发布时间:2025-12-10 19:44:37 浏览次数:4
允许Traceroute探测 (在防火墙中禁用Time Exceeded类型的ICMP包)允许Traceroute探测(在防火墙中禁用TimeExceeded类型的ICMP包)允许Traceroute探测详细描述本插件使用Traceroute探测来获取扫描器与远程主机之间的路由信息。攻击者也可以利用这些信息来了解目标网络的网络拓扑。解决办法在防火墙中禁用TimeExcee
| 允许Traceroute探测 | ||||||||||
|
解决步骤如下:
(说明:如果/etc/sysconfig/ 目录下没有 iptables 文件,需要安装 iptables,请参考:https://www.cnblogs.com/miracle-luna/p/13714709.html)
在/etc/sysconfig/iptables 文件中,增加如下内容:
-A INPUT -p icmp --icmp-type time-exceeded -j DROP-A OUTPUT -p icmp --icmp-type time-exceeded -j DROP
【正版授权,激活自己账号】:Jetbrains全家桶Ide使用,1年售后保障,每天仅需1毛
修改后,iptables 文件内容如下:
# sample configuration for iptables service# you can edit this manually or use system-config-firewall# please do not ask us to add additional ports/services to this default configuration*filter:INPUT ACCEPT [0:0]:FORWARD ACCEPT [0:0]:OUTPUT ACCEPT [0:0]-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT-A INPUT -p icmp -j ACCEPT-A INPUT -i lo -j ACCEPT-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT# 解决time exceeded问题-A INPUT -p icmp --icmp-type time-exceeded -j DROP -A OUTPUT -p icmp --icmp-type time-exceeded -j DROP -A INPUT -j REJECT --reject-with icmp-host-prohibited-A FORWARD -j REJECT --reject-with icmp-host-prohibitedCOMMIT
service iptables save
systemctl reload iptables
或者
service iptables reload
systemctl restart iptables
或者
service iptables restart
systemctl status iptables
或者
service iptables status