From: Huseyin Gomleksizoglu (huseyin@gomleksizoglu.com)
Date: Sun 23 Nov 2003 - 08:50:48 EST
bilgisayarimda acik bir proxy varmis ve bu yuzden maillerim karsi tarafa
ulasmiyormus ve kara listeye alinmisim. napmam lazim? makinemde suqid
kurulu ama calisir durumda degil. redhat'in firewall'u da acik. sadece
www,ssh ve ftp'ye izin veriyor.=20
Aslinda maillerim bir hosting firmasinda. hosting firmasinin smtp'sini
kullaniyorum ama neden benim makinemdeki acik ile ilgileniliyor ki?
netstat -a ile LISTEN durumda olan portlar=FD a=FEa=F0=FDda yazd=FDm.=20
IPChains'i kurcalama baslamadan once. Hangi portlar=FD kapatmam
gerektigini nerden bulabilirim? Yardimci olabilir misiniz?
az once kendi kendime gonderdigim mesajlarda da benzer uyarilar gordum.
onlar=FD da asagida gonderiyorum.=20
karalisteye girdiysem. IP adresimi mi degistirmem gerekiyor?
iyi bayramlar,
Huseyin
pts rule name description
--- ---------------------- ----------------------
1.9 WEIRD_PORT URI: Uses non-standard port number for HTTP
0.2 NORMAL_HTTP_TO_IP URI: Uses a dotted-decimal IP address in URL
1.1 RCVD_IN_SORBS_HTTP RBL: SORBS: sender is open HTTP proxy server
[195.174.107.174 listed in dnsbl.sorbs.net]
1.1 RCVD_IN_SORBS_MISC RBL: SORBS: sender is open proxy server
[195.174.107.174 listed in dnsbl.sorbs.net]
0.1 RCVD_IN_SORBS RBL: SORBS: sender is listed in SORBS
[195.174.107.174 listed in dnsbl.sorbs.net]
0.1 RCVD_IN_NJABL RBL: Received via a relay in dnsbl.njabl.org
[195.174.107.174 listed in dnsbl.njabl.org]
1.1 RCVD_IN_DSBL RBL: Received via a relay in list.dsbl.org
=20
[<http://dsbl.org/listing?ip=3D195.174.107.174>]
1.1 RCVD_IN_NJABL_PROXY RBL: NJABL: sender is an open proxy
[195.174.107.174 listed in dnsbl.njabl.org]
2.5 RCVD_IN_DYNABLOCK RBL: Sent directly from dynamic IP address
[Dynamic/Residential IP range listed by]
-- [root@localhost root]# netstat -a Active Internet connections (servers and established) Proto Recv-Q Send-Q Local Address Foreign Address =20 State tcp 0 0 *:32769 *:* LISTEN tcp 0 0 localhost.localdo:32770 *:* LISTEN tcp 0 0 *:mysql *:* LISTEN tcp 0 0 localhost.localdoma:783 *:* LISTEN tcp 0 0 *:sunrpc *:* LISTEN tcp 0 0 *:http *:* LISTEN tcp 0 0 *:smtps *:* LISTEN tcp 0 0 *:ftp *:* LISTEN tcp 0 0 ist02768.ultrane:domain *:* LISTEN tcp 0 0 localhost.locald:domain *:* LISTEN tcp 0 0 *:ssh *:* LISTEN tcp 0 0 localhost.localdoma:ipp *:* LISTEN tcp 0 0 *:smtp *:* LISTEN tcp 0 0 localhost.localdom:rndc *:* LISTEN tcp 0 0 *:https *:* LISTEN --- linux-baslangic listesinden cikmak ve tum listeci islemleri icin http://liste.linux.org.tr/ adresini kullanabilirisniz. Bu listeden cikmak icin <a href="mailto:linux-baslangic-request@liste.linux.org.tr?Subject=unsubscribe"> tiklayiniz</a>