INNO SANCTUM
Newbie | Редактировать | Профиль | Сообщение | Цитировать | Сообщить модератору Ruza Так и сделал. При включенном инспекторе протокола выдает [04/Jun/2008 11:06:28] FTP: Bounce attack attempt: client: 192.168.0.44, server: 77.120.103.197, command: PORT 77,120,103,197,198,116 Настораживает совпадение атрибутов команды PORT с ИП сервера... Клиент (Тотал Коммандер) сообщает, что "возможно запрещено файрволом". При отключенном инспекторе протокола клиент вываливает 500 illegal PORT, керио же молчит. Ну, как - молчит: Код: [04/Jun/2008 10:19:41] PERMIT "Alow FTP" packet to Krimar Local, proto:TCP, len:116, ip/port:77.120.103.197:21 -> 192.168.0.10:1343, flags: ACK PSH , seq:4095762155 ack:171685426, win:65535, tcplen:76 [04/Jun/2008 10:19:41] PERMIT "Alow FTP" packet from Krimar Local, proto:TCP, len:40, ip/port:192.168.0.10:1343 -> 77.120.103.197:21, flags: ACK , seq:171685426 ack:4095762231, win:65383, tcplen:0 [04/Jun/2008 10:19:41] PERMIT "Alow FTP" packet to TelNet, proto:TCP, len:40, ip/port:192.168.0.10:1343 -> 77.120.103.197:21, flags: ACK , seq:171685426 ack:4095762231, win:65383, tcplen:0 [04/Jun/2008 10:19:41] PERMIT "Alow FTP" packet from TelNet, proto:TCP, len:63, ip/port:77.120.103.197:21 -> 195.138.168.40:1343, flags: ACK PSH , seq:4095762231 ack:171685426, win:65535, tcplen:23 [04/Jun/2008 10:19:41] PERMIT "Alow FTP" packet to Krimar Local, proto:TCP, len:63, ip/port:77.120.103.197:21 -> 192.168.0.10:1343, flags: ACK PSH , seq:4095762231 ack:171685426, win:65535, tcplen:23 [04/Jun/2008 10:19:41] PERMIT "Alow FTP" packet from Krimar Local, proto:TCP, len:46, ip/port:192.168.0.10:1343 -> 77.120.103.197:21, flags: ACK PSH , seq:171685426 ack:4095762254, win:65360, tcplen:6 [04/Jun/2008 10:19:41] PERMIT "Alow FTP" packet to TelNet, proto:TCP, len:46, ip/port:192.168.0.10:1343 -> 77.120.103.197:21, flags: ACK PSH , seq:171685426 ack:4095762254, win:65360, tcplen:6 [04/Jun/2008 10:19:42] PERMIT "Alow FTP" packet from TelNet, proto:TCP, len:93, ip/port:77.120.103.197:21 -> 195.138.168.40:1343, flags: ACK PSH , seq:4095762254 ack:171685432, win:65535, tcplen:53 [04/Jun/2008 10:19:42] PERMIT "Alow FTP" packet to Krimar Local, proto:TCP, len:93, ip/port:77.120.103.197:21 -> 192.168.0.10:1343, flags: ACK PSH , seq:4095762254 ack:171685432, win:65535, tcplen:53 [04/Jun/2008 10:19:42] PERMIT "Alow FTP" packet from Krimar Local, proto:TCP, len:66, ip/port:192.168.0.10:1343 -> 77.120.103.197:21, flags: ACK PSH , seq:171685432 ack:4095762307, win:65307, tcplen:26 [04/Jun/2008 10:19:42] PERMIT "Alow FTP" packet to TelNet, proto:TCP, len:66, ip/port:192.168.0.10:1343 -> 77.120.103.197:21, flags: ACK PSH , seq:171685432 ack:4095762307, win:65307, tcplen:26 [04/Jun/2008 10:19:42] PERMIT "Alow FTP" packet from TelNet, proto:TCP, len:119, ip/port:77.120.103.197:21 -> 195.138.168.40:1343, flags: ACK PSH , seq:4095762307 ack:171685458, win:65535, tcplen:79 [04/Jun/2008 10:19:42] PERMIT "Alow FTP" packet to Krimar Local, proto:TCP, len:119, ip/port:77.120.103.197:21 -> 192.168.0.10:1343, flags: ACK PSH , seq:4095762307 ack:171685458, win:65535, tcplen:79 [04/Jun/2008 10:19:42] PERMIT "Alow FTP" packet from Krimar Local, proto:TCP, len:40, ip/port:192.168.0.10:1343 -> 77.120.103.197:21, flags: ACK , seq:171685458 ack:4095762386, win:65228, tcplen:0 [04/Jun/2008 10:19:42] PERMIT "Alow FTP" packet to TelNet, proto:TCP, len:40, ip/port:192.168.0.10:1343 -> 77.120.103.197:21, flags: ACK , seq:171685458 ack:4095762386, win:65228, tcplen:0 [04/Jun/2008 10:19:43] PERMIT "Alow FTP" packet from TelNet, proto:TCP, len:63, ip/port:77.120.103.197:21 -> 195.138.168.40:1343, flags: ACK PSH , seq:4095762386 ack:171685458, win:65535, tcplen:23 [04/Jun/2008 10:19:43] PERMIT "Alow FTP" packet to Krimar Local, proto:TCP, len:63, ip/port:77.120.103.197:21 -> 192.168.0.10:1343, flags: ACK PSH , seq:4095762386 ack:171685458, win:65535, tcplen:23 [04/Jun/2008 10:19:43] PERMIT "Alow FTP" packet from Krimar Local, proto:TCP, len:46, ip/port:192.168.0.10:1343 -> 77.120.103.197:21, flags: ACK PSH , seq:171685458 ack:4095762409, win:65205, tcplen:6 [04/Jun/2008 10:19:43] PERMIT "Alow FTP" packet to TelNet, proto:TCP, len:46, ip/port:192.168.0.10:1343 -> 77.120.103.197:21, flags: ACK PSH , seq:171685458 ack:4095762409, win:65205, tcplen:6 [04/Jun/2008 10:19:43] PERMIT "Alow FTP" packet from TelNet, proto:TCP, len:92, ip/port:77.120.103.197:21 -> 195.138.168.40:1343, flags: ACK PSH , seq:4095762409 ack:171685464, win:65535, tcplen:52 [04/Jun/2008 10:19:43] PERMIT "Alow FTP" packet to Krimar Local, proto:TCP, len:92, ip/port:77.120.103.197:21 -> 192.168.0.10:1343, flags: ACK PSH , seq:4095762409 ack:171685464, win:65535, tcplen:52 [04/Jun/2008 10:19:44] PERMIT "Alow FTP" packet from Krimar Local, proto:TCP, len:60, ip/port:192.168.0.10:1343 -> 77.120.103.197:21, flags: ACK PSH , seq:171685464 ack:4095762461, win:65153, tcplen:20 [04/Jun/2008 10:19:44] PERMIT "Alow FTP" packet to TelNet, proto:TCP, len:60, ip/port:192.168.0.10:1343 -> 77.120.103.197:21, flags: ACK PSH , seq:171685464 ack:4095762461, win:65153, tcplen:20 [04/Jun/2008 10:19:44] PERMIT "Alow FTP" packet from TelNet, proto:TCP, len:113, ip/port:77.120.103.197:21 -> 195.138.168.40:1343, flags: ACK PSH , seq:4095762461 ack:171685484, win:65535, tcplen:73 [04/Jun/2008 10:19:44] PERMIT "Alow FTP" packet to Krimar Local, proto:TCP, len:113, ip/port:77.120.103.197:21 -> 192.168.0.10:1343, flags: ACK PSH , seq:4095762461 ack:171685484, win:65535, tcplen:73 [04/Jun/2008 10:19:44] PERMIT "Alow FTP" packet from Krimar Local, proto:TCP, len:40, ip/port:192.168.0.10:1343 -> 77.120.103.197:21, flags: ACK , seq:171685484 ack:4095762534, win:65080, tcplen:0 [04/Jun/2008 10:19:44] PERMIT "Alow FTP" packet to TelNet, proto:TCP, len:40, ip/port:192.168.0.10:1343 -> 77.120.103.197:21, flags: ACK , seq:171685484 ack:4095762534, win:65080, tcplen:0 [04/Jun/2008 10:19:44] PERMIT "Alow FTP" packet from Krimar Local, proto:TCP, len:46, ip/port:192.168.0.44:1949 -> 77.120.103.197:21, flags: ACK PSH , seq:731519318 ack:911740217, win:64688, tcplen:6 [04/Jun/2008 10:19:44] PERMIT "Alow FTP" packet to TelNet, proto:TCP, len:46, ip/port:192.168.0.44:1949 -> 77.120.103.197:21, flags: ACK PSH , seq:731519318 ack:911740217, win:64688, tcplen:6 | С ФТП, как видно, работают две машины. 192.168.0.10 и 44. Пассивный режим на клиенте включен. |