bon reinsatalation de la derniere version de plesk, mise a jour de tous les logiciels de la machine...
l'interface de firewal de plesk l'air de fonctinner, et maintenant j'ai ça...
root@vds-xxxxxxxxx:/home/ts# iptables --list
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
REJECT tcp -- anywhere anywhere tcp flags:!FIN,SYN,RST,ACK/SYN reject-with tcp-reset
DROP all -- anywhere anywhere state INVALID
ACCEPT all -- anywhere anywhere
ACCEPT tcp -- anywhere anywhere tcp dpt:8443
ACCEPT tcp -- anywhere anywhere tcp dpt:8880
ACCEPT tcp -- anywhere anywhere tcp dpt:www
ACCEPT tcp -- anywhere anywhere tcp dpt:https
ACCEPT tcp -- anywhere anywhere tcp dpt:ftp
ACCEPT tcp -- localhost.localdomain anywhere tcp dpt:ssh
ACCEPT tcp -- 172.20.0.0/24 anywhere tcp dpt:ssh
ACCEPT tcp -- 192.168.0.0/16 anywhere tcp dpt:ssh
DROP tcp -- anywhere anywhere tcp dpt:ssh
DROP tcp -- anywhere anywhere tcp dpt:submission
DROP tcp -- anywhere anywhere tcp dpt:smtp
DROP tcp -- anywhere anywhere tcp dpt:ssmtp
DROP tcp -- anywhere anywhere tcp dpt:pop3
DROP tcp -- anywhere anywhere tcp dpt:pop3s
DROP tcp -- anywhere anywhere tcp dpt:imap2
DROP tcp -- anywhere anywhere tcp dpt:imaps
ACCEPT tcp -- 172.20.0.0/24 anywhere tcp dpt:poppassd
DROP tcp -- anywhere anywhere tcp dpt:poppassd
ACCEPT tcp -- localhost.localdomain anywhere tcp dpt:mysql
ACCEPT tcp -- 172.20.0.0/24 anywhere tcp dpt:mysql
DROP tcp -- anywhere anywhere tcp dpt:mysql
ACCEPT tcp -- localhost.localdomain anywhere tcp dpt:postgresql
ACCEPT tcp -- 172.20.0.0/24 anywhere tcp dpt:postgresql
DROP tcp -- anywhere anywhere tcp dpt:postgresql
DROP tcp -- anywhere anywhere tcp dpt:9008
DROP tcp -- anywhere anywhere tcp dpt:9080
ACCEPT udp -- 172.20.0.0/24 anywhere udp dpt:netbios-ns
ACCEPT udp -- 172.20.0.0/24 anywhere udp dpt:netbios-dgm
ACCEPT tcp -- 172.20.0.0/24 anywhere tcp dpt:netbios-ssn
ACCEPT tcp -- 172.20.0.0/24 anywhere tcp dpt:microsoft-ds
DROP udp -- anywhere anywhere udp dpt:netbios-ns
DROP udp -- anywhere anywhere udp dpt:netbios-dgm
DROP tcp -- anywhere anywhere tcp dpt:netbios-ssn
DROP tcp -- anywhere anywhere tcp dpt:microsoft-ds
ACCEPT udp -- anywhere anywhere udp dpt:openvpn
DROP udp -- anywhere anywhere udp dpt:domain
DROP tcp -- anywhere anywhere tcp dpt:domain
ACCEPT icmp -- localhost.localdomain anywhere icmp type 8 code 0
ACCEPT icmp -- 172.20.0.0/24 anywhere icmp type 8 code 0
DROP icmp -- anywhere anywhere icmp type 8 code 0
DROP all -- anywhere anywhere
Chain FORWARD (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
REJECT tcp -- anywhere anywhere tcp flags:!FIN,SYN,RST,ACK/SYN reject-with tcp-reset
DROP all -- anywhere anywhere state INVALID
ACCEPT all -- anywhere anywhere
DROP all -- anywhere anywhere
Chain OUTPUT (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
REJECT tcp -- anywhere anywhere tcp flags:!FIN,SYN,RST,ACK/SYN reject-with tcp-reset
DROP all -- anywhere anywhere state INVALID
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
ca 'a l'air mieux (bon pour le ftp c'est normal, mais c'est temporaire le temps de mettre a jour un de mes sites web)
le pb c'est que je n'arrive pas a me dearasser du vilain ruskof...
:/home/ts# netstat --numeric-users
Active Internet connections (w/o servers)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 62.193.XXX.XXX:45009 89.111.190.99:12 ESTABLISHED
a.k.a
netstat
Active Internet connections (w/o servers)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 vds-XXXXXXX.amen-p:45009 mangoo.webkazan.ru:12 ESTABLISHED
tcp 0 216 172.20.0.1:ssh 172.20.0.10:59027 ESTABLISHED
tcp 0 0 172.20.0.1:postgresql 172.20.0.10:57896 ESTABLISHED
tcp 0 0 172.20.0.1:postgresql 172.20.0.10:57895 ESTABLISHED
tcp 0 0 172.20.0.1:postgresql 172.20.0.10:57894 ESTABLISHED
tcp 0 0 172.20.0.1:postgresql 172.20.0.10:57893 ESTABLISHED
udp 0 0 localhost.localdo:55972 localhost.localdo:55972 ESTABLISHED
Active UNIX domain sockets (w/o servers)
Proto RefCnt Flags Type State I-Node Path
unix 2 [ ] DGRAM 4169164462 @/org/kernel/udev/monitor
unix 9 [ ] DGRAM 4169165664 /dev/log
unix 2 [ ] DGRAM 4169164443 @/org/kernel/udev/udevd
unix 2 [ ] DGRAM 4172228059 /opt/psa/var/modules/firewall/safeact.confirm
unix 2 [ ] DGRAM 4173880359
unix 3 [ ] STREAM CONNECTED 4173593567 /var/run/mysqld/mysqld.sock
unix 3 [ ] STREAM CONNECTED 4173593566
unix 2 [ ] DGRAM 4173593564
unix 2 [ ] DGRAM 4169180994
unix 3 [ ] STREAM CONNECTED 4169180232
unix 3 [ ] STREAM CONNECTED 4169180231
unix 2 [ ] DGRAM 4169179671
unix 2 [ ] DGRAM 4169179350
unix 2 [ ] DGRAM 4169166549
unix 2 [ ] DGRAM 4169165827
bien cutter en compagnie ne marchent pas et comme je le dis plus haut le reboot non plus, vilain semblant avoir mis sur ma machine un programme qui se connecte a lui
je verrais bien une règle iptable qui rejete tout ce qui sort vers lui, mais je ne sais pas comment faire... (oui je sais je suis nul...)