp -m tcp --dport 3724 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 15 --connlimit-mask 32 -j ^C
- > root@90338:~# iptables -I INPUT 1 -p tcp -m tcp --dport 3724 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 15 --connlimit-mask 32 -j REJECT
- > iptables: No chain/target/match by that name.
- > root@90338:~#
Add Comment
Please, Sign In to add comment