Linux ѧϰʹÓà iptables
ÔÚÕýʽ½éÉÜ iptables
µÄʹÓÃ
֮ǰ£¬ÎÒÃÇÏÈÀ´¿´Ò»ÏÂºÍ iptables
Ïà¹ØµÄһЩ»ù±¾¸ÅÄî¡£ÎÒÃÇÏÂÃæ½«»áƵ·±Ê¹ÓÃ
µ½
ËüÃÇ¡£
Æ¥Å䣨match£©£º·ûºÏÖ¸¶¨µÄÌõ¼þ£¬±ÈÈçÖ¸¶¨µÄ IP µØÖ·ºÍ¶Ë¿Ú¡£
¶ªÆú£¨drop£©£ºµ±Ò»¸ö°üµ½´ïʱ£¬¼òµ¥µØ¶ªÆú£¬²»×öÆäËüÈκδ¦Àí¡£
½ÓÊÜ£¨accept£©£ººÍ¶ªÆúÏà·´£¬½ÓÊÜÕâ¸ö°ü£¬ÈÃÕâ¸ö°üͨ¹ý¡£
¾Ü¾ø£¨reject£©£ººÍ¶ªÆúÏàËÆ£¬µ«Ëü»¹»áÏò·¢ËÍÕâ¸ö°üµÄÔ´Ö÷»ú·¢ËÍ´íÎóÏûÏ¢¡£Õâ¸ö´íÎóÏûÏ¢¿ÉÒÔÖ¸¶¨£¬Ò²¿ÉÒÔ×Ô¶¯²úÉú¡£
Ä¿±ê£¨target£©£ºÖ¸¶¨µÄ¶¯×÷£¬ËµÃ÷ÈçºÎ´¦ÀíÒ»¸ö°ü£¬±ÈÈ磺¶ªÆú£¬½ÓÊÜ£¬»ò¾Ü¾ø¡£
Ìø×ª£¨jump£©£ººÍÄ¿±êÀàËÆ£¬²»¹ýËüÖ¸¶¨µÄ²»ÊÇÒ»¸ö¾ßÌåµÄ¶¯×÷£¬¶øÊÇÁíÒ»¸öÁ´£¬±íÊ¾ÒªÌø×ªµ½ÄǸöÁ´ÉÏ¡£
¹æÔò£¨rule£©£ºÒ»¸ö»ò¶à¸öÆ¥Åä¼°Æä¶ÔÓ¦µÄÄ¿±ê¡£
Á´£¨chain£©£ºÃ¿ÌõÁ´¶¼°üº¬ÓÐһϵÁеĹæÔò£¬ÕâЩ¹æÔò»á±»ÒÀ´ÎÓ¦Óõ½Ã¿¸ö±éÀú¸ÃÁ´µÄÊý¾Ý°üÉÏ¡£Ã¿¸öÁ´¶¼Óи÷×ÔרÃŵÄÓÃ;£¬
ÕâÒ»µãÎÒÃÇÏÂÃæ»áÏêϸÌÖÂÛ¡£
±í £¨table£©£ºÃ¿¸ö±í°üº¬ÓÐÈô¸É¸ö²»Í¬µÄÁ´£¬±ÈÈç filter ±íĬÈϰüº¬ÓÐ INPUT£¬FORWARD£¬OUTPUT
Èý¸öÁ´¡£iptables
ÓÐËĸö±í£¬·Ö±ðÊÇ£ºraw£¬nat£¬mangleºÍfilter£¬Ã¿¸ö±í¶¼ÓÐ×Ô¼º×¨ÃŵÄÓô¦£¬±ÈÈç×î³£ÓÃfilter±í¾ÍÊÇרÃÅÓÃÀ´×ö°ü¹ýÂ˵쬶ø
nat ±íÊÇרÃÅÓÃÀ´×öNATµÄ¡£
²ßÂÔ£¨police£©£ºÎÒÃÇÔÚÕâÀïÌáµ½µÄ²ßÂÔÊÇÖ¸£¬¶ÔÓÚ iptables ÖÐijÌõÁ´£¬µ±ËùÓйæÔò¶¼Æ¥Åä²»³É¹¦Ê±ÆäĬÈϵĴ¦Àí¶¯×÷¡£
Á¬½Ó¸ú×Ù£¨connection
track£©£ºÓÖ³ÆÎª¶¯Ì¬¹ýÂË£¬¿ÉÒÔ¸ù¾ÝÖ¸¶¨Á¬½ÓµÄ״̬½øÐÐһЩÊʵ±µÄ¹ýÂË£¬ÊÇÒ»¸öºÜÇ¿´óµÄ¹¦ÄÜ£¬µ«Í¬Ê±Ò²±È½ÏÏûºÄÄÚ´æ×ÊÔ´¡£
iptables ½éÉÜ
iptables µÄ±íºÍÁ´£º
ÏÖÔÚ£¬ÈÃÎÒÃÇ¿´¿´µ±Ò»¸öÊý¾Ý°üµ½´ïʱËüÊÇÔõôÒÀ´Î´©¹ý¸÷¸öÁ´ºÍ±íµÄ¡£»ù±¾²½ÖèÈçÏ£º
1. Êý¾Ý°üµ½´ïÍøÂç½Ó¿Ú£¬±ÈÈç eth0¡£
2. ½øÈë raw ±íµÄ PREROUTING Á´£¬Õâ¸öÁ´µÄ×÷ÓÃÊǸÏÔÚÁ¬½Ó¸ú×Ù֮ǰ´¦ÀíÊý¾Ý°ü¡£
3. Èç¹û½øÐÐÁËÁ¬½Ó¸ú×Ù£¬ÔÚ´Ë´¦Àí¡£
4. ½øÈë mangle ±íµÄ PREROUTING Á´£¬ÔÚ´Ë¿ÉÒÔÐÞ¸ÄÊý¾Ý°ü£¬±ÈÈç TOS µÈ¡£
5. ½øÈë nat ±íµÄ PREROUTING Á´£¬¿ÉÒÔÔÚ´Ë×öDNAT£¬µ«²»Òª×ö¹ýÂË¡£
6. ¾ö¶¨Â·ÓÉ£¬¿´Êǽ»¸ø±¾µØÖ÷»ú»¹ÊÇת·¢¸øÆäËüÖ÷»ú¡£
µ½ÁËÕâÀïÎÒÃǾ͵÷ÖÁ½ÖÖ²»Í¬µÄÇé¿ö½øÐÐÌÖÂÛÁË£¬Ò»ÖÖÇé¿ö¾ÍÊÇÊý¾Ý°üҪת·¢¸øÆäËüÖ÷»ú£¬ÕâʱºòËü»áÒÀ´Î¾¹ý£º
7. ½øÈë mangle ±íµÄ FORWARD
Á´£¬ÕâÀïÒ²±È½ÏÌØÊ⣬ÕâÊÇÔÚµÚÒ»´Î·Óɾö¶¨Ö®ºó£¬ÔÚ½øÐÐ×îºóµÄ·Óɾö¶¨Ö®Ç°£¬ÎÒÃÇÈÔÈ»¿ÉÒÔ¶ÔÊý¾Ý°ü½øÐÐijЩÐ޸ġ£
8. ½øÈë filter ±íµÄ FORWARD
Á´£¬ÔÚÕ
Ïà¹ØÎĵµ£º
/*
* /*
* Linux x86 Dropbear SSH <= 0.34 remote root exploit
* coded by live
*
* You'll need a hacked ssh client to try this out. I included a patch
* to openssh-3.6.p1 somewhere below this comment.
*
* The point is: the buffer being exploited is too small(25 bytes) to hold our
......
linuxÔÚ2.6°æ±¾ÒÔºó½«ÅäÖÃÎļþÓÉÔÀ´µÄconfig.in¸ÄΪkconfig£¬¶ÔÓÚkconfigµÄÓï·¨ÔÚ/Documentation/kbuild/kconfig-language.txtÖÐ×öÁËÏêϸµÄ˵Ã÷£¬ÔÚÕâÀï¸ø³ökconfig-language.txtµÄÖÐÎİ档
½éÉÜ
----
ÔÚÅäÖÃÊý¾Ý¿âµÄÅäÖÃÑ¡ÏîÊÇÒÔÊ÷µÄÐÎʽ×éÖ¯µÄ£º
+- Code maturity level options
| +- ......
1¡¢ÓÃGCC±àÒë
1.1¡¢´´½¨Ô´Îļþ
(main.c) C Ô´Îļþ - main.c
#include
#include “reciprocal.hpp”
int main (int argc, char **argv)
{
int i;
i = atoi (argv[1]);
printf (“The reciprocal of %d is %g\n”, i, reciprocal (i ......
oracle dataguardÊÇÖ¸Ò»ÖÖÊý¾Ý¿â¼¶±ðµÄHA·½°¸£¬×îÖ÷ÒªµÄ¹¦ÄÜÊÇÈÝÔÖ£¬Êý¾Ý±£»¤£¬¹ÊÕϻָ´µÈ
ÔÚÉú²úÊý¾Ý¿âµÄÊÂÎñÒ»ÖÂÐÔʱ£¬Ê¹ÓòúÉúµÄÎïÀíÈ«±¸·Ý´´½¨±¸¿â£¬±¸¿âͨ¹ý´«Êä¹ýÀ´µÄ¹éµµÈÕÖ¾×Ô¶¯Î¬»¤±¸ÓÃÊý¾Ý¿â
½«ÖØ×öµÄÊý¾ÝÓ¦Óõ½±¸ÓÿâÉÏ¡£
1£¬Ç°Ì᣺
primary£º192.168.18.1;
oracle_SID:db1
  ......
ת×Ô£ºhttp://lkml.org/lkml/2005/8/2/242
--------------------------------------------------------------------------------------------
from
Jesper Juhl <>
Subject
Documentation - how to apply patches for various trees
Date
Tue, 2 Aug 2005 23:32:20 +0200
Hi,
How to apply the -rc, -git, ......