⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 close.html

📁 黑客培训教程
💻 HTML
📖 第 1 页 / 共 3 页
字号:
<html>

<head>

<title>Closing Open Holes</title>

<meta http-equiv="Content-Type" content="text/html; charset=windows-1250">

</head>



<body bgcolor="#000000" text="#CCCCCC" link="#99CCFF" vlink="#CC99FF" alink="#CCFF99" leftmargin="20" topmargin="0" marginwidth="20" marginheight="0">

<p align="center"><font size="5" color="#FFFFFF" face="Book Antiqua"><br>

  Closing Open Holes</font></p>

<p><br>

  <font face="Verdana, Arial, Helvetica" size=-2><b><br>

  </b><font face="Verdana, Arial, Helvetica" size=-2><font size="2" face="Arial, Helvetica, sans-serif"> 

  </font></font><font size="2" face="Arial, Helvetica, sans-serif"> </font><b><font size="2" face="Arial, Helvetica, sans-serif"> 

  </font></b><font size="2" face="Arial, Helvetica, sans-serif"> September 27, 

  2000</font></font><font size="2" face="Arial, Helvetica, sans-serif"><br>

  By <a href="mailto:ankit@bol.net.in">Ankit Fadia</a><br>

  <br>

  <span 

            style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">With 

  the spread of Hackers and Hacking incidents, the time has come, when not only 

  system administrators of servers of big companies, but also people who connect 

  to the Internet by dialing up into their ISP, have to worry about securing their 

  system. It really does not make much difference whether you have a static IP 

  or a dynamic one, if your system is connected to the Internet, then there is 

  every chance of it being attacked.</span></font><font size="2" face="Arial, Helvetica, sans-serif"> 

  </font> </p>

<p class=MsoNormal><font face="Arial, Helvetica, sans-serif" size="2"><span 

            style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">This 

  manual is aimed at discussing methods of system security analysis and will shed 

  light on as to how to secure your standalone (also a system connected to a LAN) 

  system.</span></font><font size="2" face="Arial, Helvetica, sans-serif"> </font> 

</p>

<p class=MsoNormal><font face="Arial, Helvetica, sans-serif" size="2"><span 

            style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><b><font color="#FFFFFF">Open 

  Ports: A Threat to Security?</font></b><font color="#FFFFFF"><br>

  </font> <br>

  In the <a 

            href="http://hackingtruths.box.sk/netstat.htm">Netstat Tutorial</a> 

  we had discussed how the netstat -a command showed the list of open ports on 

  your system. Well, anyhow, before I move on, I would like to quickly recap the 

  important part. So here goes, straight from the netstat tutorial:<br>

  <br>

  Now, the &#8216;&#8211;a&#8217; option is used to display all open connections 

  on the local machine. It also returns the remote system to which we are connected 

  to, the port numbers of the remote system we are connected to (and the local 

  machine) and also the type and state of connection we have with the remote system.</span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><o:p></o:p></span></font></p>

<p class=MsoNormal><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">For 

  Example,</span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><o:p></o:p></span></font></p>

<p class=MsoNormal><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">C:\windows&gt;netstat 

  -a</span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><o:p> 

  </o:p></span></font></p>

<p class=MsoNormal><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"> 

  Active Connections</span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><o:p><br>

  </o:p></span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">&nbsp; 

  Proto&nbsp; Local Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 

  Foreign Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 

  State<br>

  </span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">&nbsp; 

  TCP&nbsp;&nbsp;&nbsp; ankit:1031&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 

  dwarf.box.sk:ftp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 

  ESTABLISHED<br>

  </span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">&nbsp; 

  TCP&nbsp;&nbsp;&nbsp; ankit:1036&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 

  dwarf.box.sk:ftp-data &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 

  TIME_WAIT<br>

  </span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">&nbsp; 

  TCP&nbsp;&nbsp;&nbsp; ankit:1043&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 

  banners.egroups.com:80&nbsp;&nbsp;&nbsp; FIN_WAIT_2<br>

  </span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">&nbsp; 

  TCP&nbsp;&nbsp;&nbsp; ankit:1045&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 

  mail2.mtnl.net.in:pop3&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TIME_WAIT<br>

  </span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">&nbsp; 

  TCP&nbsp;&nbsp;&nbsp; ankit:1052&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 

  zztop.boxnetwork.net:80&nbsp;&nbsp; ESTABLISHED<br>

  </span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">&nbsp; 

  TCP&nbsp;&nbsp;&nbsp; ankit:1053&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 

  mail2.mtnl.net.in:pop3&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TIME_WAIT<br>

  </span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">&nbsp; 

  UDP&nbsp;&nbsp;&nbsp; ankit:1025&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 

  *:*<br>

  </span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">&nbsp; 

  UDP&nbsp;&nbsp;&nbsp; ankit:nbdatagram&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; *:*<br>

  </span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><![if !supportEmptyParas]><![endif]>&nbsp;<o:p></o:p></span></font></p>

<p class=MsoNormal><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">Now, 

  let us take a single line from the above output and see what it stands for:</span></font></p>

<p 

            class=MsoNormal><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><o:p></o:p></span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">Proto&nbsp; 

  Local Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Foreign 

  Address&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 

  State<br>

  </span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"> 

  TCP&nbsp;&nbsp;&nbsp; ankit:1031&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; 

  &nbsp;&nbsp;&nbsp; &nbsp;&nbsp; dwarf.box.sk:ftp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 

  &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ESTABLISHED</span></font></p>

<p 

            class=MsoNormal><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><o:p></o:p></span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">Now, 

  the above can be arranged as below:</span></font></p>

<p 

            class=MsoNormal><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><b><font color="#FFFFFF">Protocol:</font></b> 

  TCP (This can be Transmission Control Protocol or TCP, User Datagram Protocol 

  or UDP or sometimes even, IP or Internet Protocol.)</span></font></p>

<p 

            class=MsoNormal><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><b><font color="#FFFFFF">Local 

  System Name:</font></b> ankit (This is the name of the local system that you 

  set during the Windows setup.)</span></font></p>

<p class=MsoNormal><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">Local 

  Port opened and being used by this connection: 1031 </span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><![if !supportEmptyParas]><![endif]>&nbsp;<o:p></o:p></span></font></p>

<p class=MsoNormal><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><b><font color="#FFFFFF">Remote 

  System:</font></b> dwarf.box.sk (This is the non-numerical form of the system 

  to which we are connected.)</span></font></p>

<p 

            class=MsoNormal><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><b><font color="#FFFFFF">Remote 

  Port:</font></b> ftp (This is the port number of the remote system dwarf.box.sk 

  to which we are connected.)</span></font></p>

<p 

            class=MsoNormal><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><b><font color="#FFFFFF">State 

  of Connection:</font></b> ESTABLISHED</span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><o:p></o:p></span></font></p>

<p class=MsoNormal><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">&#8216;Netstat&#8217; 

  with the &#8216;&#8211;a&#8217; argument is normally used, to get a list of 

  open ports on your own system i.e. on the local system. This can be particularly 

  useful to check and see whether your system has a Trojan installed or not. Yes, 

  most good Antiviral software are able to detect the presence of Trojans, but, 

  we are hackers, and need to software to tell us, whether we are infected or 

  not. Besides, it is more fun to do something manually than to simply click on 

  the &#8216;Scan&#8217; button and let some software do it.</span></font></p>

<p 

            class=MsoNormal><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">The 

  following is a list of Trojans and the port numbers which they use, if you Netstat 

  yourself and find any of the following open, then you can be pretty sure, that 

  you are infected.<br>

  <br>

  </span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'"><o:p></o:p></span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">Port 

  12345(TCP)&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 

  Netbus<br>

  </span></font><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">Port 

  31337(UDP) &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 

  Back Orifice</span></font></p>

<p class=MsoNormal style="mso-layout-grid-align: none"><font size="2" face="Arial, Helvetica, sans-serif"><span style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">For 

  complete list, refer to the Tutorial on Trojans at: hackingtruths.box.sk/trojans.txt</span></font></p>

<font size="2" face="Arial, Helvetica, sans-serif">---- </font> 

<p></p>

<p class=MsoNormal><font face="Arial, Helvetica, sans-serif" size="2"><span 

            style="mso-ascii-font-family: 'Times New Roman'; mso-hansi-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'">Now, 

  the above tutorial resulted in a number of people raising questions like: If 

  the 'netstat -a' command shows open ports on my system, does this mean that 

  anyone can connect to them? Or, How can I close these open ports? How do I know 

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -