Strona 1 z 2

[+] Dziwna sprawa, port 80 już jest zajęty?

: 13 lipca 2012, 21:46
autor: Nerus
Witam.
Dziwna sprawa, port 80 już jest zajęty informuje serwer dedykowany z Debianem x64, zainstalowałem sobie apache i ku mojemu zdziwieniu wyskoczyła informacja, że ten port już jest wykorzystany. Stwierdziłem, że zobaczę sobie listę portów i uruchomionych usług.

Po wykonaniu polecenia:

Kod: Zaznacz cały

netstat -tlpn | less
Bardzo się zdziwiłem, gdyż nie widzę żadnego serwera puszczonego na tym porcie.
Jak jeszcze mogę sprawdzić co działa w systemie?

Wyjście serwera:

Kod: Zaznacz cały

[B]It works![/B]

 This is the default web page for this server.
 The web server software is running but no content has been added, yet.

: 13 lipca 2012, 22:19
autor: gajosew
A nmap co mówi?

: 13 lipca 2012, 22:24
autor: Nerus

Kod: Zaznacz cały

nmap -PA80 **********

Starting Nmap 5.00 ( [url]http://nmap.org[/url] ) at 2012-07-13 22:23 CEST
Interesting ports on ############ (**************):
Not shown: 998 filtered ports
PORT   STATE  SERVICE
21/tcp open   ftp
80/tcp closed http

: 13 lipca 2012, 22:26
autor: gajosew

Kod: Zaznacz cały

ps -aux
Jaki wynik?

: 13 lipca 2012, 22:45
autor: Nerus

Kod: Zaznacz cały

ps -aux | grep :80

Kod: Zaznacz cały

Warning: bad ps syntax, perhaps a bogus '-'? See [url]http://procps.sf.net/faq.html[/url]
root     20118  0.0  0.0  10132   844 pts/11   S+   22:45   0:00 grep :80

: 13 lipca 2012, 22:47
autor: gajosew
Poprawnie to jest:

Kod: Zaznacz cały

ps -aux | grep 80
ale sprawdź samo:

Kod: Zaznacz cały

ps -aux

: 13 lipca 2012, 22:55
autor: Nerus

Kod: Zaznacz cały

ps -aux
Warning: bad ps syntax, perhaps a bogus '-'? See [URL]http://procps.sf.net/faq.html[/URL]
USER       PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND
root         1  0.0  0.0   8400   592 ?        Ss   Jul01   0:06 init [2]
root         2  0.0  0.0      0     0 ?        S    Jul01   0:00 [kthreadd]
root         3  0.0  0.0      0     0 ?        S    Jul01   0:02 [ksoftirqd/0]
root         6 96.1  0.0      0     0 ?        S    Jul01 16697:16 [migration/0]
root         7 96.7  0.0      0     0 ?        S    Jul01 16808:59 [migration/1]
root         9  0.0  0.0      0     0 ?        S    Jul01   0:02 [ksoftirqd/1]
root        11 97.1  0.0      0     0 ?        S    Jul01 16863:50 [migration/2]
root        13  0.0  0.0      0     0 ?        S    Jul01   0:02 [ksoftirqd/2]
root        14 96.9  0.0      0     0 ?        S    Jul01 16836:55 [migration/3]
root        16  0.0  0.0      0     0 ?        S    Jul01   0:03 [ksoftirqd/3]
root        17 98.7  0.0      0     0 ?        S    Jul01 17142:05 [migration/4]
root        19  0.0  0.0      0     0 ?        S    Jul01   0:05 [ksoftirqd/4]
root        20 98.3  0.0      0     0 ?        S    Jul01 17078:15 [migration/5]
root        22  0.0  0.0      0     0 ?        S    Jul01   0:01 [ksoftirqd/5]
root        23 97.3  0.0      0     0 ?        S    Jul01 16908:42 [migration/6]
root        24  0.0  0.0      0     0 ?        S    Jul01   0:05 [kworker/6:0]
root        25  0.0  0.0      0     0 ?        S    Jul01   0:01 [ksoftirqd/6]
root        26 86.1  0.0      0     0 ?        S    Jul01 14957:56 [migration/7]
root        27  0.0  0.0      0     0 ?        S    Jul01   0:04 [kworker/7:0]
root        28  0.0  0.0      0     0 ?        S    Jul01   0:01 [ksoftirqd/7]
root        29  0.0  0.0      0     0 ?        S<   Jul01   0:00 [cpuset]
root        30  0.0  0.0      0     0 ?        S<   Jul01   0:00 [khelper]
root        31  0.0  0.0      0     0 ?        S    Jul01   0:00 [kdevtmpfs]
root        32  0.0  0.0      0     0 ?        S<   Jul01   0:00 [netns]
root       425  0.0  0.0      0     0 ?        S    Jul01   0:01 [sync_supers]
root       427  0.0  0.0      0     0 ?        S    Jul01   0:00 [bdi-default]
root       428  0.0  0.0      0     0 ?        S<   Jul01   0:00 [kintegrityd]
root       430  0.0  0.0      0     0 ?        S<   Jul01   0:00 [kblockd]
root       569  0.0  0.0      0     0 ?        S<   Jul01   0:00 [ata_sff]
root       579  0.0  0.0      0     0 ?        S    Jul01   0:00 [khubd]
root       586  0.0  0.0      0     0 ?        S<   Jul01   0:00 [md]
root       618  0.0  0.0      0     0 ?        S    Jul01   0:04 [kworker/6:1]
root       619  0.0  0.0      0     0 ?        S    Jul01   0:06 [kworker/7:1]
root       717  0.0  0.0      0     0 ?        S<   Jul01   0:00 [rpciod]
root       718  0.0  0.0      0     0 ?        S<   Jul01   0:00 [kvm-irqfd-clean]
root       803  0.0  0.0      0     0 ?        S    Jul01   0:46 [kswapd0]
root       804  0.0  0.0      0     0 ?        SN   Jul01   0:00 [ksmd]
root       805  0.0  0.0      0     0 ?        S    Jul01   0:00 [fsnotify_mark]
root       809  0.0  0.0      0     0 ?        S<   Jul01   0:00 [nfsiod]
root       814  0.0  0.0      0     0 ?        S    Jul01   0:00 [jfsIO]
root       815  0.0  0.0      0     0 ?        S    Jul01   0:00 [jfsCommit]
root       816  0.0  0.0      0     0 ?        S    Jul01   0:00 [jfsCommit]
root       817  0.0  0.0      0     0 ?        S    Jul01   0:00 [jfsCommit]
root       818  0.0  0.0      0     0 ?        S    Jul01   0:00 [jfsCommit]
root       819  0.0  0.0      0     0 ?        S    Jul01   0:00 [jfsCommit]
root       820  0.0  0.0      0     0 ?        S    Jul01   0:00 [jfsCommit]
root       821  0.0  0.0      0     0 ?        S    Jul01   0:00 [jfsCommit]
root       822  0.0  0.0      0     0 ?        S    Jul01   0:00 [jfsCommit]
root       823  0.0  0.0      0     0 ?        S    Jul01   0:00 [jfsSync]
root       824  0.0  0.0      0     0 ?        S<   Jul01   0:00 [xfs_mru_cache]
root       825  0.0  0.0      0     0 ?        S<   Jul01   0:00 [xfslogd]
root       826  0.0  0.0      0     0 ?        S<   Jul01   0:00 [xfsdatad]
root       827  0.0  0.0      0     0 ?        S<   Jul01   0:00 [xfsconvertd]
root       828  0.0  0.0      0     0 ?        S<   Jul01   0:00 [ocfs2_wq]
root       830  0.0  0.0      0     0 ?        S<   Jul01   0:00 [user_dlm]
root       833  0.0  0.0      0     0 ?        S<   Jul01   0:00 [glock_workqueue]
root       834  0.0  0.0      0     0 ?        S<   Jul01   0:00 [delete_workqueu]
root       835  0.0  0.0      0     0 ?        S<   Jul01   0:00 [gfs_recovery]
root       836  0.0  0.0      0     0 ?        S<   Jul01   0:00 [crypto]
root       864  0.0  0.0      0     0 ?        S<   Jul01   0:00 [kthrotld]
root      1541  0.0  0.0      0     0 ?        S    Jul11   0:01 [kworker/1:2]
root      1567  0.0  0.0      0     0 ?        S<   Jul01   0:00 [iscsi_eh]
root      1576  0.0  0.0      0     0 ?        S<   Jul01   0:00 [fc_exch_workque]
root      1577  0.0  0.0      0     0 ?        S<   Jul01   0:00 [fc_rport_eq]
root      1578  0.0  0.0      0     0 ?        S<   Jul01   0:00 [fcoethread/0]
root      1579  0.0  0.0      0     0 ?        S<   Jul01   0:00 [fcoethread/1]
root      1580  0.0  0.0      0     0 ?        S<   Jul01   0:00 [fcoethread/2]
root      1581  0.0  0.0      0     0 ?        S<   Jul01   0:00 [fcoethread/3]
root      1582  0.0  0.0      0     0 ?        S<   Jul01   0:00 [fcoethread/4]
root      1583  0.0  0.0      0     0 ?        S<   Jul01   0:00 [fcoethread/5]
root      1584  0.0  0.0      0     0 ?        S<   Jul01   0:00 [fcoethread/6]
root      1585  0.0  0.0      0     0 ?        S<   Jul01   0:00 [fcoethread/7]
root      1619  0.0  0.0      0     0 ?        S    Jul01   0:00 [scsi_eh_0]
root      1622  0.0  0.0      0     0 ?        S    Jul01   0:00 [scsi_eh_1]
root      1625  0.0  0.0      0     0 ?        S    Jul01   0:00 [scsi_eh_2]
root      1628  0.0  0.0      0     0 ?        S    Jul01   0:00 [scsi_eh_3]
root      1631  0.0  0.0      0     0 ?        S    Jul01   0:00 [scsi_eh_4]
root      1634  0.0  0.0      0     0 ?        S    Jul01   0:00 [scsi_eh_5]
root      1728  0.0  0.0      0     0 ?        S<   Jul01   0:00 [kpsmoused]
root      1747  0.0  0.0      0     0 ?        S<   Jul01   0:00 [dm_bufio_cache]
root      1748  0.0  0.0      0     0 ?        S<   Jul01   0:00 [kdelayd]
root      1749  0.0  0.0      0     0 ?        S<   Jul01   0:00 [kmpathd]
root      1750  0.0  0.0      0     0 ?        S<   Jul01   0:00 [kmpath_handlerd]
root      1753  0.0  0.0      0     0 ?        S<   Jul01   0:00 [edac-poller]
root      1957  0.0  0.0      0     0 ?        S    Jul01   0:31 [md2_raid1]
root      1961  0.0  0.0      0     0 ?        S    Jul01   0:10 [md1_raid1]
root      1963  0.0  0.0      0     0 ?        S    Jul01   0:04 [jbd2/md1-8]
root      1964  0.0  0.0      0     0 ?        S<   Jul01   0:00 [ext4-dio-unwrit]
root      2010  0.0  0.0  16844   512 ?        S<s  Jul01   0:00 udevd --daemon
root      2449  0.0  0.0      0     0 ?        S    Jul01   0:03 [flush-9:1]
root      2636  0.0  0.0      0     0 ?        S    Jul01   0:17 [jbd2/md2-8]
root      2637  0.0  0.0      0     0 ?        S<   Jul01   0:00 [ext4-dio-unwrit]
root      2834  0.0  0.0 120268  1064 ?        Sl   Jul01   0:06 /usr/sbin/rsyslogd -c4
root      2911  0.0  0.0   9108   488 ?        Ss   Jul01   1:24 /usr/sbin/irqbalance
107       2945  0.0  0.0  23308    88 ?        Ss   Jul01   0:00 /usr/bin/dbus-daemon --system
root      2982  0.0  0.0  22924   816 ?        Ss   Jul01   0:02 /usr/sbin/cron
root      3027  0.0  0.0   5976   448 tty1     Ss+  Jul01   0:00 /sbin/getty 38400 tty1
root      3028  0.0  0.0   5976   464 tty2     Ss+  Jul01   0:00 /sbin/getty 38400 tty2
root      3029  0.0  0.0   5976   464 tty3     Ss+  Jul01   0:00 /sbin/getty 38400 tty3
root      3030  0.0  0.0   5976   464 tty4     Ss+  Jul01   0:00 /sbin/getty 38400 tty4
root      3031  0.0  0.0   5976   464 tty5     Ss+  Jul01   0:00 /sbin/getty 38400 tty5
root      3032  0.0  0.0   5976   464 tty6     Ss+  Jul01   0:00 /sbin/getty 38400 tty6
root      4043  0.0  0.0  13256  1372 ?        S    Jul03   0:00 /bin/sh /usr/bin/mysqld_safe
mysql     4155  0.0  0.2 236140 19956 ?        Sl   Jul03   2:41 /usr/sbin/mysqld --basedir=/usr --datadir=/var/lib/mysql --user=mysql --pid-file=/var/run/mysqld/mysqld
root      4156  0.0  0.0   5872   568 ?        S    Jul03   0:00 logger -t mysqld -p daemon.error
root      4557  0.0  0.0      0     0 ?        S    Jul09   0:02 [kworker/3:2]
root      6364  0.0  0.0  37408  1300 pts/0    S    18:39   0:00 su
root      6365  0.0  0.0  21916  2104 pts/0    S+   18:39   0:00 bash
daemon    9752  0.0  0.0  18760   336 ?        Ss   Jul07   0:00 /usr/sbin/atd
root      9780  0.0  0.0  37408  1300 pts/11   S    19:38   0:00 su
root      9781  0.0  0.0  21908  2136 pts/11   S    19:38   0:00 bash
root      9817  0.0  0.0 164676  7460 ?        Ssl  Jul07   0:00 /usr/sbin/lwresd
bind      9959  0.0  0.2 252560 21376 ?        Ssl  Jul07   0:00 /usr/sbin/named -u bind
root     10242  0.0  0.0      0     0 ?        S    Jul09   0:03 [kworker/4:1]
root     10593  0.0  0.0  49220  1072 ?        Ss   Jul07   0:00 /usr/sbin/sshd
root     10664  0.0  0.0  12844   636 ?        Ss   Jul07   0:00 /sbin/mdadm --monitor --pid-file /var/run/mdadm/monitor.pid --daemonise --scan --syslog
root     10844  0.0  0.0      0     0 ?        S    Jul03   0:26 [flush-9:2]
root     11377  0.0  0.0      0     0 ?        S    20:04   0:00 [kworker/0:0]
root     12244  0.0  0.0  16840   260 ?        S<   Jul12   0:00 udevd --daemon
root     12245  0.0  0.0  16840   260 ?        S<   Jul12   0:00 udevd --daemon
root     13967  0.0  0.0      0     0 ?        S    Jul06   0:03 [kworker/5:1]
root     13990  0.0  0.0      0     0 ?        S    Jul06   0:07 [kworker/3:0]
root     14845  0.0  0.0      0     0 ?        S    21:04   0:00 [kworker/0:2]
root     17089  0.0  0.0      0     0 ?        S    Jul06   0:05 [kworker/4:2]
root     17686  0.0  0.0      0     0 ?        S    11:37   0:00 [kworker/u:2]
root     18449  0.0  0.0  70540  3348 ?        Ss   22:14   0:00 sshd: root@notty
root     18451  0.0  0.0  12484   984 ?        Ss   22:14   0:00 /usr/lib/openssh/sftp-server
www-data 18599  0.0  0.0  54240  1824 ?        S    22:16   0:00 /usr/sbin/lighttpd -f /etc/lighttpd/lighttpd.conf
root     19136  0.0  0.0      0     0 ?        S    12:03   0:00 [kworker/1:0]
root     20429  0.0  0.0  16832  1136 pts/11   R+   22:50   0:00 ps -aux
root     21831  0.0  0.0      0     0 ?        S    Jul09   0:01 [kworker/5:2]
root     25306  0.0  0.0      0     0 ?        S    14:07   0:00 [kworker/u:1]
root     27682  0.0  0.0      0     0 ?        S    04:03   0:00 [kworker/2:0]
root     31173  0.0  0.0      0     0 ?        S    Jul04   0:04 [kworker/2:2]
root     31311  0.0  0.0  27064  1196 ?        S    Jul09   0:00 /usr/sbin/vsftpd

: 13 lipca 2012, 22:58
autor: gajosew
www-data 18599 0.0 0.0 54240 1824 ? S 22:16 0:00 /usr/sbin/lighttpd -f /etc/lighttpd/lighttpd.conf
masz zainstalowanego
[LEFT]lighttpd (jak wiesz to lekki i prosty serwer www )[/LEFT][LEFT][/LEFT]

: 13 lipca 2012, 23:00
autor: Nerus
Mam ale na niestandardowym porcie, poza tym wyłączałem go przed włączeniem apacha2.

: 13 lipca 2012, 23:03
autor: gajosew
To na jakim jak go nmap nie pokazuje?
Przedstaw:

Kod: Zaznacz cały

nmap ps -aux | grep 80

Potem:

Kod: Zaznacz cały

nmap localhost

A zrzut z:

Kod: Zaznacz cały

netstat -tlpn | less

Możesz dać na