Guest User

Untitled

a guest
Jul 19th, 2018
85
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 14.95 KB | None | 0 0
  1. Last login: Sat Mar 31 12:34:05 2012 from 178.122.5.232
  2. root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  3. root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 443 -j DROP
  4. root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  5. root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  6. root@90338:~# ^C
  7. root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  8. root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  9. root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  10. root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  11. root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  12. root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 443 -j DROP
  13. root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 5666 -j DROP
  14. root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 7443 -j DROP
  15. root@90338:~# iptables
  16. iptables v1.4.4: no command specified
  17. Try `iptables -h' or 'iptables --help' for more information.
  18. root@90338:~# iptables -t filter -A INPUT -i eth1 -p tcp --dport 80 -j DROP
  19. root@90338:~# net.ipv4.conf.all.rp_filter = 1
  20. -bash: net.ipv4.conf.all.rp_filter: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  21. root@90338:~# kernel.sysrq = 1
  22. -bash: kernel.sysrq: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  23. root@90338:~# net.ipv4.conf.default.send_redirects = 1
  24. -bash: net.ipv4.conf.default.send_redirects: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  25. root@90338:~#
  26. root@90338:~# net.ipv4.conf.all.send_redirects = 0
  27. -bash: net.ipv4.conf.all.send_redirects: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  28. root@90338:~# net.ipv4.ip_forward = 1
  29. -bash: net.ipv4.ip_forward: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  30. root@90338:~# net.ipv4.ip_dynaddr = 1
  31. -bash: net.ipv4.ip_dynaddr: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  32. root@90338:~# net.ipv4.ip_dynaddr = 1
  33. -bash: net.ipv4.ip_dynaddr: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  34. root@90338:~# kernel.msgmnb = 65536
  35. -bash: kernel.msgmnb: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  36. root@90338:~# kernel.msgmax = 65536
  37. -bash: kernel.msgmax: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  38. root@90338:~# kernel.shmmax = 4294967295
  39. -bash: kernel.shmmax: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  40. root@90338:~# kernel.shmall = 268435456
  41. -bash: kernel.shmall: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  42. root@90338:~# net.ipv4.tcp_keepalive_time = 15
  43. -bash: net.ipv4.tcp_keepalive_time: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  44. root@90338:~# net.ipv4.tcp_keepalive_intvl = 10
  45. -bash: net.ipv4.tcp_keepalive_intvl: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  46. root@90338:~# net.ipv4.tcp_keepalive_probes = 5
  47. -bash: net.ipv4.tcp_keepalive_probes: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  48. root@90338:~# net.ipv4.tcp_fin_timeout = 30
  49. -bash: net.ipv4.tcp_fin_timeout: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  50. root@90338:~# net.ipv4.tcp_window_scaling = 0
  51. -bash: net.ipv4.tcp_window_scaling: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  52. root@90338:~# net.ipv4.tcp_sack = 0
  53. -bash: net.ipv4.tcp_sack: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  54. root@90338:~# net.ipv4.tcp_timestamps = 0
  55. -bash: net.ipv4.tcp_timestamps: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  56. root@90338:~# net.ipv4.netfilter.ip_conntrack_max = 224000
  57. -bash: net.ipv4.netfilter.ip_conntrack_max: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  58. root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_close = 30
  59. -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_close: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  60. root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_time_wait = 30
  61. -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_time_wait: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  62. root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_last_ack = 120
  63. -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_last_ack: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  64. root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_close_wait = 30
  65. -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_close_wait: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  66. root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_fin_wait = 60
  67. -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_fin_wait: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  68. root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_established = 190
  69. -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_established: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  70. root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_recv = 30
  71. -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_recv: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  72. root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_sent = 30
  73. -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_sent: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  74. root@90338:~# iptables -I INPUT 1 -p tcp -m tcp --dport 3724 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 15 --connlimit-mask 32 -j DROP
  75. iptables: No chain/target/match by that name.
  76. root@90338:~# iptables -I INPUT 1 -p tcp -m tcp --dport 3724 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 15 --connlimit-mask 32 -j ^C
  77. root@90338:~# iptables -I INPUT 1 -p tcp -m tcp --dport 3724 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 15 --connlimit-mask 32 -j REJECT
  78. iptables: No chain/target/match by that name.
  79. root@90338:~# Last login: Sat Mar 31 12:34:05 2012 from 178.122.5.232
  80. -bash: Last: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  81. root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  82. -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  83. root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 443 -j DROP
  84. -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  85. root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  86. root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  87. -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  88. root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  89. -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  90. root@90338:~# root@90338:~# ^C
  91. -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  92. root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  93. -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  94. root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  95. -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  96. root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  97. root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 443 -j DROP
  98. -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  99. root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  100. -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  101. root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 80 -j DROP
  102. root@90338:~# iptables
  103. iptables v1.4.4: no command specified
  104. -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  105. root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 443 -j DROP
  106. -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  107. root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 5666 -j DROP
  108. root@90338:~# net.ipv4.conf.all.rp_filter = 1
  109. -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  110. root@90338:~# root@90338:~# iptables -t filter -A INPUT -i eth0 -p tcp --dport 7443 -j DROP
  111. -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  112. root@90338:~# root@90338:~# iptables
  113. root@90338:~# kernel.sysrq = 1
  114. -bash: kernel.sysrq: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  115. -bash: root@90338:~#: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  116. root@90338:~# iptables v1.4.4: no command specified
  117. Bad argument `v1.4.4:'
  118. Try `iptables -h' or 'iptables --help' for more information.
  119. root@90338:~# Try `iptables -h' or 'iptables --help' for more information.
  120. > root@90338:~# iptables -t filter -A INPUT -i eth1 -p tcp --dport 80 -j DROP
  121. > root@90338:~# net.ipv4.conf.all.rp_filter = 1
  122. > -bash: net.ipv4.conf.all.rp_filter: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  123. > root@90338:~# kernel.sysrq = 1
  124. > -bash: kernel.sysrq: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  125. > root@90338:~# net.ipv4.conf.default.send_redirects = 1
  126. > -bash: net.ipv4.conf.default.send_redirects: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  127. > root@90338:~#
  128. > root@90338:~# net.ipv4.conf.all.send_redirects = 0
  129. > -bash: net.ipv4.conf.all.send_redirects: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  130. > root@90338:~# net.ipv4.ip_forward = 1
  131. > -bash: net.ipv4.ip_forward: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  132. > root@90338:~# net.ipv4.ip_dynaddr = 1
  133. > -bash: net.ipv4.ip_dynaddr: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  134. > root@90338:~# net.ipv4.ip_dynaddr = 1
  135. > -bash: net.ipv4.ip_dynaddr: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  136. > root@90338:~# kernel.msgmnb = 65536
  137. > -bash: kernel.msgmnb: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  138. > root@90338:~# kernel.msgmax = 65536
  139. > -bash: kernel.msgmax: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  140. > root@90338:~# kernel.shmmax = 4294967295
  141. > -bash: kernel.shmmax: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  142. > root@90338:~# kernel.shmall = 268435456
  143. > -bash: kernel.shmall: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  144. > root@90338:~# net.ipv4.tcp_keepalive_time = 15
  145. > -bash: net.ipv4.tcp_keepalive_time: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  146. > root@90338:~# net.ipv4.tcp_keepalive_intvl = 10
  147. > -bash: net.ipv4.tcp_keepalive_intvl: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  148. root@90338:~# net.ipv4.tcp_sack = 0
  149. > root@90338:~# net.ipv4.tcp_keepalive_probes = 5
  150. > -bash: net.ipv4.tcp_keepalive_probes: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  151. > root@90338:~# net.ipv4.tcp_fin_timeout = 30
  152. > -bash: net.ipv4.tcp_fin_timeout: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  153. > root@90338:~# net.ipv4.tcp_window_scaling = 0
  154. > -bash: net.ipv4.tcp_window_scaling: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  155. -bash: net.ipv4.tcp_timestamps: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  156. > root@90338:~# net.ipv4.tcp_sack = 0
  157. > -bash: net.ipv4.tcp_sack: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  158. > root@90338:~# net.ipv4.tcp_timestamps = 0
  159. > -bash: net.ipv4.tcp_timestamps: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  160. > root@90338:~# net.ipv4.netfilter.ip_conntrack_max = 224000
  161. > -bash: net.ipv4.netfilter.ip_conntrack_max: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  162. > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_close = 30
  163. > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_close: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  164. > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_time_wait = 30
  165. > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_time_wait: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  166. > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_last_ack = 120
  167. > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_last_ack: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  168. > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_close_wait = 30
  169. > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_close_wait: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  170. > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_fin_wait = 60
  171. > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_fin_wait: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  172. > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_established = 190
  173. > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_established: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  174. > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_recv = 30
  175. > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_recv: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  176. > root@90338:~# net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_sent = 30
  177. > -bash: net.ipv4.netfilter.ip_conntrack_tcp_timeout_syn_sent: п╨п╬п╪п╟пҐпЄп╟ пҐп╣ пҐп╟п╧пЄп╣пҐп╟
  178. > root@90338:~# iptables -I INPUT 1 -p tcp -m tcp --dport 3724 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 15 --connlimit-mask 32 -j DROP
  179. > iptables: No chain/target/match by that name.
  180. > root@90338:~# iptables -I INPUT 1 -p tcp -m tcp --dport 3724 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 15 --connlimit-mask 32 -j ^C
  181. > root@90338:~# iptables -I INPUT 1 -p tcp -m tcp --dport 3724 --tcp-flags FIN,SYN,RST,ACK SYN -m connlimit --connlimit-above 15 --connlimit-mask 32 -j REJECT
  182. > iptables: No chain/target/match by that name.
  183. > root@90338:~#
Add Comment
Please, Sign In to add comment