VIrus
\
Ping ke dns ada tanda aneh. ada apa kira?
statistic table route tidak kelaur apa2.
so kesimpulannya ada spyware apa virus
regard
Filed under: Advisories | 3 Comments »
\
Ping ke dns ada tanda aneh. ada apa kira?
statistic table route tidak kelaur apa2.
so kesimpulannya ada spyware apa virus
regard
Filed under: Advisories | 3 Comments »
[root@proxies rkhunter]# cat /etc/squid/squid.conf
http_port 8080
#icp_port 3130
icp_query_timeout 0
maximum_icp_query_timeout 5000
mcast_icp_query_timeout 2000
dead_peer_timeout 10 seconds
hierarchy_stoplist cgi-bin ? localhost
acl QUERY urlpath_regex cgi-bin \? localhost
Filed under: Linux, Router | 7 Comments »
Hardware
1. PROLINK Load Balancing
2. Mikrotik
3. Proxy
1. Prolink
Filed under: Warnet | 6 Comments »
Jan 3 04:17:35 router portsentry[336]: attackalert: Connect from host: bob.esthost.eu/195.5.116.234 to TCP port: 1080
Jan 3 04:17:35 router portsentry[336]: attackalert: Host 195.5.116.234 has been blocked via wrappers with string: “ALL: 195.5.116.234″
Jan 3 04:17:35 router portsentry[336]: attackalert: Host 195.5.116.234 has been blocked via dropped route using command: “route add -net 195.5.116.234 -netmask 255.255.255.255 127.0.0.1 -blackhole”
Jan 3 04:19:11 [...]
Filed under: Warnet | 2 Comments »
Hardware
1. 2 modem adsl
modem a 192.168.5.1/24
modem b 192.168.4.1/24
2. Load Balancing 2 wan and 4 lan (192.168.1.1/24)
wan ip modem a 192.168.5.2/24
wan ip modem b 192.168.4.2/24
3. Mikrotik with pc using 2 etnertnet
Local –>> 192.168.0.30/27
Public ->> 192.168.1.2/24
4. linux proxy using 1 ethernet ( 192.168.1.3/24)
Filed under: Linux, Mikrotik, Router, Warnet | 4 Comments »
Pendapatan warnet salah satu pelanggan speedy. warnet pelanggan dengan paket office unlimited. jumlah pc client 12 . dengan harga 1 jamnya Rp 3.500. cukup menjanjikan. nih pelanggannya mau nambah pc dengan nambah speedy 2 lagi untuk perluasan areal usaha.
regard
Filed under: Warnet | 6 Comments »
> cat portsentry.history
1199380689 - 01/03/2008 17:18:09 Host: bob.esthost.eu/195.5.116.234 Port: 1080 TCP Blocked
1199381847 - 01/03/2008 17:37:27 Host: bin.esthost.eu/195.5.116.238 Port: 1080 TCP Blocked
1199383844 - 01/03/2008 18:10:44 Host: 122-116-112-161.HINET-IP.hinet.net/122.116.112.161 Port: 1080 TCP Blocked
1199394885 - 01/03/2008 21:14:45 Host: 122-118-96-124.dynamic.hinet.net/122.118.96.124 Port: 1080 TCP Blocked
1199402107 - 01/03/2008 23:15:07 Host: 80.subnet125-162-100.speedy.telkom.net.id/125.162.100.80 Port: 79 TCP Blocked
1199403908 - 01/03/2008 23:45:08 Host: swiftco.irc.proxy.monitor.dal.net/208.99.203.190 Port: 1080 [...]
Filed under: Advisories | 2 Comments »
Jan 3 04:17:35 router portsentry[336]: attackalert: Connect from host: bob.esthost.eu/195.5.116.234 to TCP port: 1080
Jan 3 04:17:35 router portsentry[336]: attackalert: Host 195.5.116.234 has been blocked via wrappers with string: “ALL: 195.5.116.234″
Jan 3 04:17:35 router portsentry[336]: attackalert: Host 195.5.116.234 has been blocked via dropped route using command: “route add -net 195.5.116.234 -netmask 255.255.255.255 127.0.0.1 -blackhole”
Jan 3 04:19:11 [...]
Filed under: Advisories, Berita | No Comments »
source from sentot
a. Device Configutarion
> cat /etc/rc.conf
sshd_enable=”YES”
fsck_y_enable=”YES”
gateway_enable=”YES”
natd_interface=”tun0″
ifconfig_xl0=”up”
ifconfig_xl1=”inet 192.168.10.10 netmask 255.255.255.0″
hostname=”router.yourhostname”
ppp_enable=”YES”
ppp_mode=”ddial”
ppp_profile=”speedy”
ppp_nat=”YES”
Filed under: BSD, Router | No Comments »
[admin@Net4501] ip firewall rule input> pr
Flags: X - disabled, I - invalid, D - dynamic
0 ;;; Drop TCP Invalid packets
in-interface=Internet connection-state=invalid action=drop log=yes
1 ;;; Drop spoofed packets
src-address=192.168.1.0/24 in-interface=Internet action=drop log=yes
2 ;;; Permit local LAN traffic
in-interface=Internal action=accept
Filed under: Linux, Router | No Comments »
dari id makan di ForumMikrotik.com di coba aja mungkin ada yang bisa di pakai
/ ip firewall filter
add chain=input action=drop connection-state=invalid comment=”Drop invalid connections” disabled=no
add chain=input action=accept connection-state=established comment=”Allow established connections” disabled=no
add chain=input action=accept protocol=udp comment=”Allow UDP” disabled=no
add chain=input action=accept protocol=icmp comment=”Allow ICMP” disabled=no
add chain=input action=accept in-interface=!Public comment=”Allow connection to router from local network” disabled=no
add chain=input [...]
Filed under: Mikrotik, Router | 4 Comments »