📄 ch17_18.htm
字号:
<HTML><HEAD><TITLE>Recipe 17.17. Program: backsniff (Perl Cookbook)</TITLE><METANAME="DC.title"CONTENT="Perl Cookbook"><METANAME="DC.creator"CONTENT="Tom Christiansen & Nathan Torkington"><METANAME="DC.publisher"CONTENT="O'Reilly & Associates, Inc."><METANAME="DC.date"CONTENT="1999-07-02T01:44:45Z"><METANAME="DC.type"CONTENT="Text.Monograph"><METANAME="DC.format"CONTENT="text/html"SCHEME="MIME"><METANAME="DC.source"CONTENT="1-56592-243-3"SCHEME="ISBN"><METANAME="DC.language"CONTENT="en-US"><METANAME="generator"CONTENT="Jade 1.1/O'Reilly DocBook 3.0 to HTML 4.0"><LINKREV="made"HREF="mailto:online-books@oreilly.com"TITLE="Online Books Comments"><LINKREL="up"HREF="ch17_01.htm"TITLE="17. Sockets"><LINKREL="prev"HREF="ch17_17.htm"TITLE="17.16. Restarting a Server on Demand"><LINKREL="next"HREF="ch17_19.htm"TITLE="17.18. Program: fwdport"></HEAD><BODYBGCOLOR="#FFFFFF"><img alt="Book Home" border="0" src="gifs/smbanner.gif" usemap="#banner-map" /><map name="banner-map"><area shape="rect" coords="1,-2,616,66" href="index.htm" alt="Perl Cookbook"><area shape="rect" coords="629,-11,726,25" href="jobjects/fsearch.htm" alt="Search this book" /></map><div class="navbar"><p><TABLEWIDTH="684"BORDER="0"CELLSPACING="0"CELLPADDING="0"><TR><TDALIGN="LEFT"VALIGN="TOP"WIDTH="228"><ACLASS="sect1"HREF="ch17_17.htm"TITLE="17.16. Restarting a Server on Demand"><IMGSRC="../gifs/txtpreva.gif"ALT="Previous: 17.16. Restarting a Server on Demand"BORDER="0"></A></TD><TDALIGN="CENTER"VALIGN="TOP"WIDTH="228"><B><FONTFACE="ARIEL,HELVETICA,HELV,SANSERIF"SIZE="-1"><ACLASS="chapter"REL="up"HREF="ch17_01.htm"TITLE="17. Sockets"></A></FONT></B></TD><TDALIGN="RIGHT"VALIGN="TOP"WIDTH="228"><ACLASS="sect1"HREF="ch17_19.htm"TITLE="17.18. Program: fwdport"><IMGSRC="../gifs/txtnexta.gif"ALT="Next: 17.18. Program: fwdport"BORDER="0"></A></TD></TR></TABLE></DIV><DIVCLASS="sect1"><H2CLASS="sect1"><ACLASS="title"NAME="ch17-chap17_program_0">17.17. Program: backsniff</A></H2><PCLASS="para"><ACLASS="indexterm"NAME="ch17-idx-1000004883-0"></A><ACLASS="indexterm"NAME="ch17-idx-1000004883-1"></A><ACLASS="indexterm"NAME="ch17-idx-1000004883-2"></A>This program logs attempts to connect to ports. It uses the Sys::Syslog module (it in turn wants the <EMCLASS="emphasis">syslog.ph</EM> library, which may or may not come with your system) to log the connection attempt as level LOG_NOTICE and facility LOG_DAEMON. It uses <CODECLASS="literal">getsockname</CODE> to find out what port was connected to and <CODECLASS="literal">getpeername</CODE> to find out what machine made the connection. It uses <CODECLASS="literal">getservbyport</CODE> to convert the local port number (e.g., 7) into a service name (e.g, <CODECLASS="literal">"echo"</CODE>).</P><PCLASS="para">It produces entries in the system log file like this:</P><PRECLASS="programlisting"><CODECLASS="userinput"><B><CODECLASS="replaceable"><I>May 25 15:50:22 coprolith sniffer: Connection from 207.46.131.141 to</I></CODE></B></CODE><CODECLASS="userinput"><B><CODECLASS="replaceable"><I>207.46.130.164:echo </I></CODE></B></CODE></PRE><PCLASS="para">Install it in the <EMCLASS="emphasis">inetd.conf</EM> file with a line like this:</P><PRECLASS="programlisting"><CODECLASS="userinput"><B><CODECLASS="replaceable"><I>echo stream tcp nowait nobody /usr/scripts/snfsqrd sniffer</I></CODE></B></CODE></PRE><PCLASS="para">The program is shown in <ACLASS="xref"HREF="ch17_18.htm#ch17-14194"TITLE="backsniff">Example 17.7</A>.</P><DIVCLASS="example"><H4CLASS="example"><ACLASS="title"NAME="ch17-14194">Example 17.7: backsniff</A></H4><PRECLASS="programlisting">#!/usr/bin/perl -w# backsniff - log attempts to connect to particular portsuse <ACLASS="indexterm"NAME="ch17-idx-1000005984-0"></A>Sys::Syslog;use Socket;# identify my port and address$sockname = getsockname(STDIN) or die "Couldn't identify myself: $!\n";($port, $iaddr) = sockaddr_in($sockname);$my_address = inet_ntoa($iaddr);# get a name for the service$service = (getservbyport ($port, "tcp"))[0] || $port;# now identify remote address$sockname = getpeername(STDIN) or die "Couldn't identify other end: $!\n";($port, $iaddr) = sockaddr_in($sockname);$ex_address = inet_ntoa($iaddr);# and log the informationopenlog("sniffer", "ndelay", "daemon");syslog("notice", "Connection from %s to %s:%s\n", $ex_address, $my_address, $service); closelog();exit;<ACLASS="indexterm"NAME="ch17-idx-1000005786-0"></A><ACLASS="indexterm"NAME="ch17-idx-1000005786-1"></A><ACLASS="indexterm"NAME="ch17-idx-1000005786-2"></A></PRE></DIV></DIV><DIVCLASS="htmlnav"><P></P><HRALIGN="LEFT"WIDTH="684"TITLE="footer"><TABLEWIDTH="684"BORDER="0"CELLSPACING="0"CELLPADDING="0"><TR><TDALIGN="LEFT"VALIGN="TOP"WIDTH="228"><ACLASS="sect1"HREF="ch17_17.htm"TITLE="17.16. Restarting a Server on Demand"><IMGSRC="../gifs/txtpreva.gif"ALT="Previous: 17.16. Restarting a Server on Demand"BORDER="0"></A></TD><TDALIGN="CENTER"VALIGN="TOP"WIDTH="228"><ACLASS="book"HREF="index.htm"TITLE="Perl Cookbook"><IMGSRC="../gifs/txthome.gif"ALT="Perl Cookbook"BORDER="0"></A></TD><TDALIGN="RIGHT"VALIGN="TOP"WIDTH="228"><ACLASS="sect1"HREF="ch17_19.htm"TITLE="17.18. Program: fwdport"><IMGSRC="../gifs/txtnexta.gif"ALT="Next: 17.18. Program: fwdport"BORDER="0"></A></TD></TR><TR><TDALIGN="LEFT"VALIGN="TOP"WIDTH="228">17.16. Restarting a Server on Demand</TD><TDALIGN="CENTER"VALIGN="TOP"WIDTH="228"><ACLASS="index"HREF="index/index.htm"TITLE="Book Index"><IMGSRC="../gifs/index.gif"ALT="Book Index"BORDER="0"></A></TD><TDALIGN="RIGHT"VALIGN="TOP"WIDTH="228">17.18. Program: fwdport</TD></TR></TABLE><HRALIGN="LEFT"WIDTH="684"TITLE="footer"><FONTSIZE="-1"></DIV<!-- LIBRARY NAV BAR --> <img src="../gifs/smnavbar.gif" usemap="#library-map" border="0" alt="Library Navigation Links"><p> <a href="copyrght.htm">Copyright © 2002</a> O'Reilly & Associates. All rights reserved.</font> </p> <map name="library-map"> <area shape="rect" coords="1,0,85,94" href="../index.htm"><area shape="rect" coords="86,1,178,103" href="../lwp/index.htm"><area shape="rect" coords="180,0,265,103" href="../lperl/index.htm"><area shape="rect" coords="267,0,353,105" href="../perlnut/index.htm"><area shape="rect" coords="354,1,446,115" href="../prog/index.htm"><area shape="rect" coords="448,0,526,132" href="../tk/index.htm"><area shape="rect" coords="528,1,615,119" href="../cookbook/index.htm"><area shape="rect" coords="617,0,690,135" href="../pxml/index.htm"></map> </BODY></HTML>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -