<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>EAK Just Debian Guru Page :) &#187; Sunucu</title>
	<atom:link href="http://eakcorp.com/category/sunucu/feed/" rel="self" type="application/rss+xml" />
	<link>http://eakcorp.com</link>
	<description>Just another Linux weblog</description>
	<lastBuildDate>Wed, 24 Mar 2010 08:31:17 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Move Apache domlogs to second disk drive or any where</title>
		<link>http://eakcorp.com/2010/02/move-apache-domlogs-to-second-disk-drive-or-any-where/</link>
		<comments>http://eakcorp.com/2010/02/move-apache-domlogs-to-second-disk-drive-or-any-where/#comments</comments>
		<pubDate>Sun, 21 Feb 2010 19:34:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Sunucu]]></category>

		<guid isPermaLink="false">http://eakcorp.com/?p=240</guid>
		<description><![CDATA[Its a simple job and recommended appraoch is to stop Apache before moving domlogs so it will bring downtime. Here is how you can do it:

Quote:
service httpd stop
ps ax &#124; grep httpd  (Verify that no httpd process still running)
cd /usr/local/apache
mkdir /home2/apache ( Considering /home2 as your new drive)
mv domlogs /home2/apache/
ln -s /home2/apache/domlogs /usr/local/apache/domlogs
ls -la [...]]]></description>
			<content:encoded><![CDATA[<p>Its a simple job and recommended appraoch is to stop Apache before moving domlogs so it will bring downtime. Here is how you can do it:<br />
<!-- BEGIN TEMPLATE: bbcode_quote --></p>
<div>Quote:</div>
<p><strong>service httpd stop<br />
ps ax | grep httpd  (Verify that no httpd process still running)<br />
cd /usr/local/apache<br />
mkdir /home2/apache ( Considering /home2 as your new drive)<br />
mv domlogs /home2/apache/<br />
ln -s /home2/apache/domlogs /usr/local/apache/domlogs<br />
ls -la /usr/local/apache/ (Verify the link)<br />
service httpd start</strong></p>
<p>http://forums.cpanel.net/f5/move-apache-domlogs-second-disk-drive-98821.html</p>
]]></content:encoded>
			<wfw:commentRss>http://eakcorp.com/2010/02/move-apache-domlogs-to-second-disk-drive-or-any-where/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>if you are having problems with RPM&#8217;s, you can just get the CLI version of WinRar</title>
		<link>http://eakcorp.com/2010/01/if-you-are-having-problems-with-rpms-you-can-just-get-the-cli-version-of-winrar/</link>
		<comments>http://eakcorp.com/2010/01/if-you-are-having-problems-with-rpms-you-can-just-get-the-cli-version-of-winrar/#comments</comments>
		<pubDate>Sat, 23 Jan 2010 22:06:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Sunucu]]></category>

		<guid isPermaLink="false">http://eakcorp.com/?p=231</guid>
		<description><![CDATA[Alternativley if you are having problems with RPM's, you can just get the CLI version of WinRar directly from www.rarlab.com. Make sure you have Glibc 2.4 though.
# wget http://rarlab.com/rar/rarlinux-3.7.1.tar.gz
# tar xvzf rarlinux*
# cd rar
# make
# make install
Hope this helps.
]]></description>
			<content:encoded><![CDATA[<p>Alternativley if you are having problems with RPM's, you can just get the CLI version of WinRar directly from <a href="http://www.rarlab.com/" target="_blank">www.rarlab.com</a>. Make sure you have Glibc 2.4 though.</p>
<p># wget <a href="http://rarlab.com/rar/rarlinux-3.7.1.tar.gz" target="_blank">http://rarlab.com/rar/rarlinux-3.7.1.tar.gz</a><br />
# tar xvzf rarlinux*<br />
# cd rar<br />
# make<br />
# make install</p>
<p>Hope this helps.</p>
]]></content:encoded>
			<wfw:commentRss>http://eakcorp.com/2010/01/if-you-are-having-problems-with-rpms-you-can-just-get-the-cli-version-of-winrar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Centos Pure-ftp Problem {Lxadmin pure-ftp problemi}</title>
		<link>http://eakcorp.com/2010/01/centos-pure-ftp-problem-lxadmin-pure-ftp-problemi/</link>
		<comments>http://eakcorp.com/2010/01/centos-pure-ftp-problem-lxadmin-pure-ftp-problemi/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 09:02:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Sunucu]]></category>

		<guid isPermaLink="false">http://eakcorp.com/?p=227</guid>
		<description><![CDATA[Merhabalar, bu problem pure-ftpd nin son surumlerinde ortaya cikiyor, tabi boyle olunca celiskiye dusmemek elde degil, guncel sistem herzaman daha guvenlik acisinda daha iidir fakat butur problemlerin cikacagini dusunmek biraz kafa aritiyor:) gordugum kadariyla bu sorun lxadmin yuklu centos sunucularda meydana geliyor, cozumu basit yapmamiz gereken pure-ftp yi xinet 'in kontrolunden cikartmamiz,
rm /etc/xinet.d/pure-ftpd
Bu islem yeterli [...]]]></description>
			<content:encoded><![CDATA[<p>Merhabalar, bu problem pure-ftpd nin son surumlerinde ortaya cikiyor, tabi boyle olunca celiskiye dusmemek elde degil, guncel sistem herzaman daha guvenlik acisinda daha iidir fakat butur problemlerin cikacagini dusunmek biraz kafa aritiyor:) gordugum kadariyla bu sorun lxadmin yuklu centos sunucularda meydana geliyor, cozumu basit yapmamiz gereken pure-ftp yi xinet 'in kontrolunden cikartmamiz,</p>
<blockquote><p>rm /etc/xinet.d/pure-ftpd</p></blockquote>
<p>Bu islem yeterli gelir , sorun duzelmezse eger , pure-ftpd yi  kaldirip tekrar kurmamiz gerekir.</p>
<blockquote><p>yum remove pure-ftpd<br />
yum install pure-ftpd</p></blockquote>
<p>Daha sonra yapmamiz gereken daha onceki kayitli olan `lxadmin tarafindan olusturulan fptuser larimizi tanitmamiz lazim` pureftpd.pdb  pure-ftp.conf dosyamizda etkinlestiriyoruz.</p>
<blockquote><p>nano /etc/pure-ftpd/pure-ftpd.conf<br />
dosyayi actiktan sonra<br />
#PureDB                        /etc/pure-ftpd/pureftpd.pdb<br />
yukardaki satiri asagidaki sekilde degistiriyoruz<br />
PureDB                        /etc/pure-ftpd/pureftpd.pdb</p></blockquote>
<p>Kayit edip cikiyoruz.`ctrl-x` pure-ftpd yi durdurup tekrar baslatiyoruz. hepsi bukkadar.</p>
<blockquote><p>/etc/init.d/pure-ftpd stop<br />
/etc/init.d/pure-ftpd start</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://eakcorp.com/2010/01/centos-pure-ftp-problem-lxadmin-pure-ftp-problemi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Debian Lenny Timezone Problems</title>
		<link>http://eakcorp.com/2010/01/debian-lenny-timezone-problems/</link>
		<comments>http://eakcorp.com/2010/01/debian-lenny-timezone-problems/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 21:29:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Sunucu]]></category>

		<guid isPermaLink="false">http://eakcorp.com/?p=221</guid>
		<description><![CDATA[Hoi hoi , Debian lenny de surekli karsilastigim ve karsilasiligini dusundugum timezone sorununun cozumunu kisaca ve basitce anlatacam,
cat timezone --&#62;America/New_York -&#62;Europe/Istanbul
olarak   biz bu degeri  degisitiriyoruz ve bu sorundan kurtuluyoruz.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://eakcorp.com/wp-content/uploads/openlogo-100.jpg"><img class="size-full wp-image-220 alignleft" title="openlogo-100" src="http://eakcorp.com/wp-content/uploads/openlogo-100.jpg" alt="" width="100" height="123" /></a>Hoi hoi , Debian lenny de surekli karsilastigim ve karsilasiligini dusundugum timezone sorununun cozumunu kisaca ve basitce anlatacam,</p>
<blockquote><p>cat timezone --&gt;America/New_York -&gt;Europe/Istanbul</p>
<p>olarak   biz bu degeri  degisitiriyoruz ve bu sorundan kurtuluyoruz.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://eakcorp.com/2010/01/debian-lenny-timezone-problems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ModSecurity SecResponseBodyLimit</title>
		<link>http://eakcorp.com/2010/01/modsecurity-secresponsebodylimit/</link>
		<comments>http://eakcorp.com/2010/01/modsecurity-secresponsebodylimit/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 18:11:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Guvenlik]]></category>
		<category><![CDATA[Sunucu]]></category>

		<guid isPermaLink="false">http://eakcorp.com/?p=204</guid>
		<description><![CDATA[Merhabalar,
Karsilastigim bir sorunun cozumunu paylasmak istedim, Apache sunucumda , sitemaplari gosterirken belli bir kayittan sonra sitemap.php dosyasi hata veriyordu, 404 yada 500  hatasi veriyordu , bu sorunu  ModSecurity SecResponseBodyLimit  degerini arttirarak cozebilirsiniz.
]]></description>
			<content:encoded><![CDATA[<p>Merhabalar,</p>
<p>Karsilastigim bir sorunun cozumunu paylasmak istedim, Apache sunucumda , sitemaplari gosterirken belli bir kayittan sonra sitemap.php dosyasi hata veriyordu, 404 yada 500  hatasi veriyordu , bu sorunu  <strong>ModSecurity SecResponseBodyLimit  </strong>degerini arttirarak cozebilirsiniz.</p>
]]></content:encoded>
			<wfw:commentRss>http://eakcorp.com/2010/01/modsecurity-secresponsebodylimit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Detect DDOS if it is an attack</title>
		<link>http://eakcorp.com/2009/12/detect-ddos-if-it-is-an-attack/</link>
		<comments>http://eakcorp.com/2009/12/detect-ddos-if-it-is-an-attack/#comments</comments>
		<pubDate>Sat, 05 Dec 2009 20:23:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Guvenlik]]></category>
		<category><![CDATA[Sunucu]]></category>

		<guid isPermaLink="false">http://eakcorp.com/?p=178</guid>
		<description><![CDATA[http://forums.digitalpoint.com/showthread.php?t=592096
Depending on what type of traffic and also what type of attack it is you may need to reconfigure a number of system variables to prepare the system for extra load as it processes which connection is technically " fake ".
There are a number of tools -
Check to see if it is an attack - [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://forums.digitalpoint.com/showthread.php?t=592096">http://forums.digitalpoint.com/showthread.php?t=592096</a><br />
Depending on what type of traffic and also what type of attack it is you may need to reconfigure a number of system variables to prepare the system for extra load as it processes which connection is technically " fake ".</p>
<p>There are a number of tools -</p>
<p>Check to see if it is an attack - :: netstat -anp |grep 'tcp\|udp' | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -n<br />
<span id="more-178"></span><br />
Apache -</p>
<p>Mod_evasive<br />
httpd.conf - reconfiguration ( timeout, keepalive, server spawn )</p>
<p>Connection Monitoring -</p>
<p>netstat -</p>
<p>- Run these commands to seek all connections on port 80, with type SYN.</p>
<p>netstat -n | grep :80 |wc -l</p>
<p>netstat -n | grep :80 | grep SYN |wc -l</p>
<p>install bwm-ng ( bandwidth monitor )</p>
<p>sysctl.conf - hardening/reconfiguration. Helps the box handle extra load as connections are being processed.</p>
<p>Enable syncookies as well via echo 1 > /proc/sys/net/ipv4/tcp_syncookies</p>
]]></content:encoded>
			<wfw:commentRss>http://eakcorp.com/2009/12/detect-ddos-if-it-is-an-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using iptables to rate-limit incoming connections</title>
		<link>http://eakcorp.com/2009/04/using-iptables-to-rate-limit-incoming-connections/</link>
		<comments>http://eakcorp.com/2009/04/using-iptables-to-rate-limit-incoming-connections/#comments</comments>
		<pubDate>Sun, 05 Apr 2009 11:13:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Guvenlik]]></category>
		<category><![CDATA[Sunucu]]></category>

		<guid isPermaLink="false">http://debian.eakcorp.net/?p=120</guid>
		<description><![CDATA[
The iptables firewall has several useful extension modules which can be used to in addition to the basic firewall functionality. One of the more interesting of these extensions is the "recent" module which allows you to match recent connections, and perform simple throttling on incoming connections.
We've previously described keeping SSH access secure by limiting which [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.debian-administration.org/articles/187"><img class="alignleft" src="http://www.debian-administration.org/images/logo.png" alt="" width="104" height="111" /></a><br />
The iptables firewall has several useful extension modules which can be used to in addition to the basic firewall functionality. One of the more interesting of these extensions is the "recent" module which allows you to match recent connections, and perform simple throttling on incoming connections.</p>
<p>We've previously described keeping SSH access secure by limiting which users can connect, or just firewalling access so that only a small list of trusted IP addresses can connect. In most cases this is sufficient to protect your system.</p>
<p>However there are times when you have to allow arbitary incoming connections, when you are travelling for example.</p>
<p>In these situations you can open up your system to allow incoming connections and be the target of a dictionary attack - literally a machine trying to connect and login over and over again using usernames and passwords from a dictionary.</p>
<p>These attempts will be logged in your /var/log/auth.log file like this:</p>
<p>sshd[x]: Illegal user admin from aa.bb.cc.dd<br />
sshd[x]: Illegal user test from  aa.bb.cc.dd<br />
sshd[x]: Illegal user guest from aa.bb.cc.dd</p>
<p>In this situation you can create a collection of firewalling rules which will deny access from remote clients who attempt to connect "too many" times.</p>
<p>If you have an existing firewall in place, using iptables, then adding the rules is very straightforward.</p>
<p>The way the recent module works is fairly straightforward, you basically add IP addresses to a list, which can then be used in the future to test connection attempts against. This allows you to limit the number of connections against either a number of seconds, or connection attempts. In our example we'll do both.</p>
<p>An example is probably the simplest way to illustrate how it works. The following two rules will limit incoming connections to port 22 to no more than 3 attemps in a minute - an more than that will be dropped:</p>
<p><strong>iptables -I INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent   --set</strong></p>
<p><strong>iptables -I INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent   --update --seconds 60 --hitcount 4 -j DROP</strong></p>
<p>The --state flag takes a comma seperated list of connection states as an argument, by using "--state NEW" as we did we make sure that only new connections are managed by the module.</p>
<p>The --set parameter in the first line will make sure that the IP address of the host which initiated the connection will be added to the "recent list", where it can be tested and used again in the future i.e. in our second rule.</p>
<p>The second rule is where the magic actually happens. The --update flag tests whether the IP address is in the list of recent connections, in our case each new connection on port 22 will be in the list because we used the --set flag to add it in the preceeding rule.</p>
<p>Once that's done the --seconds flag is used to make sure that the IP address is only going to match if the last connection was within the timeframe given. The --hitcount flag works in a similar way - matching only if the given count of connection attempts is greater than or equal to the number given.</p>
<p>Together the second line will DROP an incoming connection if:</p>
<p>* The IP address which initiated the connection has previously been added to the list and<br />
* The IP address has sent a packet in the past 60 seconds and<br />
* The IP address has sent more than 4 packets in total.</p>
<p>You can adjust the numbers yourself to limit connections further, so the following example will drop incoming connections which make more than 2 connection attempts upon port 22 within ten minutes:</p>
<p><strong>iptables -I INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent \<br />
--set</strong></p>
<p><strong>iptables -I INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent \<br />
--update --seconds 600 --hitcount 2 -j DROP</strong></p>
<p>If you wish to test these rules you can script a number of connection attempts from an external host with the netcat package.</p>
<p>The following script attempts to connect to the IP address 192.168.1.1 5 times. The first couple of attempts you should see a welcome banner such as "SSH-2.0-OpenSSH_3.8.1p1 Debian-8.sarge.4" - after that the script will hang as it's packets are dropped and no response is sent:</p>
<p><strong>#!/bin/bash</strong></p>
<p><strong>for i in `seq 1 5` ; do<br />
echo 'exit' | nc 192.168.1.1 22 ;<br />
done</strong></p>
<p>There's a lot of documentation on the netfilter/iptables firewall, and it's available modules which you can find in the Netfilter Extension HOWTO.</p>
<p>This HOWTO contains documentation on many different modules, along with examples. A recommended read if you're interested in Linux firewalling.</p>
<p>If you wish to experiment with rules and testing it's worth remembering how to remove all active rules. The following commands will flush your iptables filewall, and remove all currently active rules:<br />
<strong><br />
iptables -F<br />
iptables -X</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://eakcorp.com/2009/04/using-iptables-to-rate-limit-incoming-connections/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blocking a DNS DDOS using the fail2ban package</title>
		<link>http://eakcorp.com/2009/02/blocking-a-dns-ddos-using-the-fail2ban-package/</link>
		<comments>http://eakcorp.com/2009/02/blocking-a-dns-ddos-using-the-fail2ban-package/#comments</comments>
		<pubDate>Mon, 09 Feb 2009 15:28:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Guvenlik]]></category>
		<category><![CDATA[Programlama]]></category>
		<category><![CDATA[Sunucu]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://debian.eakcorp.net/?p=94</guid>
		<description><![CDATA[[ad#ad-1]
Are you tired of getting multi-thousand line emails from the logcheck package that contain multiple reports of denied queries from named? If so this article will show how you can reject these DDOS attempts via the fail2ban package.
apt-get install fail2ban
mkdir /var/log/named
chmod a+w /var/log/named
Next, edit /etc/bind/named.conf.local and add the following lines
logging {
channel security_file {
file "/var/log/named/security.log" versions [...]]]></description>
			<content:encoded><![CDATA[<p>[ad#ad-1]<br />
Are you tired of getting multi-thousand line emails from the logcheck package that contain multiple reports of denied queries from named? If so this article will show how you can reject these DDOS attempts via the fail2ban package.</p>
<p>apt-get install fail2ban</p>
<pre>mkdir /var/log/named
chmod a+w /var/log/named</pre>
<p>Next, edit /etc/bind/named.conf.local and add the following lines</p>
<p>logging {<br />
channel security_file {<br />
file "/var/log/named/security.log" versions 3 size 30m;<br />
severity dynamic;         print-time yes;     };<br />
category security {         security_file;     };<br />
};</p>
<p>now to set up fail2ban.  Edit the /etc/fail2ban/jail.conf file and change from:</p>
<pre>[named-refused-udp]
enabled  = false to:true</pre>
<pre>[named-refused-tcp]</pre>
<pre>enabled  = false to true</pre>
<p>Then restart fail2ban in the usual manner,</p>
<pre>/etc/init.d/fail2ban restart

<a href="http://www.debian-administration.org/articles/623" target="_blank">read more article for click</a></pre>
]]></content:encoded>
			<wfw:commentRss>http://eakcorp.com/2009/02/blocking-a-dns-ddos-using-the-fail2ban-package/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Static IP on Debian and Ubuntu Linux</title>
		<link>http://eakcorp.com/2009/01/how-to-static-ip-on-debian-and-ubuntu-linux/</link>
		<comments>http://eakcorp.com/2009/01/how-to-static-ip-on-debian-and-ubuntu-linux/#comments</comments>
		<pubDate>Wed, 28 Jan 2009 23:45:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Sunucu]]></category>

		<guid isPermaLink="false">http://debian.eakcorp.net/?p=74</guid>
		<description><![CDATA[[ad#ad-1]
hi,
open with nano /etc/network/interface file and replace or add this line and make save.
# The primary network interface
allow-hotplug eth0
iface eth0 inet static
address ??.1??.4.234
netmask 255.255.255.0
network ??.1??.4.0
broadcast ??.1??.4.255
gateway ??.1??.4.1
?? your ip
Then restart network interface, /etc/init.d/networking restart
]]></description>
			<content:encoded><![CDATA[<p>[ad#ad-1]<br />
hi,<br />
open with nano /etc/network/interface file and replace or add this line and make save.</p>
<p># The primary network interface<br />
allow-hotplug eth0<br />
iface eth0 inet static<br />
address ??.1??.4.234<br />
netmask 255.255.255.0<br />
network ??.1??.4.0<br />
broadcast ??.1??.4.255<br />
gateway ??.1??.4.1<br />
?? your ip<br />
Then restart network interface, /etc/init.d/networking restart</p>
]]></content:encoded>
			<wfw:commentRss>http://eakcorp.com/2009/01/how-to-static-ip-on-debian-and-ubuntu-linux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sunucunuzu Pinglere Kapatin</title>
		<link>http://eakcorp.com/2009/01/sunucunuzu-pinglere-kapatin/</link>
		<comments>http://eakcorp.com/2009/01/sunucunuzu-pinglere-kapatin/#comments</comments>
		<pubDate>Sun, 04 Jan 2009 11:01:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Guvenlik]]></category>
		<category><![CDATA[Sunucu]]></category>

		<guid isPermaLink="false">http://debian.eakcorp.net/?p=33</guid>
		<description><![CDATA[Ufak bir onlem de olsa onlemin buyugu kucugu olmaz diyerek sunucumuzu ping isteklerine tamamen cevam vermez hale getiriyoruz bu sekilde bir takim DDOS saldirilarina ufantanda olsa onlem almis oluyoruz "Emniyet kemeri takmakta ufak bir ayrintidir fakat takmak hayat kurtarir"
nano  /etc/sysctl.conf dosyamizi aciyoruz ve bu satirlari ekliyoruz olanlarin degerlerini olmayanlarin tamamini   ekliyoruz
net.ipv4.icmp_echo_ignore_broadcasts = 1
net.ipv4.icmp_echo_ignore_all [...]]]></description>
			<content:encoded><![CDATA[<p>Ufak bir onlem de olsa onlemin buyugu kucugu olmaz diyerek sunucumuzu ping isteklerine tamamen cevam vermez hale getiriyoruz bu sekilde bir takim DDOS saldirilarina ufantanda olsa onlem almis oluyoruz <strong>"</strong><em>Emniyet kemeri takmakta ufak bir ayrintidir fakat takmak hayat kurtarir</em><strong>"</strong></p>
<p>nano  /etc/sysctl.conf dosyamizi aciyoruz ve bu satirlari ekliyoruz olanlarin degerlerini olmayanlarin tamamini <img src='http://eakcorp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  ekliyoruz</p>
<p>net.ipv4.icmp_echo_ignore_broadcasts = 1<br />
net.ipv4.icmp_echo_ignore_all = 1<br />
net.ipv4.icmp_ignore_bogus_error_responses = 1</p>
<p>sonrada kontrol ediyoruz pinglere cevap verip vermedigini sunucumuzun.[ad#ad-1]</p>
]]></content:encoded>
			<wfw:commentRss>http://eakcorp.com/2009/01/sunucunuzu-pinglere-kapatin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
