ded wrote:en suite 192.168.0.2 c'est une adresse locale
Oui c'est mon poste, c'est l'adresse de direction de inbond. J'ai recupere quelques infos supplementaires.
Deja j'ai coupe le service sendmail apres avoir vu ca : access a mes aliases dans maillog; je n'utilise jamais de prog de mail
Jun 9 11:54:25 localhost sendmail[2073]: alias database /etc/aliases rebuilt by root
Jun 9 11:54:25 localhost sendmail[2073]: /etc/aliases: 76 aliases, longest 10 bytes, 765 bytes total
Jun 9 11:54:25 localhost sendmail[2078]: starting daemon (8.14.1): SMTP+queueing@01:00:00
Jun 9 11:54:25 localhost sm-msp-queue[2087]: starting daemon (8.14.1): queueing@01:00:00
Jun 9 13:08:03 localhost sendmail[3564]: l59B7vAh003564: from=root, size=26180, class=0, nrcpts=1, msgid=<200706091107.l59B7vAh003564@localhost.localdomain>, relay=root@localhost
Jun 9 13:08:03 localhost sendmail[3848]: l59B831O003848: from=<root@localhost.localdomain>, size=26458, class=0, nrcpts=1, msgid=<200706091107.l59B7vAh003564@localhost.localdomain>, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1]
Jun 9 13:08:03 localhost sendmail[3564]: l59B7vAh003564: to=root, ctladdr=root (0/0), delay=00:00:06, xdelay=00:00:00, mailer=relay, pri=56180, relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (l59B831O003848 Message accepted for delivery)
Jun 9 13:08:04 localhost sendmail[3849]: l59B831O003848: to=<root@localhost.localdomain>, ctladdr=<root@localhost.localdomain> (0/0), delay=00:00:01, xdelay=00:00:01, mailer=local, pri=56691, dsn=2.0.0, stat=Sent
Jun 9 13:30:11 localhost sendmail[2089]: alias database /etc/aliases rebuilt by root
Jun 9 13:30:11 localhost sendmail[2089]: /etc/aliases: 76 aliases, longest 10 bytes, 765 bytes total
Jun 9 13:30:12 localhost sendmail[2094]: starting daemon (8.14.1): SMTP+queueing@01:00:00
Jun 9 13:30:12 localhost sm-msp-queue[2103]: starting daemon (8.14.1): queueing@01:00:00
ensuite j'ai recupe les ip de destination en sortie :
Jun 9 15:06:01 localhost kernel: Outbound IN= OUT=eth0 SRC=192.168.0.2 DST=224.0.0.251 LEN=177 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=157
Jun 9 15:06:01 localhost kernel: Outbound IN= OUT=eth0 SRC=192.168.0.2 DST=224.0.0.251 LEN=372 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=352
Jun 9 15:06:01 localhost kernel: Outbound IN= OUT=eth0 SRC=192.168.0.2 DST=224.0.0.251 LEN=177 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=157
Jun 9 15:06:02 localhost kernel: Outbound IN= OUT=eth0 SRC=192.168.0.2 DST=224.0.0.251 LEN=177 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=157
Jun 9 15:06:02 localhost kernel: Outbound IN= OUT=eth0 SRC=192.168.0.2 DST=224.0.0.251 LEN=165 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=145
Jun 9 15:06:02 localhost kernel: Outbound IN= OUT=eth0 SRC=192.168.0.2 DST=224.0.0.251 LEN=316 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=296
Jun 9 15:06:02 localhost kernel: Outbound IN= OUT=eth0 SRC=192.168.0.2 DST=224.0.0.251 LEN=89 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=69
Jun 9 15:06:03 localhost kernel: Outbound IN= OUT=eth0 SRC=192.168.0.2 DST=224.0.0.251 LEN=165 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=145
Jun 9 15:06:05 localhost kernel: Outbound IN= OUT=eth0 SRC=192.168.0.2 DST=224.0.0.251 LEN=165 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=145
Jun 9 15:06:07 localhost kernel: Outbound IN= OUT=eth0 SRC=192.168.0.2 DST=224.0.0.22 LEN=40 TOS=0x00 PREC=0xC0 TTL=1 ID=0 DF PROTO=2
Jun 9 15:07:46 localhost kernel: Outbound IN= OUT=eth0 SRC=192.168.0.2 DST=192.149.252.44 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=32555 DF PROTO=TCP SPT=59572 DPT=43 WINDOW=5840 RES=0x00 SYN URGP=0
Jun 9 15:07:49 localhost kernel: Outbound IN= OUT=eth0 SRC=192.168.0.2 DST=192.149.252.44 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=32556 DF PROTO=TCP SPT=59572 DPT=43 WINDOW=5840 RES=0x00 SYN URGP=0
Jun 9 15:07:49 localhost kernel: Outbound IN= OUT=eth0 SRC=192.168.0.2 DST=199.43.0.144 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=8155 DF PROTO=TCP SPT=35023 DPT=43 WINDOW=5840 RES=0x00 SYN URGP=0
Jun 9 15:07:52 localhost kernel: Outbound IN= OUT=eth0 SRC=192.168.0.2 DST=199.43.0.144 LEN=44 TOS=0x00 PREC=0x00 TTL=64 ID=8156 DF PROTO=TCP SPT=35023 DPT=43 WINDOW=5840 RES=0x00 SYN URGP=0
Voici les whois :
Voici les résultats du whois pour l'adresse IP 224.0.0.251
C'est le serveur whois.arin.net qui possède l'information suivante :
OrgName: Internet Assigned Numbers Authority
OrgID: IANA
Address: 4676 Admiralty Way, Suite 330
City: Marina del Rey
StateProv: CA
PostalCode: 90292-6695
Country: US
NetRange: 224.0.0.0 - 239.255.255.255
CIDR: 224.0.0.0/4
NetName: MCAST-NET
NetHandle: NET-224-0-0-0-1
Parent:
NetType: IANA Special Use
NameServer: FLAG.EP.NET
NameServer: STRUL.STUPI.SE
NameServer: NS.ISI.EDU
NameServer: NIC.NEAR.NET
Comment: This block is reserved for special purposes.
Comment: Please see RFC 3171 for additional information.
Comment:
RegDate: 1991-05-22
Updated: 2002-09-16
OrgAbuseHandle: IANA-IP-ARIN
OrgAbuseName: Internet Corporation for Assigned Names and Number
OrgAbusePhone: +1-310-301-5820
OrgAbuseEmail: abuse@iana.org
OrgTechHandle: IANA-IP-ARIN
OrgTechName: Internet Corporation for Assigned Names and Number
OrgTechPhone: +1-310-301-5820
OrgTechEmail: abuse@iana.org
Voici les résultats du whois pour l'adresse IP 224.0.0.222
C'est le serveur whois.arin.net qui possède l'information suivante :
OrgName: Internet Assigned Numbers Authority
OrgID: IANA
Address: 4676 Admiralty Way, Suite 330
City: Marina del Rey
StateProv: CA
PostalCode: 90292-6695
Country: US
NetRange: 224.0.0.0 - 239.255.255.255
CIDR: 224.0.0.0/4
NetName: MCAST-NET
NetHandle: NET-224-0-0-0-1
Parent:
NetType: IANA Special Use
NameServer: FLAG.EP.NET
NameServer: STRUL.STUPI.SE
NameServer: NS.ISI.EDU
NameServer: NIC.NEAR.NET
Comment: This block is reserved for special purposes.
Comment: Please see RFC 3171 for additional information.
Comment:
RegDate: 1991-05-22
Updated: 2002-09-16
OrgAbuseHandle: IANA-IP-ARIN
OrgAbuseName: Internet Corporation for Assigned Names and Number
OrgAbusePhone: +1-310-301-5820
OrgAbuseEmail: abuse@iana.org
OrgTechHandle: IANA-IP-ARIN
OrgTechName: Internet Corporation for Assigned Names and Number
OrgTechPhone: +1-310-301-5820
OrgTechEmail: abuse@iana.org
# ARIN WHOIS database, last updated 2007-06-08 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
Voici les résultats du whois pour l'adresse IP 199.43.0.144
C'est le serveur whois.arin.net qui possède l'information suivante :
OrgName: American Registry for Internet Numbers
OrgID: ARIN
Address: 3635 Concorde Parkway
Address: Suite 200
City: Chantilly
StateProv: VA
PostalCode: 20151
Country: US
NetRange: 199.43.0.0 - 199.43.0.255
CIDR: 199.43.0.0/24
OriginAS: AS10745
NetName: ARIN-BLK-3
NetHandle: NET-199-43-0-0-1
Parent: NET-199-0-0-0-0
NetType: Direct Assignment
NameServer: NS1.ARIN.NET
NameServer: NS2.ARIN.NET
NameServer: NS-SEC.RIPE.NET
NameServer: SEC1.APNIC.NET
NameServer: SEC3.APNIC.NET
Comment:
RegDate: 2005-11-09
Updated: 2007-03-28
OrgNOCHandle: ARINN-ARIN
OrgNOCName: ARIN NOC
OrgNOCPhone: +1-703-227-9840
OrgNOCEmail: noc@arin.net
OrgTechHandle: ARIN-HOSTMASTER
OrgTechName: Registration Services Department
OrgTechPhone: +1-703-227-0660
OrgTechEmail: hostmaster@arin.net
# ARIN WHOIS database, last updated 2007-06-08 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.