Türkce » WHM cPanel

Netstat Nedir ve Nasil Kullanilir?

http://forum.whmdestek.com/

Go Back   WHM/cPanel Support Platform » Türkce » WHM cPanel
 

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 21.07.08, 00:10
Ni-Osman's Avatar
Linux HelpDesk
 
Join Date: Feb 2008
Location: Denizli
Posts: 284
Rep Power: 7018
Ni-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond repute
Send a message via MSN to Ni-Osman Send a message via Yahoo to Ni-Osman Send a message via Skype™ to Ni-Osman
Netstat Nedir ve Nasil Kullanilir?

Netstat konusunda kisa giris bilgileri verecegim. Netstat (network statistics) Network baglantilari, routing tablosu, ara birim istatistikleri ve benzeri ag baglantisi bilgileri ile ilgili ayrintili bilgiler verebilen bir konsol komutudur.

Netstat komutu cesitli parametrelerle kullanilmaktadir. Bu parametrelerin anlamlari sunlardir:

-a Tüm TCP ve UDP baglantilari ekrana basar
-e Gelen ve giden paket sayisini istatistiklerini görüntüler
-n Tüm baglantilari rakamsal olarak görüntüler
-o Tüm baglantilari PID numarasi ve uygulama adina göre listeler
-p Baglantilarin kullandigi uygulama ve PID numarasini ekrana basar
-s Kurallara göre istatistiksel verileri ekrana basar
-r IP Yönlendirme tablosunu icerigini görüntüler.

Netstat ciktisinda yer alan baglanti durumlarinin anlamlari da sunlardir:

ESTABLISHED : Soket baglanti gerceklestirmis durumdadir.
SYN_SENT : Soket baglanti kurmaya calisiyordur.
SYN_RECV : Agdan bir baglanti istegi gelmistir.
FIN_WAIT1 : Soket kapatilmis , baglanti sonlandirilmak üzeredir.
FIN_WAIT2 : Baglanti sonlandirilmistir. Soket karsi ucun baglantiyi sonlandirmasini beklemektedir.
TIME_WAIT : Soket kapndiktan sonra gelebilecek paketleri alabilmek icin beklemektedir.
CLOSED : Soket kullanilmamaktadir.
CLOSE_WAIT : Karsi uc baglantiyi kapatmistir. Soketin kapanmasi beklenmektedir.
LAST_ACK : Karsi uc baglantiyi sonlandirmis ve soketi kapatmistir. Onay beklenmektedir.
LISTEN : Soket gelebilecek baglantilar icin dinleme konumundadir.
CLOSING : Yerel ve uzak soketler kapatilmis fakat tüm verilerini göndermemis durumdadirlar. Tüm veriler gönderilmeden soketler kapanmazlar.

SSH üzerinde netstat ciktilarini almak icin bazi örnek komutlar..

netstat -ntu


tüm TCP ve UDP baglantilari listeler (rakamsal olarak)

netstat -ntu | grep SYN


tüm TCP ve UDP baglantilar icinde SYN_SENT ve SYN_RECV baglanti durumlarini ekrana basar

grep sonrasinda yer alan kismi kendi isteginize göre degistirebilirsiniz. Örnek komut yazacak olursak

netstat -ntu | grep ESTABLISHED


ekrana sadece ESTABLISHED olan baglanti durumlarini basar..

netstat -ntu | awk '{print $5}' | awk '{sub("::ffff:","");print}' | cut -f1 -d ':' | sort | uniq -c | sort -n | grep -v -e server -e Address -e 127.0.0.1 -e 0.0.0.0


Yukarida yer alan komut ffff tablosu ile ekrana basilan degerler dahil tüm ip listesini kücükten büyüye göre siralar. Yine komuta grep ekleyerek baglanti durumuna göre listeleme yapabiliriz.

for i in $(netstat -ntu | awk '{print $5}' | awk '{sub("::ffff:","");print}' | cut -f1 -d ':' | sort | uniq -c | sort -n | grep -v -e server -e Address -e 127.0.0.1 -e 0.0.0.0 | awk '{ if ($1 > 30) print $2 }'); do /usr/sbin/csf -d $i;done


Yukarida yer alan komut ise 30 rakamindan büyük baglanti sayisi olusturan tüm ipleri csf firewall yazilimi araciligi ile banlayarak sunucudan uzaklastirilir. Son awk yaziliminda yer alan 30 degerini yükselterek limiti arttirabilir yine netstat sonrasi grep ekleyerek siralamayi belirli baglanti durumlarina göre listeleyebilirsiniz.

netstat ile bunun disinda bircok yaziliminizin istatistik toplayarak kullanacagi en yararli ag komutlarindan biridir.

netstat ile ilgili sormak istediklerinizi yazabilirsiniz.

iyi calismalar.

Netstat Nedir? Nasıl Kullanılır? | linux10.net
__________________
Netinternet'i sosyal paylaşım ağlarından takip edin kampanyalardan ilk haberi siz alın!!
Facebook | twitter | friendfeed
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2  
Old 21.07.08, 00:13
Ni-Osman's Avatar
Linux HelpDesk
 
Join Date: Feb 2008
Location: Denizli
Posts: 284
Rep Power: 7018
Ni-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond repute
Send a message via MSN to Ni-Osman Send a message via Yahoo to Ni-Osman Send a message via Skype™ to Ni-Osman
Konu ile ilgili

netstat -nap | grep httpd

yazmaniz durumunda elde edilecek PID numaralarini apache status üzerinde aratarak hangi ip adresinin hangi siteye girdigini kolayca bulabilirsiniz.

cok fazla istek yapan 10.0.0.7 ip sini

netstat -nap | grep 10.0.0.7 | grep httpd

seklinde aratmaniz durumunda aldiginiz PID numaralarini apache status da aratarak hangi siteye istekler gönderdigini rahatca bulabilirsiniz.
__________________
Netinternet'i sosyal paylaşım ağlarından takip edin kampanyalardan ilk haberi siz alın!!
Facebook | twitter | friendfeed
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3  
Old 04.09.08, 04:11
Athlon
 
Join Date: Jan 2008
Location: Gonya
Posts: 109
Rep Power: 7
aydin is on a distinguished road
TIME_WAIT oraninin yüksek olmasi ve bunun tek bir yerden olmasi siteye oradan saldiri geliyor olabilecegine isaret olurmu ?

asagida sadece kücük bir kismi var gecenin 5 i cok fazla oranda bu lesaweb denen yerden var

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #4  
Old 04.09.08, 04:14
Ni-Osman's Avatar
Linux HelpDesk
 
Join Date: Feb 2008
Location: Denizli
Posts: 284
Rep Power: 7018
Ni-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond reputeNi-Osman has a reputation beyond repute
Send a message via MSN to Ni-Osman Send a message via Yahoo to Ni-Osman Send a message via Skype™ to Ni-Osman
Bu ciktiyi hangi komut ile aldiniz

netstat -ntu da RDNS ler yazmaz..

yazdiginiz komudu söylerseniz güzel bir komut veirim bu konu ile ilgil.
__________________
Netinternet'i sosyal paylaşım ağlarından takip edin kampanyalardan ilk haberi siz alın!!
Facebook | twitter | friendfeed
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #5  
Old 04.09.08, 06:17
Athlon
 
Join Date: Jan 2008
Location: Gonya
Posts: 109
Rep Power: 7
aydin is on a distinguished road
netstat -a olarak sunucuya bagli reselleri yazdim

-ntu ciktisinin bir kismi asagida bu seferde ip olarak fakat yine leaseweb e ait ipiler



Quote:
tcp 0 0 84.16.252.94:59852 85.17.215.67:22 TIME_WAIT
tcp 0 0 84.16.252.94:58065 85.17.213.74:22 TIME_WAIT
tcp 0 0 84.16.252.94:59417 85.17.212.190:22 TIME_WAIT
tcp 0 0 84.16.252.94:59417 85.17.212.190:22 TIME_WAIT
tcp 0 0 84.16.252.94:59655 85.17.212.191:22 TIME_WAIT
tcp 0 0 84.16.252.94:57603 85.17.212.183:22 TIME_WAIT
tcp 0 0 84.16.252.94:59508 85.17.212.190:22 TIME_WAIT
tcp 0 0 84.16.252.94:58770 85.17.213.77:22 TIME_WAIT
tcp 0 0 84.16.252.94:58728 85.17.212.179:22 TIME_WAIT
tcp 0 0 84.16.252.94:57921 85.17.212.180:22 TIME_WAIT
tcp 0 0 84.16.252.94:57242 85.17.213.136:22 TIME_WAIT
tcp 0 0 84.16.252.94:57956 85.17.213.74:22 TIME_WAIT
tcp 0 0 84.16.252.94:59770 85.17.215.67:22 TIME_WAIT
tcp 0 0 84.16.252.94:57218 85.17.212.137:22 TIME_WAIT
tcp 0 0 84.16.252.94:57731 85.17.212.183:22 TIME_WAIT
tcp 0 0 84.16.252.94:59784 85.17.212.191:22 TIME_WAIT
tcp 0 0 84.16.252.94:59616 85.17.212.190:22 TIME_WAIT
tcp 0 0 84.16.252.94:58659 85.17.213.77:22 TIME_WAIT
tcp 0 0 84.16.252.94:58049 85.17.212.180:22 TIME_WAIT
tcp 0 0 84.16.252.94:58827 85.17.212.179:22 TIME_WAIT
tcp 0 0 84.16.252.94:59967 85.17.212.189:22 ESTABLISHED
tcp 0 0 84.16.252.94:58175 85.17.212.180:22 TIME_WAIT
tcp 0 0 84.16.252.94:59425 85.17.212.191:22 TIME_WAIT
tcp 0 0 84.16.252.94:57372 85.17.212.183:22 TIME_WAIT
tcp 0 0 84.16.252.94:57372 85.17.212.183:22 TIME_WAIT
tcp 0 0 84.16.252.94:59634 85.17.215.67:22 TIME_WAIT
tcp 0 0 84.16.252.94:59528 85.17.215.67:22 TIME_WAIT
tcp 0 0 84.16.252.94:57470 85.17.212.183:22 TIME_WAIT
tcp 0 0 84.16.252.94:57210 85.17.213.137:22 TIME_WAIT
tcp 0 0 84.16.252.94:59748 85.17.212.190:22 TIME_WAIT
tcp 0 0 84.16.252.94:58462 85.17.212.179:22 TIME_WAIT
tcp 0 0 84.16.252.94:57165 85.17.212.136:22 TIME_WAIT
tcp 0 0 84.16.252.94:58548 85.17.213.77:22 TIME_WAIT
tcp 0 0 84.16.252.94:58293 85.17.213.74:22 TIME_WAIT
tcp 0 0 84.16.252.94:59837 85.17.212.190:22 TIME_WAIT
tcp 0 0 84.16.252.94:58298 85.17.212.180:22 TIME_WAIT
tcp 0 0 84.16.252.94:58472 85.17.213.77:22 TIME_WAIT
tcp 0 0 84.16.252.94:59541 85.17.212.191:22 TIME_WAIT
tcp 0 0 84.16.252.94:58373 85.17.213.77:22 TIME_WAIT
tcp 0 0 84.16.252.94:59929 85.17.213.67:22 ESTABLISHED
tcp 0 0 84.16.252.94:58596 85.17.212.179:22 TIME_WAIT
tcp 0 0 84.16.252.94:57323 85.17.213.137:22 TIME_WAIT
tcp 0 0 84.16.252.94:58152 85.17.213.74:22 TIME_WAIT
tcp 0 0 84.16.252.94:57286 85.17.212.136:22 TIME_WAIT
tcp 0 0 84.16.252.94:59957 85.17.212.190:22 ESTABLISHED
tcp 0 0 84.16.252.94:57404 85.17.212.180:22 TIME_WAIT
tcp 0 0 84.16.252.94:59180 85.17.212.179:22 TIME_WAIT
tcp 0 0 84.16.252.94:57215 85.17.212.139:22 TIME_WAIT
tcp 0 0 84.16.252.94:57479 85.17.213.74:22 TIME_WAIT
tcp 0 0 84.16.252.94:58209 85.17.212.183:22 TIME_WAIT
tcp 0 0 84.16.252.94:59759 85.17.212.189:22 TIME_WAIT
tcp 0 0 84.16.252.94:59816 85.17.213.67:22 TIME_WAIT
tcp 0 0 84.16.252.94:59314 85.17.213.77:22 TIME_WAIT
tcp 0 0 84.16.252.94:57522 85.17.212.180:22 TIME_WAIT
tcp 0 0 84.16.252.94:59308 85.17.212.179:22 TIME_WAIT
tcp 0 0 84.16.252.94:59216 85.17.213.77:22 TIME_WAIT
tcp 0 0 84.16.252.94:57325 85.17.212.139:22 TIME_WAIT
tcp 0 0 84.16.252.94:58321 85.17.212.183:22 TIME_WAIT
tcp 0 0 84.16.252.94:57379 85.17.213.74:22 TIME_WAIT
tcp 0 0 84.16.252.94:59844 85.17.212.189:22 TIME_WAIT
tcp 0 0 84.16.252.94:59708 85.17.213.67:22 TIME_WAIT
tcp 0 0 84.16.252.94:57833 85.17.213.74:22 TIME_WAIT
tcp 0 0 84.16.252.94:59421 85.17.212.189:22 TIME_WAIT
tcp 0 0 84.16.252.94:57312 85.17.213.116:22 TIME_WAIT
tcp 0 0 84.16.252.94:59105 85.17.213.77:22 TIME_WAIT
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Safe Mod Nedir, Nasil Acilir, Joomla Siteler icin Özel Safe Mod Degeri Vermek ? RAMBilisim WHM cPanel 22 11.06.10 15:50
Memcached nedir? Nasil kurulur? wmaster WHM cPanel 2 21.12.08 06:09
Nano Nedir? Nasil Kurulur? Mutlu WHM cPanel 27 22.11.08 18:50
Migrasyon Servisi Nedir Nasil Kullanilir ? prowas WHM cPanel 1 06.12.07 15:10
SQL Injection nedir ve nasil korunulur ? CaLViN WHM cPanel 0 14.06.07 18:02


Navigasyon
Menü