linuxÄÚºËnetfilterµÄʵÏÖÒÔ¼°ipset
netfilterµÄʵÏÖ»úÖÆ»ùÓÚËĸö²ã´ÎµÄÆ¥Å䣬Êý¾Ý°üÔÚÿ¸ö²ã´Î¶¼Òª¾¹ýÒ»¸ö¹ýÂËÁ´±í£¬µÚÒ»¸ö²ã´Î¾ÍÊÇhook£¬ÖÚËùÖÜÖªlinuxÄÚºËÖÐÒ»¹²ÓµÓÐ5¸öhooks£¬µ±È»ÄãÒ²¿ÉÒÔ×Ô¼ºÐÞ¸ÄÄÚºËÔÚÈκεط½Ìí¼Óhook£»µÚ¶þ¸ö²ã´Î¾ÍÊÇÿ¸öhookÏÂÃæµÄtables£¬Ã¿Ò»¸öhook¶¼¹ý¹ÒÔØÁã¸ö»òÕßÈô¸É¸ötables£¬Êý¾Ý°üÒªÒ»¸öÒ»¸ö¾¹ýÕâЩtables£»µÚÈý¸ö²ã´Î¾ÍÊÇrule£¬Ã¿¸ötableÏÂÃæÓµÓÐÁã¸ö»òÕßÈô¸É¸örule£¬Êý¾Ý°üÒªÒÀ´Î¾¹ýÕâЩrules£¬Ö»ÒªÓÐÒ»¸örule¶ÔÊý¾Ý°ü½øÐÐÁ˲þö£¬ÄÇô½«²»ÔÙ¾¹ý¸ÃhookµÄ¸ÃtableµÄ¶ÔÓ¦ruleµÄºóÃærules£»µÚËĸö²ã´ÎÊÇmatchs£¬ºÍrulesµÄ±éÀúÕýºÃÏà·´£¬Êý¾Ý°üÖ»ÓÐÔÚ¶ÔÓ¦ruleÏÂÃæµÄËùÓеÄmatchs¶¼Æ¥Åäºó²ÅËãÆ¥Åä¡£
ÔÚÄÚºËÖУ¬netfilterÊÇÓÉÏÂÃæ4¸öºËÐĽṹÌåÖ§³ÅÆðÀ´µÄ£º
struct xt_table_info
{
unsigned int size;
unsigned int number;
unsigned int initial_entries;
unsigned int hook_entry[NF_IP_NUMHOOKS];
unsigned int underflow[NF_IP_NUMHOOKS];
char *entries[NR_CPUS];
};
entries[cpu]Ö¸ÏòÁËÒ»¸öipt_entryÊý×飬¸ÃÊý×éµÄÄÚ´æ×éÖ¯ÐÎʽÊÇƽ̹µÄ£¬Í¨¹ýipt_entryµÄnext_offset×ֶνøÐбéÀú£º
struct ipt_entry
{
struct ipt_ip ip;
unsigned int nfcache;
u_int16_t target_offset;
u_int16_t next_offset;
unsigned int comefrom;
struct xt_counters counters;
unsigned char elems[0];
};
elemsÖ¸ÏòÁËÒ»¿éƽ̹ÄÚ´æģʽµÄ£¬°üº¬ÁËÈô¸É¸ömatchsºÍÒ»¸ötarget£¬targetͨ¹ýtarget_offsetÀ´¶¨Î»£¬¸÷¸ömatchsÕýÈçÉÏÃæËù˵£¬Í¨¹ýnext_offsetÀ´½øÐбéÀúµÄ£º
struct xt_entry_match
{
union {
struct {
u_int16_t match_size;
char name[XT_FUNCTION_MAXNAMELEN-1];
u_int8_t revision;
} user;
struct {
&nbs
Ïà¹ØÎĵµ£º
×ÜÀÀ
ÓÃiptables -ADC À´Ö¸¶¨Á´µÄ¹æ
Ôò
£¬-AÌí¼Ó -Dɾ³ý -C ÐÞ¸Ä
iptables - [RI] chain rule num rule-specification[option]
ÓÃiptables - RI ͨ¹ý¹æÔòµÄ˳ÐòÖ¸¶¨
iptables -D chain rule num[option]
ɾ³ýÖ¸¶¨¹æÔò
iptables -[LFZ] [chain][option]
ÓÃiptables -LFZ Á´Ãû [Ñ¡Ïî]
iptables -[NX] chain
ÓÃ -NX ......
crontabµÄÓ÷¨---linux¶¨Ê±ÈÎÎñ
2008Äê07ÔÂ30ÈÕ ÐÇÆÚÈý ÏÂÎç 01:00
crontabµÄÓ÷¨---linux¶¨Ê±ÈÎÎñ
Step 1:
ʹÓÃÃüÁîcrontab
-e±à¼Ò»¸ö¶¨Ê±Ö´ÐеÄÈÎÎñ»òÔÚ/var/spool/cron/crontabsĿ¼ÏÂн¨Ò»¸öÓë×Ô¼ºÓû§ÃûÏàͬµÄÈÎÎñ.
¼´:
#ÿ¸ôÒ»·ÖÖÓÖ´ÐÐÒ»´Îº ......
linux arp ÃüÁî³£ÓòÎÊýÏê½â
ÏÔʾºÍÐ޸ĵØÖ·½âÎöÐÒé(ARP)ʹÓõēIP µ½ÎïÀ픵Øַת»»±í¡£
ARP -s inet_addr eth_addr [if_addr]
ARP -d inet_addr [if_addr]
ARP -a [inet_addr] [-N if_addr] [-v]
-a ͨ¹ýѯÎʵ±Ç°ÐÒéÊý¾Ý£¬ÏÔʾµ±Ç° ARP Ïî¡£Èç¹ûÖ¸¶¨ ......
Æô¶¯ÅäÖãº
/etc/init.d/rcS
# mkfs.jffs2 -r yyfs/ -o yy.jffs2 -p -l -n -e 0x8000 -m size
ÄÚºËÆô¶¯ÏÔʾ£º
unable to open an initial console.
½â¾ö£º
´´½¨rootfs¹ý³ÌÖУ¬ÔÚ/devĿ¼ÏÂÊÖ¶¯´´½¨ÈçϽڵ㣺
mknod -m 660 null c 1 3
mknod -m 660 console c 5 1
Taking the GNU/Linux hos ......