Журнал лабораторных работ

Содержание

Журнал

Пятница (04/27/12)

/dev/pts/0
13:17:22
#iptables
iptables v1.4.8: no command specified
Try `iptables -h' or 'iptables --help' for more information.
13:17:34
#iptables -h
iptables v1.4.8
Usage: iptables -[AD] chain rule-specification [options]
       iptables -I chain [rulenum] rule-specification [options]
       iptables -R chain rulenum rule-specification [options]
       iptables -D chain rulenum [options]
       iptables -[LS] [chain [rulenum]] [options]
       iptables -[FZ] [chain] [options]
       iptables -[NX] chain
       iptables -E old-chain-name new-chain-name
       iptables -P chain target [options]
...
[!] --out-interface -o output name[+]
                                network interface name ([+] for wildcard)
  --table       -t table        table to manipulate (default: `filter')
  --verbose     -v              verbose mode
  --line-numbers                print line numbers when listing
  --exact       -x              expand numbers (display exact values)
[!] --fragment  -f              match second or further fragments only
  --modprobe=<command>          try to insert modules using this command
  --set-counters PKTS BYTES     set the counter during insert/append
[!] --version   -V              print package version.
13:17:37
#iptables --table
iptables v1.4.8: option `--table' requires an argument
Try `iptables -h' or 'iptables --help' for more information.
13:17:44
#iptables -t
iptables v1.4.8: option `-t' requires an argument
Try `iptables -h' or 'iptables --help' for more information.
13:17:53
#iptables -l
iptables v1.4.8: option `-l' requires an argument
Try `iptables -h' or 'iptables --help' for more information.
13:18:11
#iptables --list
Chain INPUT (policy ACCEPT)
target     prot opt source               destination
Chain FORWARD (policy ACCEPT)
target     prot opt source               destination
Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination
13:18:14
#ls
asterisk-festival.pl  check-failed-regs.pl  l3-agent  l3-config  l3script
13:18:19
#ch
chage          chat           checksctp      chfn           chkdupexe      chpasswd       chsh
chardet        chattr         checksendmail  chgpasswd      chmod          chroot         chvt
charmap        chcon          cheese         chgrp          chown          chrt
13:18:19
#ch
chage          chat           checksctp      chfn           chkdupexe      chpasswd       chsh
chardet        chattr         checksendmail  chgpasswd      chmod          chroot         chvt
charmap        chcon          cheese         chgrp          chown          chrt
13:18:19
#ls
asterisk-festival.pl  check-failed-regs.pl  l3-agent  l3-config  l3script
13:18:33
#/usr/local/bin/check-gailed-regs.pl
bash: /usr/local/bin/check-gailed-regs.pl: No such file or directory
13:18:56
#ls -l
total 48
-rwxr-xr-x 1 root staff   702 Apr 25 17:14 asterisk-festival.pl
-rw-r--r-- 1 root staff  1409 Apr 27 12:53 check-failed-regs.pl
-rwxr-xr-x 1 root staff 33439 Apr 23 12:04 l3-agent
-rwxr-xr-x 1 root staff   100 Apr 23 12:04 l3-config
lrwxrwxrwx 1 root staff     9 Apr 23 12:04 l3script -> /bin/bash
13:19:02
#chmod 755 check-failed-regs.pl

13:20:04
#chown root:root check-failed-regs.pl

13:20:29
#less check-gailed-regs.pl
13:20:51
#ls
asterisk-festival.pl  check-failed-regs.pl  l3-agent  l3-config  l3script
13:20:53
#less check-failed-regs.pl
13:21:00
#check-failed-regs.pl
iptables: No chain/target/match by that name.
iptables: No chain/target/match by that name.
192.168.20.1 blocked. 9 attempts.
iptables: No chain/target/match by that name.
192.168.30.1 blocked. 1 attempts.
13:21:20
#iptables --list
Chain INPUT (policy ACCEPT)
target     prot opt source               destination
Chain FORWARD (policy ACCEPT)
target     prot opt source               destination
Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination
13:25:48
#check-failed-regs.pl
iptables: No chain/target/match by that name.
iptables: No chain/target/match by that name.
192.168.20.1 blocked. 9 attempts.
iptables: No chain/target/match by that name.
192.168.30.1 blocked. 1 attempts.
13:26:07
#iptables -t -L
iptables v1.4.8: no command specified
Try `iptables -h' or 'iptables --help' for more information.
13:30:05
#iptables -L -n
Chain INPUT (policy ACCEPT)
target     prot opt source               destination
Chain FORWARD (policy ACCEPT)
target     prot opt source               destination
Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination
13:30:14
#iptables -N asterisk

13:33:13
#iptables -I INPUT asterisk
iptables v1.4.8: Invalid rule number `asterisk'
Try `iptables -h' or 'iptables --help' for more information.
13:33:25
#iptables -I INPUT -j asterisk

13:33:33
#iptables -L -n
Chain INPUT (policy ACCEPT)
target     prot opt source               destination
asterisk   all  --  0.0.0.0/0            0.0.0.0/0
Chain FORWARD (policy ACCEPT)
target     prot opt source               destination
Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination
Chain asterisk (1 references)
target     prot opt source               destination
13:34:01
#check-failed-regs.pl
192.168.20.1 blocked. 9 attempts.
192.168.30.1 blocked. 1 attempts.
13:34:12
#iptables -L -n
Chain INPUT (policy ACCEPT)
target     prot opt source               destination
asterisk   all  --  0.0.0.0/0            0.0.0.0/0
Chain FORWARD (policy ACCEPT)
target     prot opt source               destination
Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination
Chain asterisk (1 references)
target     prot opt source               destination
DROP       all  --  192.168.30.1         0.0.0.0/0
DROP       all  --  192.168.20.1         0.0.0.0/0
13:34:14
#iptables -L -n
Chain INPUT (policy ACCEPT)
target     prot opt source               destination
asterisk   all  --  0.0.0.0/0            0.0.0.0/0
Chain FORWARD (policy ACCEPT)
target     prot opt source               destination
Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination
Chain asterisk (1 references)
target     prot opt source               destination
DROP       all  --  192.168.30.1         0.0.0.0/0
DROP       all  --  192.168.20.1         0.0.0.0/0
13:35:23
#tail -f /var/lo
local/ lock/  log/
13:35:23
#tail -f /var/log/asterisk/messages
[Apr 27 13:00:47] NOTICE[7171] chan_sip.c: Registration from '<sip:1002@192.168.10.1>' failed for '192.168.10.10' - Wrong password
[Apr 27 13:00:48] NOTICE[7171] chan_sip.c: Registration from '<sip:1002@192.168.10.1>' failed for '192.168.10.10' - Wrong password
[Apr 27 13:01:25] NOTICE[7171] chan_sip.c: Registration from '<sip:1002@192.168.10.1>' failed for '192.168.10.10' - Wrong password
[Apr 27 13:01:28] NOTICE[7171] chan_sip.c: Registration from '<sip:1002@192.168.10.1>' failed for '192.168.10.10' - Wrong password
[Apr 27 13:01:30] NOTICE[7171] chan_sip.c: Registration from '<sip:1002@192.168.10.1>' failed for '192.168.10.10' - Wrong password
[Apr 27 13:01:30] NOTICE[7171] chan_sip.c: Registration from '<sip:1002@192.168.10.1>' failed for '192.168.10.10' - Wrong password
[Apr 27 13:01:31] NOTICE[7171] chan_sip.c: Registration from '<sip:1002@192.168.10.1>' failed for '192.168.10.10' - Wrong password
[Apr 27 14:35:05] NOTICE[7171] chan_sip.c: Registration from '<sip:1002@192.168.10.1>' failed for '192.168.10.10' - Wrong password
[Apr 27 14:35:06] NOTICE[7171] chan_sip.c: Registration from '<sip:1002@192.168.10.1>' failed for '192.168.10.10' - Wrong password
[Apr 27 14:35:07] NOTICE[7171] chan_sip.c: Registration from '<sip:1002@192.168.10.1>' failed for '192.168.10.10' - Wrong password
[Apr 27 14:36:41] NOTICE[7171] chan_sip.c: Registration from '<sip:1002@192.168.10.1>' failed for '192.168.10.10' - Wrong password
^C
прошло 12 минут
13:47:37
#apt-cache search etter
aaphoto - Auto Adjust Photo, automatic color correction of photos
abcde - A Better CD Encoder
qlo10k1 - ALSA ld10k1 utility
antennavis - antenna radiation pattern visualization software
anypaper - front-end for wallpapersetter
libapache2-mod-upload-progress - upload progress support for the Apache web server
apt-zip - Update a non-networked computer using apt and removable media
aroarfw-dev - framework to build hardware with RoarAudio portocol support
aroarfw-doc - framework to build hardware with RoarAudio portocol support (documentation)
aspell - GNU Aspell spell-checker
...
yodl-doc - Documenation for Your Own Document Language (Yodl)
yodl - Your Own Document Language (Yodl) is a pre-document language
zoomer - generate a video from a picture by zooming from one point to another
bsdcpio - cpio(1) from FreeBSD, using libarchive
bsdtar - tar(1) from FreeBSD, using libarchive
libjsf-api-java - JavaServer Faces 2.0 Java EE web framework - API
libjsf-impl-java - JavaServer Faces 2.0 Java EE web framework - Implementation
libjsf-java-doc - Documentation for libjsf-api-java
samba-dbg - Samba debugging symbols
locales-all - Embedded GNU C Library: Precompiled locale data
13:47:58
#apt-cache search ettercap
ettercap-common - Common support files and plugins for ettercap
ettercap-gtk - Multipurpose sniffer/interceptor/logger for switched LAN
ettercap - Multipurpose sniffer/interceptor/logger for switched LAN
13:48:01
#apt-get install ettercap
Reading package lists... Done
Building dependency tree
Reading state information... Done
The following packages were automatically installed and are no longer required:
  mysql-common libmysqlclient16
Use 'apt-get autoremove' to remove them.
The following extra packages will be installed:
  ettercap-common
The following NEW packages will be installed:
  ettercap ettercap-common
...
Get:2 http://10.0.35.1/debian/ squeeze/main ettercap i386 1:0.7.3-2.1 [190 kB]
Fetched 493 kB in 0s (10.8 MB/s)
Selecting previously deselected package ettercap-common.
(Reading database ... 147143 files and directories currently installed.)
Unpacking ettercap-common (from .../ettercap-common_1%3a0.7.3-2.1_i386.deb) ...
Selecting previously deselected package ettercap.
Unpacking ettercap (from .../ettercap_1%3a0.7.3-2.1_i386.deb) ...
Processing triggers for man-db ...
Setting up ettercap-common (1:0.7.3-2.1) ...
Setting up ettercap (1:0.7.3-2.1) ...
13:48:24
#ettercap -M arp -T -L log /192.168.10.10/
ettercap NG-0.7.3 copyright 2001-2004 ALoR & NaGA
Listening on eth0... (Ethernet)
  eth0 ->       00:0F:FE:7E:B9:2F      192.168.10.1     255.255.255.0
SSL dissection needs a valid 'redir_command_on' script in the etter.conf file
Privileges dropped to UID 65534 GID 65534...
  28 plugins
  39 protocol dissectors
  53 ports monitored
7587 mac vendor fingerprint
1698 tcp OS fingerprint
...
Fri Apr 27 14:49:15 2012
TCP  192.168.10.10:55636 --> 192.168.10.1:22 | AP
.5..J.......Ow.h..K-........><..L.3..T..ss.^....8D... h.B.#...A..r..
Fri Apr 27 14:49:15 2012
TCP  192.168.10.1:22 --> 192.168.10.10:55636 | AP
..fzaYS.L.i.|.;;.M......$%....$..U8.GLJc.5(.    >J...F.b.+.,..
l(......
Fri Apr 27 14:49:15 2012
TCP  192.168.10.10:55636 --> 192.168.10.1:22 | A
User requested a CTRL+C... (deprecated, next time use proper shutdown)
13:49:22
#apt-get install openoffice.org
Reading package lists... Done
Building dependency tree
Reading state information... Done
The following packages were automatically installed and are no longer required:
  mysql-common libmysqlclient16
Use 'apt-get autoremove' to remove them.
The following extra packages will be installed:
  ca-certificates-java default-jre default-jre-headless gcj-4.4-base gcj-4.4-jre-lib java-common libaccess-bridge-java
  libaccess-bridge-java-jni libcommons-beanutils-java libcommons-collections3-java libcommons-compress-java
  libcommons-digester-java libcommons-logging-java libdb-je-java libdb4.7-java libdb4.7-java-gcj libgcj-bc
...
update-alternatives: using /usr/lib/jvm/java-6-openjdk/jre/bin/pluginappletviewer to provide /usr/bin/pluginappletviewer (pluginappletviewer) in auto mode.
update-alternatives: using /usr/lib/jvm/java-6-openjdk/jre/bin/policytool to provide /usr/bin/policytool (policytool) in auto mode.
Setting up default-jre (1:1.6-40) ...
Setting up libhsqldb-java (1.8.0.10-9) ...
Setting up openoffice.org-base (1:3.2.1-11+squeeze4) ...
Setting up openoffice.org-report-builder-bin (1:3.2.1-11+squeeze4) ...
Setting up openoffice.org-officebean (1:3.2.1-11+squeeze4) ...
Setting up openoffice.org-filter-mobiledev (1:3.2.1-11+squeeze4) ...
Setting up openoffice.org (1:3.2.1-11+squeeze4) ...
Processing triggers for menu ...
прошло 29 минут
14:18:30
#iptables -L -n
Chain INPUT (policy ACCEPT)
target     prot opt source               destination
asterisk-whitelist  all  --  0.0.0.0/0            0.0.0.0/0
Chain FORWARD (policy ACCEPT)
target     prot opt source               destination
Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination
Chain asterisk (0 references)
target     prot opt source               destination
ACCEPT     all  --  192.168.30.1         0.0.0.0/0
ACCEPT     all  --  192.168.20.1         0.0.0.0/0
DROP       all  --  192.168.10.10        0.0.0.0/0
DROP       all  --  192.168.30.1         0.0.0.0/0
DROP       all  --  192.168.20.1         0.0.0.0/0
Chain asterisk-whitelist (1 references)
target     prot opt source               destination
14:18:43
#iptables -F

14:26:21
#sip reload
bash: sip: command not found
прошло 47 минут
15:13:42
#asterisk -rvvv
Asterisk 1.6.2.9-2+squeeze4, Copyright (C) 1999 - 2010 Digium, Inc. and others.
Created by Mark Spencer <markster@digium.com>
Asterisk comes with ABSOLUTELY NO WARRANTY; type 'core show warranty' for details.
This is free software, with components licensed under the GNU General Public
License version 2 and other licenses; you are welcome to redistribute it under
certain conditions. Type 'core show license' for details.
=========================================================================
  == Parsing '/etc/asterisk/asterisk.conf':   == Found
  == Parsing '/etc/asterisk/extconfig.conf':   == Found
Connected to Asterisk 1.6.2.9-2+squeeze4 currently running on linux1 (pid = 7127)
...
    -- Executing [1005@gr-all:4] Monitor("SIP/1005-0000000f", "wav,1005-1005-2012-04-27-16_20_08,m") in new stack
    -- Executing [1005@gr-all:5] Dial("SIP/1005-0000000f", "SIP/1005,30,tT") in new stack
  == Using SIP RTP CoS mark 5
  == Using SIP VRTP CoS mark 6
    -- Called 1005
    -- SIP/1005-00000010 is ringing
  == Spawn extension (gr-all, 1005, 5) exited non-zero on 'SIP/1005-0000000f'
linux1*CLI>
Disconnected from Asterisk server
Executing last minute cleanups
15:21:05
#apt-get install tshark
Reading package lists... Done
Building dependency tree
Reading state information... Done
tshark is already the newest version.
The following packages were automatically installed and are no longer required:
  mysql-common libmysqlclient16
Use 'apt-get autoremove' to remove them.
0 upgraded, 0 newly installed, 0 to remove and 9 not upgraded.
15:23:08
#scp root@192.168.15.252:/usr/src/certified-asterisk-1.8.11-cert1.tar.gz /usr/scr
root@192.168.15.252's password:
certified-asterisk-1.8.11-cert1.tar.gz                                                100%   24MB  12.1MB/s   00:02
15:24:20
#ls
acerhk-modules-2.6.32-5-686_0.5.35-8+2.6.32-41squeeze2_i386.deb       linux-headers-2.6.32-5-common
acerhk.tar.bz2                                                        linux-kbuild-2.6.32
alsa-driver.tar.bz2                                                   linux-wlan-ng.tar.bz2
alsa-modules-2.6.32-5-686_1.0.23+dfsg-2+2.6.32-41squeeze2_i386.deb    lirc-modules.tar.bz2
cdfs-2.6.32-5-686_2.6.23-4+2.6.32-41squeeze2_i386.deb                 loop-aes.tar.bz2
cdfs.tar.bz2                                                          mga-vid.tar.gz
cloop-module-2.6.32-5-686_2.6.31.1.1+2.6.32-41squeeze2_i386.deb       modules
cloop.tar.bz2                                                         ndiswrapper.tar.bz2
comedi.tar.bz2                                                        openafs.tar.bz2
dahdi-modules-2.6.32-5-686_2.3.0.1+dfsg-2+2.6.32-41squeeze2_i386.deb  openswan-modules.tar.bz2
dahdi.tar.bz2                                                         qc-usb.tar.bz2
device3dfx.tar.gz                                                     rtai-source.tar.bz2
kernel-patches                                                        sysprof-module.tar.bz2
linux                                                                 virtualbox-ose.tar.bz2
linux-headers-2.6.32-5-686                                            vpb-driver.tar.bz2
15:24:39
#tar --help
Usage: tar [OPTION...] [FILE]...
GNU `tar' saves many files together into a single tape or disk archive, and can
restore individual files from the archive.
Examples:
  tar -cf archive.tar foo bar  # Create archive.tar from files foo and bar.
  tar -tvf archive.tar         # List all files in archive.tar verbosely.
  tar -xf archive.tar          # Extract all files from archive.tar.
 Main operation mode:
  -A, --catenate, --concatenate   append tar files to an archive
  -c, --create               create a new archive
...
  shell-always
  c
  c-maybe
  escape
  locale
  clocale
*This* tar defaults to:
--format=gnu -f- -b20 --quoting-style=escape --rmt-command=/usr/sbin/rmt
--rsh-command=/usr/bin/rsh
Report bugs to <bug-tar@gnu.org>.
15:24:44
#tar --usage
Usage: tar [-AcdrtuxGnSkUWOmpsMBiajJzZhPlRvwo?] [-g FILE] [-f ARCHIVE]
            [-F NAME] [-L NUMBER] [-b BLOCKS] [-H FORMAT] [-V TEXT] [-I PROG]
            [-C DIR] [-K MEMBER-NAME] [-N DATE-OR-FILE] [-T FILE] [-X FILE]
            [--catenate] [--concatenate] [--create] [--diff] [--compare]
            [--delete] [--append] [--list] [--test-label] [--update]
            [--extract] [--get] [--check-device] [--listed-incremental=FILE]
            [--incremental] [--ignore-failed-read] [--level=NUMBER] [--seek]
            [--no-check-device] [--no-seek] [--occurrence[=NUMBER]]
            [--sparse-version=MAJOR[.MINOR]] [--sparse] [--keep-old-files]
            [--keep-newer-files] [--no-overwrite-dir] [--overwrite]
...
            [--ignore-case] [--no-anchored] [--no-ignore-case] [--no-wildcards]
            [--no-wildcards-match-slash] [--wildcards]
            [--wildcards-match-slash] [--checkpoint[=NUMBER]]
            [--checkpoint-action=ACTION] [--index-file=FILE] [--check-links]
            [--no-quote-chars=STRING] [--quote-chars=STRING]
            [--quoting-style=STYLE] [--block-number] [--show-defaults]
            [--show-omitted-dirs] [--show-transformed-names]
            [--show-stored-names] [--totals[=SIGNAL]] [--utc] [--verbose]
            [--warning=KEYWORD] [--interactive] [--confirmation] [--help]
            [--restrict] [--usage] [--version] [FILE]...
15:24:50
#man tar
15:28:10
#tar -xvz certified-asterisk-1.8.11-cert1.tar.gz
^C
15:28:22
#tar -xvz certified-asterisk-1.8.11-cert1.tar.gz
^C
15:28:37
#ls l
ls: cannot access l: No such file or directory
15:28:53
#ls -l
total 15228
-rw-r--r--  1 root root   29366 Apr 25 11:58 acerhk-modules-2.6.32-5-686_0.5.35-8+2.6.32-41squeeze2_i386.deb
-rw-r--r--  1 root root   28523 Jul  3  2009 acerhk.tar.bz2
-rw-r--r--  1 root root 3582891 Oct 23  2010 alsa-driver.tar.bz2
-rw-r--r--  1 root root 1999336 Apr 25 12:02 alsa-modules-2.6.32-5-686_1.0.23+dfsg-2+2.6.32-41squeeze2_i386.deb
-rw-r--r--  1 root root   23612 Apr 25 12:02 cdfs-2.6.32-5-686_2.6.23-4+2.6.32-41squeeze2_i386.deb
-rw-r--r--  1 root root   80578 Nov 26  2008 cdfs.tar.bz2
-rw-r--r--  1 root root   29614 Apr 25 12:02 cloop-module-2.6.32-5-686_2.6.31.1.1+2.6.32-41squeeze2_i386.deb
-rw-r--r--  1 root root   28728 Jan 15  2010 cloop.tar.bz2
-rw-r--r--  1 root root  941147 Jun  2  2009 comedi.tar.bz2
...
-rw-r--r--  1 root root   15938 May 18  2010 mga-vid.tar.gz
drwxr-xr-x 11 root root    4096 Oct 29  2010 modules
-rw-r--r--  1 root root  141942 Feb 14  2010 ndiswrapper.tar.bz2
-rw-r--r--  1 root root  858234 Feb  9  2011 openafs.tar.bz2
-rw-r--r--  1 root root  489970 Dec 24 19:14 openswan-modules.tar.bz2
-rw-r--r--  1 root root   91234 Feb  4  2010 qc-usb.tar.bz2
-rw-r--r--  1 root root 4475454 Jul  3  2010 rtai-source.tar.bz2
-rw-r--r--  1 root root    6592 Jun 14  2010 sysprof-module.tar.bz2
-rw-r--r--  1 root root  439650 Oct 13  2010 virtualbox-ose.tar.bz2
-rw-r--r--  1 root root   68983 Jan 16  2011 vpb-driver.tar.bz2
15:28:55
#ls -l cer*
ls: cannot access cer*: No such file or directory
15:29:00
#ls cer*
ls: cannot access cer*: No such file or directory
15:29:03
#cd /usr/scr
bash: cd: /usr/scr: Not a directory
15:29:18
#cd /usr/src

15:29:23
#ls
acerhk-modules-2.6.32-5-686_0.5.35-8+2.6.32-41squeeze2_i386.deb       linux-headers-2.6.32-5-common
acerhk.tar.bz2                                                        linux-kbuild-2.6.32
alsa-driver.tar.bz2                                                   linux-wlan-ng.tar.bz2
alsa-modules-2.6.32-5-686_1.0.23+dfsg-2+2.6.32-41squeeze2_i386.deb    lirc-modules.tar.bz2
cdfs-2.6.32-5-686_2.6.23-4+2.6.32-41squeeze2_i386.deb                 loop-aes.tar.bz2
cdfs.tar.bz2                                                          mga-vid.tar.gz
cloop-module-2.6.32-5-686_2.6.31.1.1+2.6.32-41squeeze2_i386.deb       modules
cloop.tar.bz2                                                         ndiswrapper.tar.bz2
comedi.tar.bz2                                                        openafs.tar.bz2
dahdi-modules-2.6.32-5-686_2.3.0.1+dfsg-2+2.6.32-41squeeze2_i386.deb  openswan-modules.tar.bz2
dahdi.tar.bz2                                                         qc-usb.tar.bz2
device3dfx.tar.gz                                                     rtai-source.tar.bz2
kernel-patches                                                        sysprof-module.tar.bz2
linux                                                                 virtualbox-ose.tar.bz2
linux-headers-2.6.32-5-686                                            vpb-driver.tar.bz2
15:29:56
#scp root@192.168.15.252:/usr/src/certified-asterisk-1.8.11-cert1.tar.gz /usr/scr/
root@192.168.15.252's password:
/usr/scr/: Is a directory