sleed Posted February 4, 2014 Report Posted February 4, 2014 (edited) In acest tutorial prezint instalarea unui modul de securitate ,PSAD , care detecteaza ce porturi sunt scanate.Primul pas , activam login-urile de la ip tables : iptables -A INPUT -j LOGiptables -A FORWARD -j LOGSalvam , iptables-save > /etc/iptables.up.rulesPasul II : apt-get install psad Instalam psadnano /etc/psad/psad.conf -> aICI ESTE LISTA DE configuratie , puteti sa o configurati dupa cum doriti.[QUOTE]nano /etc/psad/auto_dl[/QUOTE] ---> Lista de IP-URI , Allow/Deny --->nano /etc/psad/auto_dlApoi ii dam un restart : systemctl restart psad.servicePentru a afisa daca merge sau nu , executam : psad -SSursa : Sursa + optimizat putin de mine. Se poate folosi si cu CSF. 24 start() { 25 # Check if psad is already running 26 if [ ! -f /var/lock/subsys/psad ]; then 27 echo -n $"Starting $prog: " 28 daemon /usr/sbin/psad 29 RETVAL=$? 30 [ $RETVAL -eq 2 ] && touch /var/lock/subsys/psad 31 echo 32 fi 33 return $RETVAL 34 }Va multumesc! Edited February 4, 2014 by sleed Quote
kp112 Posted February 6, 2014 Report Posted February 6, 2014 curata si tu pm`urile ca am nevoie de tine Quote