Журнал лабораторных работ

Содержание

Журнал

Вторник (06/02/09)

/dev/pts/24
15:45:30
#watch iptables -L -n -v

прошло 14 минут
16:00:09
#man mdadm
/dev/pts/3
16:06:38
#screen -x
/dev/pts/24
16:08:22
#lsmod | less
16:12:08
#iptables -t nat -Ln
iptables: No chain/target/match by that name.
16:12:12
#iptables -t nat -L
Chain PREROUTING (policy ACCEPT)
target     prot opt source               destination
Chain POSTROUTING (policy ACCEPT)
target     prot opt source               destination
Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination
16:12:23
#ls /proc/net/
anycast6   dev_snmp6      ip_conntrack         ip_tables_names    netfilter  psched     rt_acct   sockstat6     tr_rif
arp        if_inet6       ip_conntrack_expect  ip_tables_targets  netlink    raw        rt_cache  softnet_stat  udp
atm        igmp           ip_mr_cache          ipv6_route         netstat    raw6       snmp      stat          udp6
dev        igmp6          ip_mr_vif            mcfilter           packet     route      snmp6     tcp           unix
dev_mcast  ip6_flowlabel  ip_tables_matches    mcfilter6          protocols  rt6_stats  sockstat  tcp6          wireless
/dev/pts/8
16:12:51
#screen -x
/dev/pts/28
16:12:52
#screen -x
/dev/pts/42
16:13:24
#screen -x
/dev/pts/24
16:15:52
#netstat -np -A inet
Active Internet connections (w/o servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name
tcp        0      0 10.0.35.100:22          192.168.15.15:58191     ESTABLISHED 9775/18
tcp        0      0 10.0.35.100:22          192.168.15.9:58891      ESTABLISHED 9212/2
tcp        0   9616 10.0.35.100:22          192.168.107.2:46852     ESTABLISHED 12556/10
tcp        0      0 10.0.35.100:22          192.168.15.13:54318     ESTABLISHED 16372/3
tcp        0      0 10.0.35.100:22          192.168.104.8:48747     ESTABLISHED 12279/40
tcp        0      0 10.0.35.100:59651       194.150.93.78:18030     TIME_WAIT   -
tcp        0      0 10.0.35.100:22          192.168.108.2:37156     ESTABLISHED 16537/28
tcp        0      0 10.0.35.100:22          192.168.101.2:44992     ESTABLISHED 11659/34
...
tcp        0      0 10.0.35.100:22          192.168.106.2:45420     ESTABLISHED 15095/6
tcp        0      0 10.0.35.100:22          192.168.15.253:43536    ESTABLISHED 10506/30
tcp        0      0 10.0.35.100:22          192.168.15.7:38295      ESTABLISHED 11438/22
tcp        0      0 10.0.35.100:22          192.168.102.2:48057     ESTABLISHED 15666/44
tcp        0    288 10.0.35.100:22          192.168.107.2:40979     ESTABLISHED 11730/36
tcp        0      0 10.0.35.100:22          192.168.103.2:55292     ESTABLISHED 16679/42
tcp        0      0 127.0.0.1:3002          127.0.0.1:46269         CLOSE_WAIT  13398/nc
tcp        0      0 10.0.35.100:22          192.168.15.3:33397      ESTABLISHED 9770/14
tcp        0      0 10.0.35.100:22          192.168.105.2:39379     ESTABLISHED 15518/12
tcp        0      0 10.0.35.100:22          192.168.15.6:54367      ESTABLISHED 16535/8
16:15:55
#cat /proc/net/ip_conntrack | less
/dev/pts/22
16:21:30
#screen -x
/dev/pts/24
16:22:05
#cat /proc/net/ip_conntrack | grep src=192.168.102.2
tcp      6 432000 ESTABLISHED src=192.168.102.2 dst=10.0.35.100 sport=48057 dport=22 packets=2707 bytes=147959 src=10.0.35.100 dst=192.168.102.2 sport=22 dport=48057 packets=3465 bytes=962983 [ASSURED] mark=0 use=1
tcp      6 427160 ESTABLISHED src=10.0.35.100 dst=192.168.102.2 sport=39855 dport=80 packets=1 bytes=40 [UNREPLIED] src=192.168.102.2 dst=10.0.35.100 sport=80 dport=39855 packets=0 bytes=0 mark=0 use=1
tcp      6 427140 ESTABLISHED src=10.0.35.100 dst=192.168.102.2 sport=43520 dport=80 packets=1 bytes=40 [UNREPLIED] src=192.168.102.2 dst=10.0.35.100 sport=80 dport=43520 packets=0 bytes=0 mark=0 use=1
16:22:37
#iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE

/dev/pts/10
16:26:03
#screen -x
прошло 11 минут
/dev/pts/20
16:37:24
#netstat -n
Active Internet connections (w/o servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State
tcp        0      0 10.0.35.100:22          192.168.15.15:58191     ESTABLISHED
tcp        0      0 10.0.35.100:22          192.168.15.9:58891      ESTABLISHED
tcp        0      0 10.0.35.100:22          192.168.15.13:54318     ESTABLISHED
tcp        0      0 10.0.35.100:22          192.168.104.8:48747     ESTABLISHED
tcp        0      0 10.0.35.100:22          192.168.108.2:37156     ESTABLISHED
tcp        0      0 10.0.35.100:22          192.168.15.7:41057      ESTABLISHED
tcp        0      0 10.0.35.100:22          192.168.101.2:44992     ESTABLISHED
tcp        0      0 10.0.35.100:22          192.168.15.1:35465      ESTABLISHED
...
unix  3      [ ]         STREAM     CONNECTED     27217    /dev/log
unix  3      [ ]         STREAM     CONNECTED     27215
unix  3      [ ]         STREAM     CONNECTED     27104    /dev/log
unix  3      [ ]         STREAM     CONNECTED     27103
unix  3      [ ]         STREAM     CONNECTED     26969    /dev/log
unix  3      [ ]         STREAM     CONNECTED     26968
unix  3      [ ]         STREAM     CONNECTED     25477    /dev/log
unix  3      [ ]         STREAM     CONNECTED     25474
unix  3      [ ]         STREAM     CONNECTED     4760     /dev/log
unix  3      [ ]         STREAM     CONNECTED     4759
16:37:45
#netstat -nl
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State
tcp        0      0 0.0.0.0:79              0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:9999            0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN
tcp        0      0 127.0.0.1:25            0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:3002            0.0.0.0:*               LISTEN
tcp6       0      0 :::22                   :::*                    LISTEN
Active UNIX domain sockets (only servers)
Proto RefCnt Flags       Type       State         I-Node   Path
unix  2      [ ACC ]     STREAM     LISTENING     4399     /dev/log
16:37:49
#netstat -ns
Ip:
    1253638 total packets received
    6480 with invalid addresses
    0 forwarded
    0 incoming packets discarded
    1231755 incoming packets delivered
    1222335 requests sent out
Icmp:
    215538 ICMP messages received
    1010 input ICMP message failed.
...
    256 fast retransmits
    37 forward retransmits
    1156 retransmits in slow start
    372 other TCP timeouts
    24 SACK retransmits failed
    3 times receiver scheduled too late for direct processing
    86 DSACKs sent for old packets
    497 DSACKs received
    2 connections reset due to early user close
    18 connections aborted due to timeout
16:37:54
#netstat -na
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address           Foreign Address         State
tcp        0      0 0.0.0.0:79              0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:9999            0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN
tcp        0      0 127.0.0.1:25            0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:3002            0.0.0.0:*               LISTEN
tcp        0      0 10.0.35.100:22          192.168.15.15:58191     ESTABLISHED
tcp        0      0 10.0.35.100:22          192.168.15.9:58891      ESTABLISHED
tcp        0      0 10.0.35.100:22          192.168.15.13:54318     ESTABLISHED
...
unix  3      [ ]         STREAM     CONNECTED     27217    /dev/log
unix  3      [ ]         STREAM     CONNECTED     27215
unix  3      [ ]         STREAM     CONNECTED     27104    /dev/log
unix  3      [ ]         STREAM     CONNECTED     27103
unix  3      [ ]         STREAM     CONNECTED     26969    /dev/log
unix  3      [ ]         STREAM     CONNECTED     26968
unix  3      [ ]         STREAM     CONNECTED     25477    /dev/log
unix  3      [ ]         STREAM     CONNECTED     25474
unix  3      [ ]         STREAM     CONNECTED     4760     /dev/log
unix  3      [ ]         STREAM     CONNECTED     4759
16:37:56
#arp -v
Address                  HWtype  HWaddress           Flags Mask            Iface
10.0.35.9                ether   00:04:75:82:53:43   C                     eth0
10.0.35.1                ether   00:16:3E:04:00:01   C                     eth0
192.168.16.2             ether   00:16:3E:04:00:12   CM                    eth0
10.0.35.22               ether   00:15:60:7A:63:80   C                     eth0
192.168.16.2             *       <from_interface>    MP                    eth0
Entries: 5      Skipped: 0      Found: 5
16:38:20
#arp -va
? (10.0.35.9) at 00:04:75:82:53:43 [ether] on eth0
? (10.0.35.1) at 00:16:3E:04:00:01 [ether] on eth0
? (192.168.16.2) at 00:16:3E:04:00:12 [ether] PERM on eth0
? (10.0.35.22) at 00:15:60:7A:63:80 [ether] on eth0
? (192.168.16.2) at <from_interface> PERM PUB on eth0
Entries: 5      Skipped: 0      Found: 5
16:38:46
#who
root     pts/2        2009-06-02 09:48 (linux9.unix.nt)
root     pts/6        2009-06-02 15:15 (192.168.106.2)
root     pts/8        2009-06-02 16:12 (linux6.unix.nt)
root     pts/10       2009-06-02 16:25 (192.168.107.2)
root     pts/14       2009-06-02 10:17 (linux3.unix.nt)
root     pts/16       2009-06-02 10:17 (192.168.103.2)
root     pts/18       2009-06-02 10:17 (linux15.unix.nt)
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
root     pts/22       2009-06-02 16:21 (linux7.unix.nt)
root     pts/26       2009-06-02 14:33 (linux11.unix.nt)
...
root     pts/32       2009-06-02 10:57 (linux1.unix.nt)
root     pts/34       2009-06-02 11:08 (192.168.101.2)
root     pts/12       2009-06-02 15:28 (192.168.105.2)
root     pts/0        2009-06-01 17:24 (:pts/2:S.0)
root     pts/3        2009-06-02 16:06 (linux13.unix.nt)
root     pts/24       2009-06-02 10:41 (:pts/31:S.1)
root     pts/38       2009-06-02 11:33 (:pts/23:S.2)
root     pts/40       2009-06-02 11:39 (192.168.104.8)
root     pts/42       2009-06-02 16:13 (192.168.103.2)
root     pts/44       2009-06-02 15:32 (192.168.102.2)
16:40:14
#who
root     pts/2        2009-06-02 09:48 (linux9.unix.nt)
root     pts/6        2009-06-02 15:15 (192.168.106.2)
root     pts/8        2009-06-02 16:12 (linux6.unix.nt)
root     pts/10       2009-06-02 16:25 (192.168.107.2)
root     pts/14       2009-06-02 10:17 (linux3.unix.nt)
root     pts/16       2009-06-02 10:17 (192.168.103.2)
root     pts/18       2009-06-02 10:17 (linux15.unix.nt)
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
root     pts/22       2009-06-02 16:21 (linux7.unix.nt)
root     pts/28       2009-06-02 16:12 (192.168.108.2)
root     pts/30       2009-06-02 10:26 (192.168.15.253)
root     pts/32       2009-06-02 10:57 (linux1.unix.nt)
root     pts/34       2009-06-02 11:08 (192.168.101.2)
root     pts/12       2009-06-02 15:28 (192.168.105.2)
root     pts/0        2009-06-01 17:24 (:pts/2:S.0)
root     pts/3        2009-06-02 16:06 (linux13.unix.nt)
root     pts/24       2009-06-02 10:41 (:pts/31:S.1)
root     pts/38       2009-06-02 11:33 (:pts/23:S.2)
root     pts/40       2009-06-02 11:39 (192.168.104.8)
root     pts/42       2009-06-02 16:13 (192.168.103.2)
root     pts/44       2009-06-02 15:32 (192.168.102.2)
16:42:33
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:42:52
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:42:53
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:42:54
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:42:55
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:42:55
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:42:56
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:42:57
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:42:58
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:43:02
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:43:03
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:43:21
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:43:22
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:43:23
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:43:27
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:43:28
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:43:29
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:43:29
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
16:43:31
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
root     pts/26       2009-06-02 16:43 (linux11.unix.nt)
16:43:34
#who |grep linux11
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
root     pts/26       2009-06-02 16:50 (linux11.unix.nt)
/dev/pts/36
16:43:44
#who
root     pts/2        2009-06-02 09:48 (linux9.unix.nt)
root     pts/6        2009-06-02 15:15 (192.168.106.2)
root     pts/8        2009-06-02 16:12 (linux6.unix.nt)
root     pts/10       2009-06-02 16:25 (192.168.107.2)
root     pts/14       2009-06-02 10:17 (linux3.unix.nt)
root     pts/16       2009-06-02 10:17 (192.168.103.2)
root     pts/18       2009-06-02 10:17 (linux15.unix.nt)
root     pts/20       2009-06-02 15:26 (linux11.unix.nt)
root     pts/22       2009-06-02 16:21 (linux7.unix.nt)
root     pts/26       2009-06-02 16:43 (linux11.unix.nt)
...
root     pts/36       2009-06-02 16:43 (linux6.unix.nt)
root     pts/12       2009-06-02 15:28 (192.168.105.2)
root     pts/0        2009-06-01 17:24 (:pts/2:S.0)
root     pts/3        2009-06-02 16:06 (linux13.unix.nt)
root     pts/24       2009-06-02 10:41 (:pts/31:S.1)
root     pts/38       2009-06-02 11:33 (:pts/23:S.2)
root     pts/40       2009-06-02 11:39 (192.168.104.8)
root     pts/42       2009-06-02 16:13 (192.168.103.2)
root     pts/44       2009-06-02 15:32 (192.168.102.2)
root     pts/46       2009-06-02 16:43 (linux13.unix.nt)
/dev/pts/46
16:43:51