Salut à tous,
sur une SME Server 6.0.1-01, pour la description des services installés voici un ps -ef :
- Code: Tout sélectionner
root 1 0 0 Oct27 ? 00:00:06 init [7]
root 2 1 0 Oct27 ? 00:00:00 [keventd]
root 3 1 0 Oct27 ? 00:00:00 [kapmd]
root 4 1 0 Oct27 ? 00:00:00 [ksoftirqd_CPU0]
root 5 1 0 Oct27 ? 00:00:07 [kswapd]
root 6 1 0 Oct27 ? 01:04:32 [kscand]
root 7 1 0 Oct27 ? 00:00:00 [bdflush]
root 8 1 0 Oct27 ? 00:00:00 [kupdated]
root 9 1 0 Oct27 ? 00:00:00 [mdrecoveryd]
root 13 1 0 Oct27 ? 00:01:13 [kjournald]
root 104 1 0 Oct27 ? 00:00:00 [khubd]
root 317 1 0 Oct27 ? 00:00:00 [kjournald]
root 454 1 0 Oct27 tty2 00:00:00 /sbin/mingetty tty2
root 455 1 0 Oct27 tty3 00:00:00 /sbin/mingetty tty3
root 456 1 0 Oct27 ? 00:00:00 /usr/local/bin/svscan /service
root 487 456 0 Oct27 ? 00:00:00 supervise cvm-unix-local
root 488 456 0 Oct27 ? 00:00:00 supervise log
root 489 487 0 Oct27 ? 00:00:00 /usr/bin/cvm-unix-local /var/lib/cvm/cvm-unix-local.socket
cvmlog 490 488 0 Oct27 ? 00:00:00 /usr/local/bin/multilog t s5000000 /var/log/cvm
root 491 456 0 Oct27 ? 00:00:00 supervise qmail
root 492 456 0 Oct27 ? 00:00:00 supervise log
root 493 456 0 Oct27 ? 00:00:00 supervise smtpfront-qmail
root 494 456 0 Oct27 ? 00:00:00 supervise log
root 495 456 0 Oct27 ? 00:00:00 supervise dnscache
root 496 456 0 Oct27 ? 00:00:00 supervise log
root 497 456 0 Oct27 ? 00:00:00 supervise imap
root 498 456 0 Oct27 ? 00:00:00 supervise log
root 499 456 0 Oct27 ? 00:00:00 supervise dhcpcd
root 500 456 0 Oct27 ? 00:00:00 supervise log
root 501 456 0 Oct27 ? 00:00:00 supervise dhcpd
root 502 456 0 Oct27 ? 00:00:00 supervise log
root 503 456 0 Oct27 ? 00:00:00 supervise pppoe
root 504 456 0 Oct27 ? 00:00:00 supervise log
dnslog 505 496 0 Oct27 ? 00:00:00 /usr/local/bin/multilog t s5000000 /var/log/dnscache
qmaill 506 492 0 Oct27 ? 00:00:00 /usr/local/bin/multilog t s5000000 /var/log/qmail
imaplog 507 498 0 Oct27 ? 00:00:00 /usr/local/bin/multilog t s5000000 /var/log/imap
root 508 456 0 Oct27 ? 00:00:00 supervise nmbd
root 509 456 0 Oct27 ? 00:00:00 supervise log
qmaill 510 494 0 Oct27 ? 00:00:00 /usr/local/bin/multilog t s5000000 /var/log/smtpfront-qmail
smelog 511 500 0 Oct27 ? 00:00:00 /usr/local/bin/multilog t s5000000 /var/log/dhcpcd
root 512 456 0 Oct27 ? 00:00:00 supervise smbd
root 513 456 0 Oct27 ? 00:00:00 supervise log
root 514 456 0 Oct27 ? 00:00:00 supervise tinydns
root 515 456 0 Oct27 ? 00:00:00 supervise log
root 516 456 0 Oct27 ? 00:00:00 supervise popd
root 517 456 0 Oct27 ? 00:00:00 supervise log
qmaill 518 504 0 Oct27 ? 00:00:00 /usr/local/bin/multilog t s5000000 /var/log/pppoe
smelog 519 502 0 Oct27 ? 00:00:00 /usr/local/bin/multilog t s5000000 /var/log/dhcpd
dnslog 520 515 0 Oct27 ? 00:00:00 /usr/local/bin/multilog t s5000000 /var/log/tinydns
root 521 509 0 Oct27 ? 00:00:00 /usr/local/bin/multilog t s5000000 /var/log/nmbd
smelog 522 517 0 Oct27 ? 00:00:00 /usr/local/bin/multilog t s5000000 /var/log/popd
root 523 513 0 Oct27 ? 00:00:00 /usr/local/bin/multilog t s5000000 /var/log/smbd
root 540 1 0 Oct27 ? 00:00:21 syslogd -m 0
root 545 1 0 Oct27 ? 00:00:12 klogd -c 1 -2
nobody 705 1 0 Oct27 ? 00:00:00 /usr/sbin/oidentd -m -f -u nobody -g nobody
root 1269 1 0 Oct27 ? 00:00:00 [eth0]
root 1456 1 0 Oct27 ? 00:00:00 crond
root 1497 499 0 Oct27 ? 00:00:00 /bin/sh ./run
root 1503 1497 0 Oct27 ? 00:00:00 fghack dhcpcd -dCR eth1
root 1504 1503 0 Oct27 ? 00:00:00 [dhcpcd <defunct>]
root 1506 1 0 Oct27 ? 00:00:00 dhcpcd -dCR eth1
root 1549 1 0 Oct27 ? 00:00:00 xinetd -stayalive -pidfile /var/run/xinetd.pid
dnscache 1777 495 0 Oct27 ? 00:00:00 /usr/local/bin/dnscache
dns 1879 514 0 Oct27 ? 00:00:00 /usr/local/bin/tinydns
lp 1961 1 0 Oct27 ? 00:00:00 lpd Waiting
ldap 2095 1 0 Oct27 ? 00:00:00 /usr/sbin/slapd -u ldap
ldap 2096 2095 0 Oct27 ? 00:00:00 /usr/sbin/slapd -u ldap
ldap 2101 2096 0 Oct27 ? 00:00:00 /usr/sbin/slapd -u ldap
ntp 2136 1 0 Oct27 ? 00:00:00 ntpd -U ntp
ntp 2193 1 0 Oct27 ? 00:00:00 ntpd -U ntp
root 2263 1 0 Oct27 ? 00:00:01 httpd
root 2464 1 0 Oct27 ? 00:00:00 /usr/sbin/httpd-admin -f /etc/httpd/admin-conf/httpd.conf -D HAVE_PERL -D HAVE_PHP4 -D HAVE_PROXY -D HAVE_SSL -D HAV
root 2486 1 0 Oct27 ? 00:00:00 /bin/sh /usr/bin/safe_mysqld --defaults-file=/etc/my.cnf
mysql 2546 2486 0 Oct27 ? 00:00:00 /usr/libexec/mysqld --defaults-file=/etc/my.cnf --basedir=/usr --datadir=/var/lib/mysql --user=mysql --pid-file=/var
root 2617 512 0 Oct27 ? 00:00:00 /usr/sbin/smbd -F -S
root 2627 1 0 Oct27 ? 00:00:00 squid -D
squid 2629 2627 0 Oct27 ? 00:00:02 (squid) -D
root 2630 1 0 Oct27 ? 00:00:00 atalkd -f /etc/atalk/atalkd.conf
root 2658 508 0 Oct27 ? 00:00:00 /usr/sbin/nmbd -F -S
mysql 2660 2546 0 Oct27 ? 00:00:00 /usr/libexec/mysqld --defaults-file=/etc/my.cnf --basedir=/usr --datadir=/var/lib/mysql --user=mysql --pid-file=/var
mysql 2661 2660 0 Oct27 ? 00:00:00 /usr/libexec/mysqld --defaults-file=/etc/my.cnf --basedir=/usr --datadir=/var/lib/mysql --user=mysql --pid-file=/var
squid 2662 2629 0 Oct27 ? 00:00:00 (unlinkd)
mysql 2700 2660 0 Oct27 ? 00:00:00 /usr/libexec/mysqld --defaults-file=/etc/my.cnf --basedir=/usr --datadir=/var/lib/mysql --user=mysql --pid-file=/var
root 2701 1 0 Oct27 ? 00:11:00 /usr/bin/perl -w /usr/bin/sme6admind
root 2777 1 0 Oct27 ? 00:01:41 /usr/bin/perl -w /usr/sbin/sysmon
root 2847 1 0 Oct27 tty1 00:00:00 /sbin/mingetty tty1
root 2880 1 0 Oct27 ? 00:00:00 papd -f /etc/atalk/papd.conf
root 2885 1 0 Oct27 ? 00:00:00 afpd -c 20 -n fw-maisondieu -f /etc/atalk/AppleVolumes.default -s /etc/atalk/AppleVolumes.system -U uams_dhx.so,uams
snort 24794 1 0 Nov14 ? 00:00:04 /usr/sbin/snort -D -i eth1 -u snort -g snort -c /etc/snort/snort.conf
root 14525 1 0 10:35 ? 00:00:00 sshd: root@pts/0
root 14527 14525 0 10:35 pts/0 00:00:00 -bash
root 14762 1 0 10:47 ? 00:00:00 sshd: admin [priv]
admin 14769 14762 0 10:48 ? 00:00:00 sshd: admin@pts/1
root 14770 14769 0 10:48 pts/1 00:00:00 /usr/bin/perl -wT /dev/fd/3//sbin/e-smith/console
root 14771 14770 0 10:48 pts/1 00:00:00 /usr/bin/logger -p local1.info -t console
root 14775 14770 0 10:48 pts/1 00:00:00 /usr/bin/lynx -auth= -localhost -nopause -restrictions=all -rlogin -telnet localhost/common/noframes
www 16434 2263 0 11:40 ? 00:00:00 httpd
www 16435 2263 0 11:40 ? 00:00:00 httpd
www 16436 2263 0 11:40 ? 00:00:00 httpd
www 16437 2263 0 11:40 ? 00:00:00 httpd
www 16438 2263 0 11:40 ? 00:00:00 httpd
www 16439 2263 0 11:40 ? 00:00:00 httpd
www 16440 2263 0 11:40 ? 00:00:00 httpd
www 16441 2263 0 11:40 ? 00:00:00 httpd
www 16442 2263 0 11:40 ? 00:00:00 httpd
www 16513 2263 0 11:40 ? 00:00:00 httpd
root 16567 501 0 11:40 ? 00:00:00 /usr/sbin/dhcpd -d -f -cf /etc/dhcpd.conf -lf /var/lib/dhcp/dhcpd.leases -pf /var/run/dhcpd-eth0.pid eth0
root 16608 1 0 11:40 ? 00:00:00 /usr/sbin/sshd
root 16815 1 0 11:40 ? 00:00:00 /usr/sbin/pptpd -f
admin 16844 2464 0 11:40 ? 00:00:00 /usr/sbin/httpd-admin -f /etc/httpd/admin-conf/httpd.conf -D HAVE_PERL -D HAVE_PHP4 -D HAVE_PROXY -D HAVE_SSL -D HAV
admin 16855 2464 0 11:40 ? 00:00:00 /usr/sbin/httpd-admin -f /etc/httpd/admin-conf/httpd.conf -D HAVE_PERL -D HAVE_PHP4 -D HAVE_PROXY -D HAVE_SSL -D HAV
root 18314 14527 0 13:02 pts/0 00:00:00 ps -ef
Donc sur ce serveur, mon adresse ip est bannie.
Le port ssh est ouvert et je peux m'y connecter de n'importe quelle ip sauf la mienne.
Je ne peux même pas accéder aux pages web de base sur le port 80, encore moins au server-manager.
Je ne peux pas le pinger non plus alors que les autres le peuvent.
J'ai autoriser mon ip pour le remote management.
Qu'est-ce qui me bloque de la sorte ? je n'ai pas ajouté de règles particulières. Il y a snort qui m'a peut-être blacklisté ...?
Pouvez-vous m'aider ?