<!DOCTYPE html> <html> <head> </head> <body> <p># Detect if an attack is in progress…</p> <p><strong>netstat -plant</strong><br />– Filtra per IP<br /><strong>netstat -plant |grep -c 185.11.147.63</strong></p> <p>– Filtra per utente hosting<br /><strong>ps faux |grep paganico<br /><br /></strong># Counts connections for IP [ottimo modo per contare le sessioni per IP]<strong><br />netstat -anp |grep 'tcp|udp' | awk '{print $5}' | sed s/::ffff:// | cut -d: -f1 | sort | uniq -c | sort -n<br /><br /></strong># Sessions count for IP<strong><br />netstat -nA inet |awk '/^[ut]/{split($5,a,":");print a[1]}'|sort |uniq -c |sort -n<br /><br /></strong>#To view the total number of connections to a port, run the following command in ssh<strong><br />netstat -tuna | awk -F':+| +' 'NR>2{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n<br /><br /></strong>#To view the total number of connections from a single ip, run the following command in ssh<strong><br />netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n<br /><br /></strong>#Show number of connections by state<strong><br />netstat -nat | awk '{print $6}' | sort | uniq -c | sort -n<br /><br /></strong>#Show all IPs connected<strong><br />netstat -nat | awk '{ print $5}' | cut -d: -f1 | sed -e '/^$/d' | uniq<br /><br /></strong>#Show number of connections per IP<strong><br />netstat -atun | awk '{print $5}' | cut -d: -f1 | sed -e '/^$/d' |sort | uniq -c | sort -n <br /><br /></strong></p> <p>#Per installare CSF su cPanel</p> <p>To install CSF, run the following at the command line as the root user:</p> <p><strong>#wget http://configserver.com/free/csf.tgz</strong><br /><strong>#tar -xzf csf.tgz</strong><br /><strong>#cd csf & ./install.cpanel.sh</strong></p> <p>To configure CSF, use WHM's ConfigServer & Firewall interface (Home >> Plugins >> ConfigServer & Firewall).<br /><br />SYNFLOOD = “1″<br />SYNFLOOD_RATE = “30/s”<br />SYNFLOOD_BURST = “10″<br />PORTFLOOD = 80;tcp;100;5,22;tcp;5;300<br /><br />CT_LIMIT = 50 (25 forse è meglio)<br />CT_INTERVAL = 30<br />CT_PORTS = 80,443 (non mettere niente per tutte le porte)<br /><br /><br /></p> <p> Porte configurate attualmente sui server cPanel<br /><br /></p> <p>TCP_IN = 20,21,22,25,26,53,80,110,143,443,465,587,783,990,993,995,2077,2078,2079,2080,2082,2083,2086,2087,2095,2096,30000:50000<br />TCP_OUT = 20,21,22,25,26,37,43,53,80,111,113,443,465,587,873,990,2049,2077,2078,2079,2080,2089,2195,2703,30000:50000</p> <p>UDP_IN = 53,161,465,783<br />UDP_OUT = 53,111,123,161,465,873,2049,20048,30000,33434:33523</p> <p> </p> <table style="width: 1000px; border-color: black;"><caption> </caption> <tbody> <tr> <td style="border-color: black; width: 37.2727px;"><strong>Port </strong></td> <td style="border-color: black; width: 110px;"><strong>Service</strong></td> <td style="border-color: black; width: 28.1818px;"><strong>TCP </strong></td> <td style="border-color: black; width: 30.9091px;"><strong>UDP </strong></td> <td style="border-color: black; width: 60px;"><strong>Inbound </strong></td> <td style="border-color: black; width: 70px;"><strong>Outbound </strong></td> <td style="border-color: black; width: 662.727px;"><strong>Notes</strong></td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">1</td> <td style="border-color: black; width: 110px;"><strong>CPAN</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;"> </td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;">The <em>Show Available Modules</em> option in cPanel's <em><a href="https://documentation.cpanel.net/display/70Docs/Perl+Modules">Perl Modules</a> </em>interface (<em>cPanel >> Home >> Software >> Perl Modules</em>) uses this port to improve the speed in which it appears.</td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">20</td> <td style="border-color: black; width: 110px;"><strong>FTP</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">21</td> <td style="border-color: black; width: 110px;"><strong>FTP</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">22</td> <td style="border-color: black; width: 110px;"><strong>SSH</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;">(X)</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">25</td> <td style="border-color: black; width: 110px;"><strong>SMTP</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">26</td> <td style="border-color: black; width: 110px;"><strong>SMTP</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">37</td> <td style="border-color: black; width: 110px;"><strong>rdate</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;"> </td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">43</td> <td style="border-color: black; width: 110px;"><strong>whois</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;"> </td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">53</td> <td style="border-color: black; width: 110px;"><strong>bind</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;">X</td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">80</td> <td style="border-color: black; width: 110px;"><strong>http</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">110</td> <td style="border-color: black; width: 110px;"><strong>POP3</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;"> </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">111</td> <td style="border-color: black; width: 110px;"><strong>NFS Sun</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;">X</td> <td style="border-color: black; width: 60px; text-align: center;"> </td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">113</td> <td style="border-color: black; width: 110px;"><strong>ident</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;"> </td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">143</td> <td style="border-color: black; width: 110px;"><strong>IMAP</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;"> </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">443</td> <td style="border-color: black; width: 110px;"><strong>https</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">465</td> <td style="border-color: black; width: 110px;"><strong>STMP, SSL/TLS</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;">X</td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">579</td> <td style="border-color: black; width: 110px;"><strong>cPHulk</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;"> </td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;"> </td> <td style="border-color: black; width: 70px; text-align: center;"> </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">783</td> <td style="border-color: black; width: 110px;"><strong>Apache SpamAssassin</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;">X</td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;"> </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">873</td> <td style="border-color: black; width: 110px;"><strong>rsync</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;">X</td> <td style="border-color: black; width: 60px; text-align: center;"> </td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">993</td> <td style="border-color: black; width: 110px;"><strong>IMAP SSL</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;"> </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">995</td> <td style="border-color: black; width: 110px;"><strong>POP3 SSL</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;"> </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">2049</td> <td style="border-color: black; width: 110px;"><strong>NFS Sun</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;"> </td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">2703</td> <td style="border-color: black; width: 110px;"><strong>Razor</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;"> </td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">2077</td> <td style="border-color: black; width: 110px;"><strong>WebDAV</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">2078</td> <td style="border-color: black; width: 110px;"><strong>WebDAV SSL</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">2079</td> <td style="border-color: black; width: 110px;"><strong>CalDAV and CardDAV</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">2080</td> <td style="border-color: black; width: 110px;"><strong>CadDAV and CardDAV SSL</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">2082</td> <td style="border-color: black; width: 110px;"><strong>cPanel</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;"> </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">2083</td> <td style="border-color: black; width: 110px;"><strong>cPanel SSL</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;"> </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">2086</td> <td style="border-color: black; width: 110px;"><strong>WHM</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;"> </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">2087</td> <td style="border-color: black; width: 110px;"><strong>WHM SSL</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;"> </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">2089</td> <td style="border-color: black; width: 110px;"><strong>cPanel Licensing</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;"> </td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">2095</td> <td style="border-color: black; width: 110px;"><strong>WebMail</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;"> </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">2096</td> <td style="border-color: black; width: 110px;"><strong>WebMail SSL</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;"> </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">2195</td> <td style="border-color: black; width: 110px;"><strong>APNs</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;"> </td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">3306</td> <td style="border-color: black; width: 110px;"><strong>MySQL</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">(X)</td> <td style="border-color: black; width: 70px; text-align: center;"> </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">6277</td> <td style="border-color: black; width: 110px;"><strong>DCC</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;">X</td> <td style="border-color: black; width: 30.9091px; text-align: center;">X</td> <td style="border-color: black; width: 60px; text-align: center;">X</td> <td style="border-color: black; width: 70px; text-align: center;">X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">30000:50000</td> <td style="border-color: black; width: 110px;"><strong>FTP Passive mode pool</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;"> X</td> <td style="border-color: black; width: 30.9091px; text-align: center;"> </td> <td style="border-color: black; width: 60px; text-align: center;">X </td> <td style="border-color: black; width: 70px; text-align: center;">X </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;">33434:33523</td> <td style="border-color: black; width: 110px;"><strong>Traceroute pool</strong></td> <td style="border-color: black; width: 28.1818px; text-align: center;"> </td> <td style="border-color: black; width: 30.9091px; text-align: center;"> X</td> <td style="border-color: black; width: 60px; text-align: center;"> </td> <td style="border-color: black; width: 70px; text-align: center;"> X</td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;"> </td> <td style="border-color: black; width: 110px;"> </td> <td style="border-color: black; width: 28.1818px;"> </td> <td style="border-color: black; width: 30.9091px;"> </td> <td style="border-color: black; width: 60px;"> </td> <td style="border-color: black; width: 70px;"> </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> <tr> <td style="border-color: black; width: 37.2727px;"> </td> <td style="border-color: black; width: 110px;"> </td> <td style="border-color: black; width: 28.1818px;"> </td> <td style="border-color: black; width: 30.9091px;"> </td> <td style="border-color: black; width: 60px;"> </td> <td style="border-color: black; width: 70px;"> </td> <td style="border-color: black; width: 662.727px;"> </td> </tr> </tbody> </table> <p> </p> <p> </p> <p><strong><br /> </strong> </p> <p> </p> </body> </html>
Subscribe
0 Comments
Oldest