Home Map Index Search News Archives Links About LF
[Top Bar]
[Bottom
Bar]
[Photo of the
Author]
Javi Polo
§@ªÌ²¤¶¡G §Ú¤µ¦~¤Q¤K·³¡A ¦b¤E¤ë¤§«e¡A ¤´µM¬O Catalan ¾Ç®Õ¸Ì¡u·Î¼õ¤¤¡vªº¤¤¾Ç¥Í¡C ³Ì¤jªº¿³½ì¬O¹q¸£¬ì¾Ç¡A §Ú§Æ±æ¥Ó½Ð UIB ³q¹L¡A ¥H»²­×¹q¶Ç³q°T¡A ¨Ã¥D­×¹q¸£¬ì¾Ç¡C §Ú³ßÅwµw¿¶­µ¼Ö¡A ¨Ã¥B¥[¤J¤F¤@­Ó¥s°µ Niko-Chan's Kingdom ªº¼Ö¹Î¡C §Ú¦³­Ó«Ü¦nªº¤kªB¤Í¥s°µ Xiska¡A ¤j·§´N³o¼Ë¡A ¨S¨ä¥L¦n»¡ªº¤F 0:)

»P§@ªÌÁpô

TCPD »P¨Ï¥Î IPFWADM ¨Ó³]©w¨¾¤õÀð

[Ilustration]

¤º®eºK­n¡G ¥»¤å§ã­n¦a¤¶²Ð¡A ¦b¨t²Î¸Ì³]©w inetd ªA°È¡A ¥H¼W¶i¨t²Î¦w¥þªº¤èªk¡A §Ú­Ì§âµJÂI©ñ¦b IPFWADM ³o­Ó¨t²ÎºÞ²z¤u¨ã¡A ¥H¤Î inetd ªA°Èªº³]©w¤W­±¡C




­º¥ý¡A §Ú­Ì¥²¶·Âç²M¤°»ò¬O inetd¡C ²³æ¦a»¡¡A inetd ¬O¤@­Ó¦øªAµ{¦¡¡A ¥Î¥H±±¨î¥D¾÷³s¤Wºô¸ô®É¡A ©Ò´£¨Ñªº¦U¶µªA°È¡C ±z¦³¥i¯à·|¹J¨ì¤@³¡¹q¸£¡A ¨ä¹w³]ª¬ªp¨Ã¥¼³]©w¦n inetd ¨Ó±±¨î©Ò¦³ªºªA°È¡A ¦]¦¹¡A ²Ä¤@¥ó¨Æ¡A «K¬O§ä¥X /etc/inetd.conf ÀɮסA ¨ÃÀˬd¦³­þ¨Ç²{¦sªºªA°È¥Ñ¥¦±±¨î ( ¤]´N¬O¨S¦³ "#" ²Å¸¹¶}ÀYªº¨º´X¦æ¤º®e )¡C µ¹±zªº²Ä¤@­Ó©¾§i´N¬O¡A °£«D¯uªº»Ý­n³o¶µªA°È¡A ¤£µM¤d¸U§O±Ò°Ê¥¦¡A ¨º¨Ç±q¥¼¨Ï¥Îªº¦øªAµ{¦¡¸Ì¡A ¥i¯àÂ泯ä¦ä¡A ÁקK¦³¤H§Q¥Î¦¹Ãþº|¬}¤J«Iªº³Ì¦n¤èªk¡A ´N¬O¤£­n¥Î¥¦¡C °²³]ŪªÌ¤âÃ䦳¤@¥÷ inet.conf Àɮתº¤º®e¡A ±µ¤U¨Ó§Ú´N¸ÑĶ¤@¤U¸ÌÀYªº·N¸q¡C

Á|¨Ò¨Ó»¡¡A ¤U­±³o¤@¦æ¡G
ftp stream tcp nowait root /usr/sbin/tcpd in.ftpd -l -a

²Ä¤@­Ó¦r¬O©Ò´£¨ÑªºªA°È¦WºÙ ( ¥»¨Ò¤¤«üªº¬O "ftp"¡A §Ú­Ì¥i¥H¥t¥~¦b /etc/services Àɮ׸̡A ¬d¥X¥¦©Ò³sµ²ªº¬O­þ¤@­Ó°ð¸¹ )¡C

²Ä¤G­ÓÄæ¦ì¬O©Ò¶}±Òªº socket Ãþ«¬¡A¥¦¥i¥H¬O¡G stream ( ¦p¥»¨Ò§Y¬O )¡B dgram¡B raw¡B rdm¡B ©Î seqpacket¡C

±µ¤U¨ÓªºÄæ¦ì¬O©Ò¨Ï¥Îªº³q°T¨ó©w¡A ±z¥²¶·¥ý¦b /etc/protocols Àɮפ¤«Å§i¡A ¦b«e¨Ò¤¤¡A §Ú­Ì°²©w±z¤w¸g¦b¦¹Àɸ̫ŧi¤F TCP ³q°T¨ó©w¡C

¦b³q°T¨ó©w¤§«á¡A ±µµÛ¬O wait/nowait ªºÄæ¦ì¡C °£¤F datagram (dgram) Ãþ«¬¤§¥~ªº socket¡A ¨ä¥L³£À³¸Ó¬O nowait¡A ¦Ü©ó datagram Ãþ«¬ªº socket¡A ¦pªG¦øªAµ{¦¡¤ä´©¦h°õ¦æºü¡A ¨º»ò§Ú­ÌÀ³¸Ó³]©w nowait¡A ¦pªG¦øªAµ{¦¡¶È¤ä´©³æ¤@°õ¦æºü¡A ¨º»ò½Ð³]©w¬° wait¡C ­ì¦]¬O¦h°õ¦æºü¨t²Î¡A ·í¨ä¦¬¨ì³s½u­n¨D®É¡A ¥¦·|±Ò°Ê¤@­Ó·sªº process¡A µM«á¦A§â­ì¥»ªº socket ÄÀ©ñ±¼¡A Åý inetd ¥i¥HÄ~Äò listen ¨ä¥Lªº³s½u­n¨D¡A ¦]¦¹­n¨Ï¥Î nowait¡C ¦b³æ¤@°õ¦æºü¨t²Îªº³õ¦X¡A «h»Ý­n³]©w¬° wait¡A ¦]¬°¦øªAµ{¦¡·|¤@ª½¦uµÛ¦P¤@­Ó socket¡A ¦Ó¤£¯à¥t¥~²£¥Í process ¥H¨Ñ³sµ²¡C °£¦¹¤§¥~¡A ÁÙ¦³¤@¨Ç®æ¦¡¤WªºÅܤơA §Ú­Ì¥i¥H¼g¦¨ nowait.50 ¡Ð¡Ð ¥Nªíµu®É¶¡¤º¡A ³Ì¦h¥i¥H±Ò°Ê 50 ­Ó¦øªAµ{¦¡ ( ±q¥t¤@­Ó¨¤«×¨Ó¬Ý¡A ©ÎªÌ¥i¥H»¡¡A ¬O±µ¨ü³o»ò¦h­Ó³s½u­n¨D )¡C ¨ä¹w³]­È¬O 40 ­Ó¡C

²Ä¤­­ÓÄæ¦ì¡A «ü©ú¤F¦øªAµ{¦¡¡A ¬O¥H­þ¦ì¨Ï¥ÎªÌªº¦WºÙ¨Ó°õ¦æ¡A ¦b³o­Ó¨Ò¤l¤¤¡A ftp ¬O¥H root ³o­Ó¨Ï¥ÎªÌ¦WºÙ¨Ó°õ¦æ¡C

²Ä¤»­Ó¥H¤Î±µ¤U¨ÓªºÄæ¦ì¡A «K¬O°õ¦æªºµ{¦¡»P¨ä©Ò±µªº°Ñ¼Æ¤F¡C ¦b§Ú­Ìªº¨Ò¤l·í¤¤¡A ¦øªAµ{¦¡ tcpd ³Q±Ò°Ê¡A «áÀY±µ¤F¦øªAµ{¦¡ in.ftpd »P -l -a ¬°°Ñ¼Æ¡C ±µ¤U¨Ó¡A §Ú­Ì´N­n¨Ó½Í½Í³Ì¦³½ìªº³¡¥÷¡A TCPD ªº³]©w°ÝÃD¡C

¶â¡A tcpd ¬O­Ó¥Î¨Ó¹LÂo³s½u­n¨Dªº¦øªAµ{¦¡¡A ¥¦·|®Ú¾Ú­þ­Ó¦øªAµ{¦¡§Y±N³Q±Ò°Ê¡A ¨Ó¨M©w°µ­þ¨Ç¨Æ¡A ¥H¦V´£¥X³o¨Ç³s½u­n¨Dªº IP ¦ì§}¡A °µ¥X¦^À³ªº°Ê§@¡C ¦Ó¨s³º·|«ç»ò°µ¨M©w¡A «hµø /etc/hosts.allow »P /etc/hosts.deny ³o¨â­ÓÀɮצp¦ó³]©w¡C

­ì«h¤W¡A /etc/hosts.deny Àɮ׬O¥Î¨Ó«ü©w©Úµ´¦V­þ¨Ç¥D¾÷´£¨ÑªA°È¡A ¦Ó /etc/hosts.allow Àɮ׫h¬O¥Î¨Ó«ü©w¤¹³\¦V­þ¨Çɧ¾÷´£¨ÑªA°È¡C

³o¨â­ÓÀɮתº³]©w®æ¦¡¦p¤U¡G
DAEMON: IP[: OPTION1 [: OPTION2 ]]

¤W­zªº DAEMON¡A ¥i¥H¬O·Q­n±Ò°Êªº¦øªAµ{¦¡¦WºÙ¡A ¦p«e¨Ò¤¤©Ò¥Üªº in.ftpd¡A ©ÎªÌ¬O ALL ³o­Ó¦r¡A ¥¦¥NªíµÛ©Ò¦³ªº¦øªAµ{¦¡¡C

IP ¥i¥H¬O¬Y­Ó¯S©wªº IP¡A ©Î¬O¬Y­Ó URL¡A ©Î¬O¬Y¤@½d³òªº IP ( ©Î URL )¡A ©ÎªÌ¬Oµ¥¤@¤U·|¸ÑÄÀ¨ìªº¸U¥Î¦r¡C

¬°¤F¯à°÷«ü©w¬Y¤@½d³òªº IP ¦ì§}¡A ¨Ò¦p»¡¡A §Ú­Ì¥i¥H³o¼Ë¼g¡G `123.32'¡A ³o­Óªí¥Ü¤è¦¡¡A ¥Nªí¤F 123.32.XXX.XXX ªº©Ò¦³ IP¡A ¦P¼Ë¦a¡A ¹³ `.ml.org' ¥i¥H¥Î¨Ó«ü©w¬Y¤@½d³òªº URL¡A ¥¦¥Nªí©Ò¦³ ml.org ©³¤Uªº¤lºô¸ô¡C

¥H IP/MASK ¤§®æ¦¡¨Ó«ü©w¬Y¤@½d³òªº IP¡A «h¬O§ó¬°¶Ç²Îªº¤èªk¡A Á|¨Ò¨Ó»¡¡A ±q 127.0.0.0 ¨ì 127.0.255.255¡A ¦¹¤@½d³òªº IP ¥i³Q«ü©w¬° 127.0.0.0/255.255.0.0

«e­±´£¨ìªº¸U¥Î¦r¦³¡G
ALL ¥NªíÀɮ׸̡A ©Ò¦³¥i¯àªº¼Æ­È³£¬O¤¹³\ªº
LOCAL ·|²Å¦X¨ì©Ò¦³¦WºÙ¸Ì¨S¦³ ^Ó.^Ô ªº¥D¾÷
UNKNOWN ¥Nªí©Ò¦³¦WºÙ©Î IP ¦ì§}¬°¥¼ª¾ªº¥D¾÷
KNOWN ¥Nªí©Ò¦³¦WºÙ¤Î IP ¦ì§}§¡¬°¤wª¾ªº¥D¾÷
PARANOID ¥Nªí©Ò¦³¦WºÙ»P IP ¦ì§}¨Ã¤£¤@­Pªº¥D¾÷

«e­±´£¨ìªº¿ï¶µ¦³¡G

allow ¤£ºÞ hosts.allow »P hosts.deny Àɮ׸̪º³]©w¬°¦ó¡A ²Å¦X¦¹¤@³]©w±ø¥óªÌ¡A ³£±µ¨ü¨ä³s½u­n¨D¡C ³o­Ó¿ï¶µ³]©w¡A À³¸Ó¸m©ó¸Ó¦æªº³Ì«á­±¡C
deny Ãþ¦ü¤W­±ªº¿ï¶µ³]©w¡A ¤£¹L¡A ¥¦¬O¥Î¨Ó«ü©w©Úµ´³s½uªº±ø¥ó¡C
spawn ·í¦¬¨ì³s½u­n¨D®É¡A ·|±Ò°Ê¤@­Ó©R¥O´ßªº«ü¥O¡A Ä´¦p»¡¡A ¥i¥H¦b¨C¦¸¦³¤H·Q­n±q¥~­±¡A ³s¶i§Úªº¾÷¾¹®É¡A °õ¦æ¤@­Ó¹ÍÁn³qª¾¡C
twist ³o­Ó©M spawn ¿ï¶µÃþ¦ü¡A ¤£¹L¡A ·í©R¥O´ß«ü¥O°õ¦æ§¹²¦«á¡A ³s½uª¬ºA«K·|¤¤Â_¡C ¦¹¤@¿ï¶µ¡A ¦P¼Ë¥²¶·¸m©ó³]©w¦æªº³Ì«á­±¡C

¤W­zªº³Ì«á¨â­Ó¿ï¶µ¡A ÁÙ¥i¥H°t¦X¾A·íªºÂX¥R¦r¤¸µ¹ tcpd ¨Ï¥Î¡A ³o¨ÇÂX¥R¦r¤¸¦³¡G

%a «È¤áºÝ¥D¾÷ªº¦ì§}
%c «È¤áºÝªº¸ê°T ( ¥i¯à¬O¹³ user@machine¡A ©Î¬O¨ä¥L¥Ñ«È¤áºÝ©Ò±oªº¸ê°T )
%d
%h ¦b¥i¥H¨ú±oªº±¡ªp¤U¡A ³o·|¥Nªí«È¤áºÝªº¦WºÙ©Î IP ¦ì§}
%n «È¤áºÝªº¦WºÙ
%p ¦øªAµ{¦¡ªº PID
%s ¦øªAºÝªº¸ê°T ( ¨Ò¦p daemon@machine ©Î¥u¦³ daemon ¤§¸ê°T¡A µø±¡ªp¦Ó©w )
%u «È¤áºÝ¨Ï¥ÎªÌªº¦WºÙ
%% ³o¬Oªí¥Ü % ³o­Ó¦r¤¸

°t¦X³o¨ÇÂX¥R¦r¤¸»P¿ï­¶¡A ±z¤w¸g¥i¥H°µ«Ü¦h¨Æ¤F¡A ¨Ò¦p¡A §Úª¾¹D¦³¤H³]©w¦¨¡A ¤@¥¹¦³¤H·Q­n¸g¥Ñ telnet ³s¶i¥Lªº¥D¾÷¡A «K¦Û°Ê°e¥X¤@­Ó teardrop §ðÀ» :)

ªþµù¡G teardrop ¬O¤@ºØ Dos ( Denial of Service¡A ·|³y¦¨¨t²Î­«·s¶}¾÷¡A ©Î­«·s°_©l¤Æªº§ðÀ»¤è¦¡ )¡C ¥¦¬O¦]¬° TCP «Ê¥]­«²Õ®Éªº¯ä¦ä¦Ó°_¡A ¦h¼Æªº§@·~¨t²Î³£¦³³o­Ó°ÝÃD ( ©ÎªÌ»¡¡A ¥H©¹ªº§@·~¨t²Î¬O¦p¦¹¡A ¦]¬°³\¦hªº®Ö¤ßµ{¦¡¤w¸g°w¹ï¦¹°ÝÃD¡A ¥[¥H­×¥¿¤F )¡A ¦b InterNet ¤Wªº¸ê®Æ¡A ¬O³z¹L TCP/IP ³q°T¨ó©w¨Ó¶Ç°e ( ¦¹¤@³q°T©w¡A ¦b¨ä¥LÃþ«¬ªººô¸ô¤W¤]¥i¥H¬Ý¨ì¡A Ä´¦p¹³ intranet ´N¬O )¡A ¹ê»Ú¤W¡A ¥¦¬O¨âºØ³q°T¨ó©w¡G TCP ­t³d±N¸ê®Æ¡A ¥[¥H¤À³Î¦¨¤@¬q¬qªº«Ê¥]¡A µM«á¦A§â¥¦¶Çµ¹ IP ³q°T¨ó©w¡A ¥Ñ¥¦°e©¹¥Øªº¦a¡F ¤@¥¹¸ê®Æ°e¹F¥Øªº¥D¾÷«á¡A TCP ³q°T¨ó©w·|Àˬd¡A ¬O§_©Ò¦³«Ê¥]³£§¹¾ã¡A µM«á¦A±N¥¦­Ì­«²Õ¦¨­ì¥»ªº¸ê®Æ¡C µM¦Ó¡A ¤W­z ( ¥H¤Î³\¦h®Ú¾Ú¦¹¤@­ì²z ) ªº§ðÀ»¤è¦¡¡A §Q¥Î¦h¼Æªº§@·~¨t²Î¡A ¦b­«²Õ«Ê¥]¤§«e¡A ¤£·|Àˬd«Ê¥]¹L¤pªº°ÝÃD¡A ¦]¦¹¡A ³o¼Ëªº¾÷¾¹¦b­«²Õ«Ê¥]«á¡A ´N·|µo¥Í¿ù¶Ãªºª¬ªp¡C ÅãµM¦a¡A ¹ï¦¹¦b¤U¨Ã¤£½T©w«ç¼Ë¤~¬O§¹¾ãªº¸ÑÄÀ¡A ¦]¦¹Åwªï¤j®a´£¥X¦U¦¡§åµû»P«ü±Ð¡C ¦nªº¡A ¸g¹L¤W­zªºÂ²µu¸ÑÄÀ«á¡A Åý§Ú­ÌÄ~Äò...

½d¨Ò¡G
#hosts.allow 

ALL: 127.0.0.1 # ¤¹³\ localhost ¶i¤J°µ©Ò¦³¨Æ

in.ftpd: ALL: spawn (wavplay /usr/share/sounds/intruder.wav & )
# Åý©Ò¦³¤H³£¥i¥H³z¹L ftp ¶i¤J¡A
# ¦ý·|±Ò°Ê¤@­ÓÁn­µÀÉ ( ¦]¦¹¥¦¥i¥Hĵ§i§Ú )

in.telnetd:  ALL: twist ( teardrop %h %h )
# ©Ò¦³¤H·Q­n³z¹L telnet ªº¸Ü¡A
# °e¦^¤@­Ó teardrop ªº§ðÀ»

#fin
#hosts.deny

ALL: `.bsa.org'   # ¸T¤î¨Ó¦Û bsa.org ºô°ìªº©Ò¦³³s½u

in.fingerd: ALL	  # ¸T¤î©Ò¦³ªº fingerd ªA°È :)

#fin

Ãö©ó tcpd¡A §Ú·Q»¡ªº´N¬O³o¨Ç¤F¡A ¦]¬°©Ò¾Ç¦³­­¡A ¥i¯àÁ¿±o¤£°÷¦n¡C ¦b¤Uªº«Øij¬O¡A ¸ÕµÛ¥h¹êÅç¤@¨Ç³]©w¶µ¥Ø¡A ¨Ã¥B¼ôŪ½u¤W¤â¥U ( tcpd, host_acess(5) ªº manual pages )¡A ¬Û«HŪªÌ¥i¥H¾Ç±o¤ñ§Ú©Ò±ÐªºÁÙ­n¦h¡C

±µ¤U¨Ó¡A Åý§Ú­Ì¶i¤J IPFWADM ¤u¨ãµ{¦¡ªº³¡¤À¡C

­º¥ý¡A ¤£¥i©Î¯Êªº¬O¡A ­n§â®Ö¤ßµ{¦¡¤¤¡A ¦³Ãö IP Firewalling ªº¤ä´©¥[¤J ( Networking -> Network firewalls + IP: firewalling )¡C ±µ¤U¨Ó¡A ­«·s½sĶ¤Î¨t²Î­«·s¶}¾÷«á¡A §Ú­Ì´N·Ç³Æ¦n¥i¥H¨Ï¥Î³o­Ó¤u¨ã¤F¡C

IPFWADM ¥i¥HÅý§Ú­ÌºÞ²z¬Y¨Çµ{¦¡ ( ³o¨ÇÀ³¥Îµ{¦¡¡A ¨Ã¤£­­©ó§Ú¦b¥»¤å¤¤©Ò¤¶²Ðªº )¡A ¨ä TCP¡B UDP¡B ICMP «Ê¥]ªº¶i¥Xª¬ªp¡C ²³æ¦a»¡¡A ºÞ²z­û¥i¥H³W©w­þ¨Ç«Ê¥]¤~¤¹³\¶i¤J¡A ¥i¥H«ü©wªº±ø¥ó¥]¬A¡G ¨Ó¦Û©ó¬Y­Ó IP¡B ©Î¬Y¬q IP ½d³òªº¥D¾÷¡A ­þ¤@­Ó¯S©wªº°ð¸¹¡A ­þ¤@ºØ¯S©wªº³q°T¨ó©w¡A ©Î¬O¤W­z¦UºØ±ø¥óªº²Õ¦X... ¦P¼Ë¦a¡A ¹ï©ó·Ç³Æ°e©¹¥D¾÷¥~ªº«Ê¥]¡A §Ú­Ì¤]¥i¥H¨ã¦³¬Û¦Pµ{«×ªººÞ²z±±¨î¡C

ipfwadm ¦³´XºØ¥D­nªº°Ñ¼Æ¡G

  • -A «ü©w°O¿ý (accounting) ¤§³B²z¤è¦¡
  • -I «ü©w·Ç³Æ¶i¤J¥D¾÷¤ºªº«Ê¥] (incoming packets) ¤§³B²z¤è¦¡
  • -O «ü©w·Ç³Æ°e©¹¥D¾÷¥~ªº«Ê¥] (outgoing packets) ¤§³B²z¤è¦¡
  • -F «ü©w«Ê¥]Âà°e (forwarding) ¤§³B²z¤è¦¡
  • -M ¥Î¨Ó¶i¦æ IP masquareding ªººÞ²z

¥»¤å¤¤¡A §Ú¥u¥´ºâ¤¶²Ð -I »P -O °Ñ¼Æ¡A ¥¦­Ì¨âªÌ³£¨ã¦³¬Û¦Pªº»yªk¡C

³o¨Ç°Ñ¼Æªº¿ï¶µ¦³¡G

  • -a ¦bªí³æ«á­±¥[¶i¤@­Ó©Î¦h­Ó³B²z¤è¦¡
  • -i ¦bªí³æ«e­±¥[¤J¤@­Ó©Î¦h­Ó³B²z¤è¦¡
  • -d ±qªí³æ¸Ì­±§R°£¤@­Ó©Î¦h­Ó³B²z¤è¦¡
  • -l Åã¥Üªí³æ¤W­±ªº³B²z¤è¦¡
  • -f §R°£ªí³æ¤W­±©Ò¦³ªº³B²z¤è¦¡
  • -p «ü©w­þ¨Ç«Ê¥]¤@©w³Q acceppted (a)¡B denied (d) ©Î rejected (r)
  • -c Àˬd¬Y­Ó«Ê¥]·Ç³Æ¶i¤J®É¡A ¨äÀ³¥Î­þ¨Ç³B²z¤è¦¡
  • -h »²§U»¡©ú
­«­nªº°Ñ¼Æ¦³¡G

-P «ü©w¬Y­Óªí³æ¤W¡A ³B²z¤è¦¡©Ò§@¥Î¨ìªº³q°T¨ó©w¡C ³o¸Ìªº³q°T¨ó©w¡A ¥i¥H¬O TCP¡B UDP¡B ICMP ©Î all ( ªí¥Ü©Ò¦³ªº³q°T¨ó©w )
-S «ü©w«Ê¥]ªº¨Ó·½¦ì§}¡C ¨ä®æ¦¡¬°¡G ADDRESS[/MASK] [PORT]   Á|¨Ò¨Ó»¡¡A ¹³³o¼Ë 123.32.34.0/255.255.255.250 25 «K¥Nªí±q 123.32.34.0 ¨ì 123.32.34.5 ªº IP ½d³ò
-D «ü©w«Ê¥]ªº¥Øªº¦ì§}¡A ¨ä®æ¦¡»P -S ¬Û¦P

­ì«h¤W¡A ³o¨Ç³£¬O³Ì°ò¥»ªº°Ñ¼Æ¡A ¦]¦¹¡A ·Q­nÅý©Ò¦³±q§Úªº¹q¸£µo¥Xªº«Ê¥]¡A ¯à°÷¨ì¹F§Ú¦Û¤vªº¹q¸£¡A ¥i¥H³o¼Ë³]©w³B²z¤è¦¡¡G

ipfwadm -I -i a -S 127.0.0.1

ÁÙ·Q­n¾×±¼¨Ó¦Û©ó 123.34.22.XXX ªº«Ê¥]¡A ¥i¥H³o¼Ë³]©w¡G

ipfwadm -I -a d -S 123.34.22.0/255.255.255.0

±µ¤U¨Ó¡A ¦pªG°£¤F 111.222.123.221 ³o­Ó IP ¤§¥~¡A §Ú·Q­n¾×±¼©Ò¦³¨ä¥L¹ï©ó netbios °ð¸¹ªº³s½u­n¨D¡A ¥i¥H³o¼Ë³]©w¡G

ipfwadm -I -a a -P tcp -S 111.222.123.221 139
ipfwadm -I -a d -P tcp -D 0.0.0.0/0 139

¦n§a¡A §Ú·Q³o´N¬O¤å³¹ªº¥þ³¡¤F¡A ¼g±o¦³ÂI¤£¦n¡A ©Ò¾Ç¤£ºëÅo O:)


¥»¤å¥Ñ Penelope Marr ©Ò½Ķ

¥Dºô¯¸¥Ñ Miguel Angel Sepulveda ºûÅ@
© Javi Polo 1998
LinuxFocus 1998