<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Güvenlik | M. Şahin KURU</title>
	<atom:link href="https://www.sahinkuru.com.tr/guvenlik/feed" rel="self" type="application/rss+xml" />
	<link>https://www.sahinkuru.com.tr</link>
	<description>Senior System Architect • Linux &#38; Microsoft Core Infra • Cloud &#38; DC &#38; Network Consultant • Cybersecurity &#38; Digital Forensics • Enterprise Backup &#38; Disaster Recovery</description>
	<lastBuildDate>Sun, 04 Dec 2022 02:03:31 +0000</lastBuildDate>
	<language>tr</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
<site xmlns="com-wordpress:feed-additions:1">117096499</site>	<item>
		<title>UZAK MASAÜSTÜ BAĞLANTISI ŞİFRE HATIRLAMA SORUNU  (Windows Defender Credential Guard Kaydedilmiş Kimlik Bilgilerini Kullanmaya İzin Vermiyor)</title>
		<link>https://www.sahinkuru.com.tr/2022/12/04/uzak-masaustu-baglantisi-sifre-hatirlama-sorunu-windows-defender-credential-guard-kaydedilmis-kimlik-bilgilerini-kullanmaya-izin-vermiyor.html</link>
					<comments>https://www.sahinkuru.com.tr/2022/12/04/uzak-masaustu-baglantisi-sifre-hatirlama-sorunu-windows-defender-credential-guard-kaydedilmis-kimlik-bilgilerini-kullanmaya-izin-vermiyor.html#comments</comments>
		
		<dc:creator><![CDATA[M. Şahin KURU]]></dc:creator>
		<pubDate>Sun, 04 Dec 2022 02:01:25 +0000</pubDate>
				<category><![CDATA[Cloud (Bulut Bilişim)]]></category>
		<category><![CDATA[Güvenlik]]></category>
		<category><![CDATA[Server Systems]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">https://www.sahinkuru.com.tr/?p=1287</guid>

					<description><![CDATA[<p>Windows Defender Credential Guard Kaydedilmiş Kimlik Bilgilerini Kullanmaya İzin Vermiyor Windows Defender Credential Guard does not allow using saved credentials Yukarıda yazan &#8221;Windows Defender Credential&#8230;</p>
The post <a href="https://www.sahinkuru.com.tr/2022/12/04/uzak-masaustu-baglantisi-sifre-hatirlama-sorunu-windows-defender-credential-guard-kaydedilmis-kimlik-bilgilerini-kullanmaya-izin-vermiyor.html">UZAK MASAÜSTÜ BAĞLANTISI ŞİFRE HATIRLAMA SORUNU  (Windows Defender Credential Guard Kaydedilmiş Kimlik Bilgilerini Kullanmaya İzin Vermiyor)</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></description>
										<content:encoded><![CDATA[<p>Windows Defender Credential Guard Kaydedilmiş Kimlik Bilgilerini Kullanmaya İzin Vermiyor</p>



<p>Windows Defender Credential Guard does not allow using saved credentials</p>



<p>Yukarıda yazan &#8221;Windows Defender Credential Guard Kaydedilmiş Kimlik Bilgilerini Kullanmaya İzin Vermiyor&#8221; hatasını aldığınızda istemci bilgisayarınızda yapmanız gerekenler sırası ile;</p>



<p>çalıştır&#8217;a regedit.exe yazıp açılan pencerede,</p>



<p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard alanına gidin ve 2 adet dword değer oluşturun</p>



<p>1) EnableVirtualizationBasedSecurity isminde değeri 0 olacak</p>



<p>2) RequirePlatformSecurityFeatures isminde değeri 0 olacak</p>



<p>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa alanına gidin ve 1 adet dword değer oluşturun</p>



<p>1) LsaCfgFlags isminde değeri 0 olacak.</p>



<p>Sonrasında istemci bilgisayarınızı yeniden başlatın artık şifrelerinizi kaydedebileceksiniz.</p>The post <a href="https://www.sahinkuru.com.tr/2022/12/04/uzak-masaustu-baglantisi-sifre-hatirlama-sorunu-windows-defender-credential-guard-kaydedilmis-kimlik-bilgilerini-kullanmaya-izin-vermiyor.html">UZAK MASAÜSTÜ BAĞLANTISI ŞİFRE HATIRLAMA SORUNU  (Windows Defender Credential Guard Kaydedilmiş Kimlik Bilgilerini Kullanmaya İzin Vermiyor)</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.sahinkuru.com.tr/2022/12/04/uzak-masaustu-baglantisi-sifre-hatirlama-sorunu-windows-defender-credential-guard-kaydedilmis-kimlik-bilgilerini-kullanmaya-izin-vermiyor.html/feed</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1287</post-id>	</item>
		<item>
		<title>Hide DNS Software Version</title>
		<link>https://www.sahinkuru.com.tr/2020/12/12/hide-dns-software-version.html</link>
					<comments>https://www.sahinkuru.com.tr/2020/12/12/hide-dns-software-version.html#respond</comments>
		
		<dc:creator><![CDATA[M. Şahin KURU]]></dc:creator>
		<pubDate>Sat, 12 Dec 2020 00:26:20 +0000</pubDate>
				<category><![CDATA[Cloud (Bulut Bilişim)]]></category>
		<category><![CDATA[Güvenlik]]></category>
		<category><![CDATA[İnformation Technology]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Server Systems]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">https://www.sahinkuru.com.tr/?p=1228</guid>

					<description><![CDATA[<p>Sometimes a new vulnerability is found in DNS software and script kiddies are scanning the Internet to exploit unpatched systems. It&#8217;s a best practice to&#8230;</p>
The post <a href="https://www.sahinkuru.com.tr/2020/12/12/hide-dns-software-version.html">Hide DNS Software Version</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></description>
										<content:encoded><![CDATA[<p>Sometimes a new vulnerability is found in DNS software and script kiddies are scanning the Internet to exploit unpatched systems. It&#8217;s a best practice to hide software version on your DNS servers, although this is not a real protection it just makes a little harder to find your servers via scanning.</p>



<p>Use&nbsp;<code>dig</code>&nbsp;command to find which version is running on your name servers:</p>



<pre class="wp-block-code"><code>$ dig +short @ns1.example.com version.bind txt chaos
"9.8.2rc1-RedHat-9.8.2-0.23.rc1.el6_5.1"
</code></pre>



<h2 class="wp-block-heading" id="bind">Bind</h2>



<p>To hide version in when using&nbsp;<a href="http://www.isc.org/downloads/bind/">Bind</a>, open&nbsp;<code>named.conf</code>&nbsp;configuration file using your favorite editor, go to&nbsp;<code>options</code>&nbsp;section and set a custom version string using&nbsp;<code>version</code>&nbsp;option.</p>



<p>Example:</p>



<pre class="wp-block-code"><code><em>// /etc/named.conf
</em>options {
  <em>// Hide bind version
</em>  version "unknown";
};
</code></pre>



<p>Restart the server (use&nbsp;<code>bind9</code>&nbsp;instead of&nbsp;<code>named</code>&nbsp;on systems based on Debian):</p>



<pre class="wp-block-code"><code>$ sudo service named restart
Stopping named: .                                          <strong>&#91;</strong>  OK  <strong>]</strong>
Starting named:                                            <strong>&#91;</strong>  OK  <strong>]</strong>
</code></pre>



<p>Verify that server is returning new version string:</p>



<pre class="wp-block-code"><code>$ dig +short @ns1.example.com version.bind txt chaos
"unknown"
</code></pre>



<h2 class="wp-block-heading" id="knot">Knot</h2>



<p>Edit&nbsp;<code>knot.conf</code>&nbsp;and set&nbsp;<code>version</code>&nbsp;parameter in&nbsp;<code>system</code>&nbsp;section to&nbsp;<code>off</code>:</p>



<pre class="wp-block-code"><code>system <strong>{</strong>
  <em># Used for answer to CH TXT 'version.server' or 'version.bind'</em>
  version off;
<strong>}</strong>
</code></pre>



<p>Restart the server to apply changes:</p>



<pre class="wp-block-code"><code>$ sudo service knot restart
Stopping knot: .                                          <strong>&#91;</strong>  OK  <strong>]</strong>
Starting knot:                                            <strong>&#91;</strong>  OK  <strong>]</strong>
</code></pre>



<h2 class="wp-block-heading" id="mydns">MyDNS</h2>



<p>TODO</p>



<h2 class="wp-block-heading" id="nsd">NSD</h2>



<p>Edit&nbsp;<code>nsd.conf</code>&nbsp;configuration file and set&nbsp;<code>hide-version</code>&nbsp;parameter to&nbsp;<code>yes</code>&nbsp;in&nbsp;<code>server</code>&nbsp;section.</p>



<pre class="wp-block-code"><code>server:
  <em># /etc/nsd/nsd.conf</em>
  <em># Don't answer VERSION.BIND and VERSION.SERVER CHAOS class queries</em>
  hide-version: yes
</code></pre>



<p>Restart NSD server:</p>



<pre class="wp-block-code"><code>$ sudo service nsd restart
Stopping nsd:                                              <strong>&#91;</strong>  OK  <strong>]</strong>
Starting nsd:                                              <strong>&#91;</strong>  OK  <strong>]</strong>
</code></pre>



<h2 class="wp-block-heading" id="powerdns">PowerDNS</h2>



<p>Edit /etc/pdns/pdns.conf and set&nbsp;<code>version-string</code>&nbsp;to&nbsp;<code>anonymous</code>&nbsp;then restart PowerDNS server.</p>



<pre class="wp-block-code"><code>version-string<strong>=</strong>anonymous
</code></pre>



<h2 class="wp-block-heading" id="tinydns">TinyDNS</h2>



<p>TinyDNS doesn&#8217;t expose version.</p>



<h2 class="wp-block-heading" id="microsoft-dns">Microsoft DNS</h2>



<p>To control how the server responds to version query, use&nbsp;<code>dnscmd</code>&nbsp;command with EnableVersionQuery parameter. Possible values:</p>



<ul class="wp-block-list"><li><strong>0x00000000</strong>&nbsp;(DNS_VERSION_QUERY_OFF) No version information will be returned.</li><li><strong>0x00000001</strong>&nbsp;(DNS_VERSION_QUERY_FULL) The server responds with major operating system version, minor operating system version, and operating system revision.</li><li><strong>0x00000002</strong>&nbsp;(DNS_VERSION_QUERY_MINIMAL) The server responds with major operating system version and minor operating system version.</li></ul>



<p>Example:</p>



<pre class="wp-block-code"><code>dnscmd /config /EnableVersionQuery 0
</code></pre>



<p>On Windows Server 2008 and Windows Server 2008 R2, the default value is 0x00000001. On Windows Server 2012 and Windows Server 2012 R2, the default value is 0x00000000.</p>



<h2 class="wp-block-heading" id="yadifa">YADIFA</h2>



<p>Yadifa version can be hidden setting&nbsp;<code>version</code>&nbsp;in&nbsp;<code>main</code>&nbsp;section:</p>



<pre class="wp-block-code"><code>&lt;main&gt;
  version "not disclosed"
&lt;/main&gt;</code></pre>The post <a href="https://www.sahinkuru.com.tr/2020/12/12/hide-dns-software-version.html">Hide DNS Software Version</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.sahinkuru.com.tr/2020/12/12/hide-dns-software-version.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1228</post-id>	</item>
		<item>
		<title>How to Disable LFD Notification for Permanent IP Block?</title>
		<link>https://www.sahinkuru.com.tr/2020/11/15/how-to-disable-lfd-notification-for-permanent-ip-block.html</link>
					<comments>https://www.sahinkuru.com.tr/2020/11/15/how-to-disable-lfd-notification-for-permanent-ip-block.html#respond</comments>
		
		<dc:creator><![CDATA[M. Şahin KURU]]></dc:creator>
		<pubDate>Sun, 15 Nov 2020 19:38:34 +0000</pubDate>
				<category><![CDATA[Cloud (Bulut Bilişim)]]></category>
		<category><![CDATA[Güvenlik]]></category>
		<category><![CDATA[İnformation Technology]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Server Systems]]></category>
		<guid isPermaLink="false">https://www.sahinkuru.com.tr/?p=1223</guid>

					<description><![CDATA[<p>Many of the clients are getting lots of LFD notification about IP block due to SSH failure. Do the following steps to disable such notifications?&#8230;</p>
The post <a href="https://www.sahinkuru.com.tr/2020/11/15/how-to-disable-lfd-notification-for-permanent-ip-block.html">How to Disable LFD Notification for Permanent IP Block?</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></description>
										<content:encoded><![CDATA[<p>Many of the clients are getting lots of LFD notification about IP block due to SSH failure. Do the following steps to disable such notifications? Here we provide an example notification regarding IP block.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p>Time: Fri Oct 24 06:25:44 2014 +0100</p><p>IP: 91.201.244.50 (UA/Ukraine/-)</p><p>Failures: 10 (ftpd)</p><p>Interval: 3600 seconds</p><p>Blocked: Permanent Block</p></blockquote>



<p>Steps to disable IP block LFD notifications.</p>



<p>1) Login to WHM.</p>



<p>2) Navigate to “ConfigServer Security &amp; Firewall” under “Plugin” section.</p>



<div class="wp-block-image"><figure class="aligncenter"><a href="https://www.interserver.net/tips/wp-content/uploads/2018/03/Disable-lfd-for-ip-block1.png"><img decoding="async" src="https://www.interserver.net/tips/wp-content/uploads/2018/03/Disable-lfd-for-ip-block1.png" alt="Disable lfd for ip block" class="wp-image-9102"/></a></figure></div>



<p>3) Click on “Firewall Configuration” button to edit the CSF configuration File.</p>



<div class="wp-block-image"><figure class="aligncenter"><a href="https://www.interserver.net/tips/wp-content/uploads/2018/03/Disable-lfd-for-ip-block2.png"><img decoding="async" src="https://www.interserver.net/tips/wp-content/uploads/2018/03/Disable-lfd-for-ip-block2-1024x550.png" alt="Disable lfd for ip block" class="wp-image-9103"/></a></figure></div>



<p>4) Search for “LF_PERMBLOCK_ALERT” on the configuration file and click on “Off” button.</p>



<div class="wp-block-image"><figure class="aligncenter"><a href="https://www.interserver.net/tips/wp-content/uploads/2018/03/Disable-lfd-for-ip-block3.png"><img decoding="async" src="https://www.interserver.net/tips/wp-content/uploads/2018/03/Disable-lfd-for-ip-block3.png" alt="Disable lfd for ip block" class="wp-image-9104"/></a></figure></div>



<p>5) Click on “Change” button to save the changes.</p>



<div class="wp-block-image"><figure class="aligncenter"><a href="https://www.interserver.net/tips/wp-content/uploads/2018/03/Disable-lfd-for-ip-block4.png"><img decoding="async" src="https://www.interserver.net/tips/wp-content/uploads/2018/03/Disable-lfd-for-ip-block4-1024x263.png" alt="Disable lfd for ip block" class="wp-image-9105"/></a></figure></div>



<p>We need to restart csf and lfd services to enable all changes that we made in the above steps. So click on the “Restart csf+lfd” button to restart both the services.</p>



<div class="wp-block-image"><figure class="aligncenter"><a href="https://www.interserver.net/tips/wp-content/uploads/2018/03/Disable-lfd-for-ip-block5.png"><img decoding="async" src="https://www.interserver.net/tips/wp-content/uploads/2018/03/Disable-lfd-for-ip-block5.png" alt="Disable lfd for ip block" class="wp-image-9106"/></a></figure></div>



<p>We can do above settings from the server via terminal.</p>



<p>1) Log in to the server via SSH.</p>



<p>2) Open csf configuration file and search for “LF_PERMBLOCK_ALERT” and set the value to 0.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p># vi /etc/csf/csf.conf</p><p>LF_PERMBLOCK_ALERT =0</p></blockquote>



<p>3) Then you need to restart both csf and lfd services to enable the changes.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow"><p># service csf restart</p><p># service lfd restart</p></blockquote>



<p>If you need any further help please do reach our support department.</p>The post <a href="https://www.sahinkuru.com.tr/2020/11/15/how-to-disable-lfd-notification-for-permanent-ip-block.html">How to Disable LFD Notification for Permanent IP Block?</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.sahinkuru.com.tr/2020/11/15/how-to-disable-lfd-notification-for-permanent-ip-block.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1223</post-id>	</item>
		<item>
		<title>PHP Warning: Module already loaded in Unknown on line 0</title>
		<link>https://www.sahinkuru.com.tr/2020/10/31/php-warning-module-already-loaded-in-unknown-on-line-0.html</link>
					<comments>https://www.sahinkuru.com.tr/2020/10/31/php-warning-module-already-loaded-in-unknown-on-line-0.html#respond</comments>
		
		<dc:creator><![CDATA[M. Şahin KURU]]></dc:creator>
		<pubDate>Fri, 30 Oct 2020 23:59:41 +0000</pubDate>
				<category><![CDATA[Cloud (Bulut Bilişim)]]></category>
		<category><![CDATA[Güvenlik]]></category>
		<category><![CDATA[İnformation Technology]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Server Systems]]></category>
		<category><![CDATA[Web Tasarım]]></category>
		<guid isPermaLink="false">https://www.sahinkuru.com.tr/?p=1215</guid>

					<description><![CDATA[<p>1. Make sure extension=&#8221;imagick.so&#8221; is commented-out from these: /usr/lib/php.ini/usr/local/lib/php.ini/opt/cpanel/ea-php56/root/etc/php.ini/opt/cpanel/ea-php56/root/etc/php.d/02-pecl.ini 2. Make sure extension=&#8221;imagick.so&#8221; is not commented out in: /opt/cpanel/ea-php56/root/etc/php.d/imagick.ini 3. Run /usr/sbin/cagefsctl &#8211;force-update 4. Restart&#8230;</p>
The post <a href="https://www.sahinkuru.com.tr/2020/10/31/php-warning-module-already-loaded-in-unknown-on-line-0.html">PHP Warning: Module already loaded in Unknown on line 0</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></description>
										<content:encoded><![CDATA[<ul class="wp-block-list"><li></li></ul>



<pre class="wp-block-code"><code>PHP Warning:  Module 'imagick' already loaded in Unknown on line 0</code></pre>



<p></p>



<p>1. Make sure extension=&#8221;imagick.so&#8221; is commented-out from these:</p>



<p>/usr/lib/php.ini<br>/usr/local/lib/php.ini<br>/opt/cpanel/ea-php56/root/etc/php.ini<br><strong>/opt/cpanel/ea-php56/root/etc/php.d/02-pecl.ini</strong></p>



<p>2. Make sure extension=&#8221;imagick.so&#8221; is not commented out in:</p>



<p>/opt/cpanel/ea-php56/root/etc/php.d/imagick.ini</p>



<p>3. Run</p>



<p>/usr/sbin/cagefsctl &#8211;force-update</p>



<p>4. Restart Apache</p>



<p>Now my users can send email to my support addresses at all my helpdesk scripts without receiving a &#8220;could not deliver, PHP Warning: Module &#8216;imagick&#8217; already loaded in Unknown on line 0&#8221; message back to them, and I&#8217;ve re-opened normal operation of my helpdesks.</p>



<p>Thank you guys so much! You guys have no idea how grateful I am right now&#8230; the sleep depravation and holiday support overload was already taking a toll, and this was really putting a hurt on me. Wow, maybe I can go get a couple hours of sleep now. THANK YOU!</p>The post <a href="https://www.sahinkuru.com.tr/2020/10/31/php-warning-module-already-loaded-in-unknown-on-line-0.html">PHP Warning: Module already loaded in Unknown on line 0</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.sahinkuru.com.tr/2020/10/31/php-warning-module-already-loaded-in-unknown-on-line-0.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1215</post-id>	</item>
		<item>
		<title>How to delist a blacklisted IP address</title>
		<link>https://www.sahinkuru.com.tr/2020/07/25/how-to-delist-a-blacklisted-ip-address.html</link>
					<comments>https://www.sahinkuru.com.tr/2020/07/25/how-to-delist-a-blacklisted-ip-address.html#respond</comments>
		
		<dc:creator><![CDATA[M. Şahin KURU]]></dc:creator>
		<pubDate>Sat, 25 Jul 2020 00:20:34 +0000</pubDate>
				<category><![CDATA[Cloud (Bulut Bilişim)]]></category>
		<category><![CDATA[Güvenlik]]></category>
		<category><![CDATA[Haberler]]></category>
		<category><![CDATA[İnformation Technology]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mac OS]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Server Systems]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">https://www.sahinkuru.com.tr/?p=1205</guid>

					<description><![CDATA[<p>PROBLEM My IP address is blacklisted by some sender reputation RBL and emails are not delivered.How can I remove it form the blacklists? RBLs Our&#8230;</p>
The post <a href="https://www.sahinkuru.com.tr/2020/07/25/how-to-delist-a-blacklisted-ip-address.html">How to delist a blacklisted IP address</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></description>
										<content:encoded><![CDATA[<p><strong>PROBLEM</strong></p>



<p>My IP address is blacklisted by some sender reputation RBL and emails are not delivered.<br>How can I remove it form the blacklists?</p>



<p><strong>RBLs</strong></p>



<p><strong>Our dedicated IP are only assigned to one account at a time, so we expect those users to take responsibility for all of the mail that is sent through their account.&nbsp;</strong></p>



<p><strong><em>Please note: in the event that a sending domain (and not the IP address) is blacklisted, that domain’s controller will be responsible for handling the delisting request.</em></strong></p>



<p>RBLs are blacklists of IP addresses. One IP address enters into a blacklist for spamming activity.<br>Here you can find instructions on what to do once the IP address entered into one or more blacklists.</p>



<p><strong>Why did you get into the blacklist in the first place?</strong></p>



<p>First of all, make sure you identified the reason for the blacklisting.<br>If you didn’t identify and resolve it, you will just make things worse by asking for delisting. The IP will be quickly re-blacklisted and it will be harder to delist it.<br>So, check why the IP has been blacklisted and fix the source of the problem before going ahead.<br>Once you resolved all the problems (if it is a new IP address there is no problem to resolve, of course), you can go ahead with the delisting with the following instructions.</p>



<p><strong>First time cleanup</strong></p>



<p>If you just acquired this IP address, make sure that the dns reverse lookup is set before requesting removal from blacklists.<br>When asked for a reason for requesting delisting, tell that you just acquired the IP address.</p>



<p><strong>Delisting</strong></p>



<p>First of all, let Valli check a bunch of RBLs for you:&nbsp;<a href="http://multirbl.valli.org/lookup">http://multirbl.valli.org/lookup</a><br>For each RBL where the IP is listed, follow the link and read the instructions on how to delist.<br>Each RBL has it’s own rules, some of them require an email verification in order to delist, some of them require that you explain the reasons of the listing (if it’s a new ip address just tell them that this ip address has just been assigned to you), some of them don’t allow delisting at all (it’s automatic after some time).</p>



<p>In the Valli list of RBLs, some are more important than others.<br>Some important blacklists are&nbsp;<strong>Spamhaus</strong>,&nbsp;<strong>Barracuda</strong>,&nbsp;<strong>SORBS</strong>,&nbsp;<strong>V4BL</strong>.<br>Start requesting the delisting from the important ones and then proceed until you requested delisting from all of the blacklists that allow it. The ones that don’t accept delisting requests will delist automatically after some time (like rbldns.ru).</p>



<p>There are some important blacklists that are not checked by Valli, make sure you remove the IP address also from those:</p>



<p><strong>Outlook (Microsoft):</strong>&nbsp;<a href="https://support.microsoft.com/en-us/getsupport?oaspworkflow=start_1.0.0.0&amp;wfname=capsub&amp;productkey=edfsmsbl3&amp;locale=en-us&amp;ccsid=636014233369251686">https://support.microsoft.com/en-us/getsupport?oaspworkflow=start_1.0.0.0&amp;wfname=capsub&amp;productkey=edfsmsbl3&amp;locale=en-us&amp;ccsid=636014233369251686<br></a>This list doesn’t provide a test to check if the IP is blacklisted, you can easily test by sending an email&nbsp;from the ESVA IP address&nbsp;to a hotmail email address. If the email does go through then the IP address is not blacklisted, if the email isn’t delivered you can read in the SMTP response message the reason. You can find the SMTP response message in the maillog. Copy the text because it is needed in the removal request.</p>



<p><strong>Microsoft Office:</strong>&nbsp;<a href="https://sender.office.com/Delist">https://sender.office.com/Delist</a><br>This service offers a reputation check. You will be required to enter the ip address and your email address where a confirmation link will be sent.</p>



<p><strong>Trend Micro:</strong>&nbsp;<a href="https://www.ers.trendmicro.com/reputations">https://ers.trendmicro.com/reputations</a><br>Reputation check available.</p>



<p><strong>Sophos:</strong>&nbsp;<a href="https://www.sophos.com/en-us/threat-center/ip-lookup.aspx">https://www.sophos.com/en-us/threat-center/ip-lookup.aspx</a><br>Reputation check available.</p>



<p><strong>Symantec:</strong>&nbsp;<a href="http://ipremoval.sms.symantec.com/lookup/">http://ipremoval.sms.symantec.com/</a><br>Reputation check available.</p>



<p><strong>Yahoo:</strong>&nbsp;<a href="http://help.yahoo.com/l/us/yahoo/mail/postmaster/bulkv2.html">http://help.yahoo.com/l/us/yahoo/mail/postmaster/bulkv2.html</a><br>This service is not just for bulk mailers, it is also used for delisting requests. Just like the Outlook service above, it does not offer a reputation lookup service so you should test for blacklisting trying to send an email to a yahoo email address and checking the result as described above for Outlook. In order to request delisting you must have a yahoo account, which you can create for free.</p>



<p><strong>AT&amp;T:</strong>&nbsp;<a href="http://rbl.att.net/cgi-bin/rbl/block_admin.cgi">http://rbl.att.net/cgi-bin/rbl/block_admin.cgi</a><br>It is not possible to check whether an ip address is listed or not. If your ip address is listed your messages will be bounced with an SMTP clause similar to this:<br>553 5.3.0 alph155 DNSBL:ATTRBL 521&lt; 199.169.39.199 &gt;_is_blocked.For assistance forward this email to abuse_rbl@abuse-att.net&gt;</p>



<p><strong>Barracuda:&nbsp;</strong><a href="https://www.barracudacentral.org/rbl/removal-request">https://www.barracudacentral.org/rbl/removal-request</a>Delist request.</p>



<p><strong>Cloudmark:</strong>&nbsp;<a href="https://csi.cloudmark.com/en/reset/">https://csi.cloudmark.com/en/reset/</a><br>Delist request.</p>



<p><strong>Comcast:</strong>&nbsp;<a href="http://postmaster.comcast.net/block-removal-request.html">http://postmaster.comcast.net/block-removal-request.html</a><br>Delist request.</p>



<p><strong>McAfee:</strong>&nbsp;<a href="https://www.mcafee.com/enterprise/en-us/threat-center/threat-feedback.html">https://www.mcafee.com/enterprise/en-us/threat-center/threat-feedback.html</a><br>Delist request.</p>



<p><strong>Mimecast:</strong>&nbsp;<a href="https://www.mimecast.com/senderfeedback/">https://www.mimecast.com/senderfeedback/</a><br>Delist request.</p>



<p><strong>ProofPoint:</strong>&nbsp;<a href="https://ipcheck.proofpoint.com/">https://ipcheck.proofpoint.com/</a><br>Delist request.</p>



<p><strong>SORBS:</strong>&nbsp;<a href="http://www.sorbs.net/overview.shtml">http://www.sorbs.net/overview.shtml</a><br>Delisting and Reputation check available.</p>



<p><strong>SpamCop:</strong>&nbsp;<a href="https://www.spamcop.net/bl.shtml">https://www.spamcop.net/bl.shtml</a><br>Delisting and Reputation check available.</p>



<p><strong>Spam rats:</strong>&nbsp;<a href="https://www.spamrats.com/removal.php">https://www.spamrats.com/removal.php</a><br>Delisting service.</p>



<p><strong>Spamhaus:</strong>&nbsp;<a href="https://www.spamhaus.org/lookup/">https://www.spamhaus.org/lookup/</a><br>Delisting service.</p>



<p><strong>SURBL:</strong>&nbsp;<a href="http://www.surbl.org/surbl-analysis">http://www.surbl.org/surbl-analysis</a><br>Delisting service.</p>



<p><strong>URIBL:</strong>&nbsp;<a href="https://admin.uribl.com/">https://admin.uribl.com/</a><br>Delist service.</p>



<p><strong>Whitelisting</strong></p>



<p>It is a good thing also to enter into white lists:<br><a href="https://www.dnswl.org/selfservice/">https://www.dnswl.org/selfservice/</a></p>



<p><strong>IP Reputation Monitoring</strong></p>



<p>There are some services that allow you to monitor your reputation and check it over time. You can take advantage of this services if you send a few thousand emails on a daily basis to domains like gmail or hotmail. For small amounts of email traffic they don’t provide feedback.</p>



<p><strong>Google:</strong>&nbsp;<a href="https://postmaster.google.com/">https://postmaster.google.com/</a><br><strong>Microsoft:</strong>&nbsp;<a href="https://postmaster.live.com/snds/JMRP.aspx">https://postmaster.live.com/snds/JMRP.aspx</a></p>The post <a href="https://www.sahinkuru.com.tr/2020/07/25/how-to-delist-a-blacklisted-ip-address.html">How to delist a blacklisted IP address</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.sahinkuru.com.tr/2020/07/25/how-to-delist-a-blacklisted-ip-address.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1205</post-id>	</item>
		<item>
		<title>How to change Exim mail server IP address in cpanel server</title>
		<link>https://www.sahinkuru.com.tr/2020/05/01/reverse-dns-does-not-match-smtp-banner.html</link>
					<comments>https://www.sahinkuru.com.tr/2020/05/01/reverse-dns-does-not-match-smtp-banner.html#respond</comments>
		
		<dc:creator><![CDATA[M. Şahin KURU]]></dc:creator>
		<pubDate>Fri, 01 May 2020 04:53:24 +0000</pubDate>
				<category><![CDATA[Cloud (Bulut Bilişim)]]></category>
		<category><![CDATA[Güvenlik]]></category>
		<category><![CDATA[İnformation Technology]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Server Systems]]></category>
		<guid isPermaLink="false">https://www.sahinkuru.com.tr/?p=1194</guid>

					<description><![CDATA[<p>Sometimes the mail which we sent being rejected by recipient (such as google.com, yahoo.com, domain.com..etc..) due to server IP blacklisted in SPAM database. Why its&#8230;</p>
The post <a href="https://www.sahinkuru.com.tr/2020/05/01/reverse-dns-does-not-match-smtp-banner.html">How to change Exim mail server IP address in cpanel server</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></description>
										<content:encoded><![CDATA[<p>Sometimes the mail which we sent being rejected by recipient (such as google.com, yahoo.com, domain.com..etc..) due to server IP blacklisted in SPAM database. Why its happen ? due to lack of monitoring. What we will do to prevent ? We need to monitor the server properly its mean if you got any relay alert or lots of mails in queue you should look into mail service and identify whether anybody SPAM from server or any open relay is there. If our IP address got blacklisted, first we need to check the server IP using&nbsp;<a href="https://mxtoolbox.com/blacklists.aspx" target="_blank" rel="noreferrer noopener">this link</a>.</p>



<p>If its blacklisted, You need to take further action to remove the IP address from blacklist. They don’t remove your IP immediately and it will take time. So mean while we can change our exim outbound IP address to solve our issue.</p>



<h4 class="wp-block-heading">1) Add new IP address to server</h4>



<p>Check on your server whether if you have additional IP. If so you can leave this step. If no you need to add new IP address (Make sure you should have additional free IP on your server. If no you should ask your Server provider to get additional IP) on your server to proceed further.</p>



<pre class="wp-block-preformatted"># Checking assigned IP address in server #
# ifconfig

# Adding new IP address into server #
# ifconfig eth0:1 xxx.xx.xx.xx netmask 255.255.255.0
</pre>



<h4 class="wp-block-heading">2) Add new IP address to mailips file</h4>



<p>Just open&nbsp;<strong>/etc/mailips</strong>&nbsp;file and add your new IP address with below format. So that all the domain Outbound mails take new IP address from your server.</p>



<pre class="wp-block-preformatted"># Adding new IP address to mailips file #
# nano /etc/mailips
*:xxx.xx.xx.xx
</pre>



<h4 class="wp-block-heading">3) Add new IP address to exim.conf file</h4>



<p>Just open&nbsp;<strong>/etc/exim.conf</strong>&nbsp;file and find&nbsp;<strong>remote_smtp:</strong>&nbsp;then remove&nbsp;<strong>interface &amp; helo_data</strong>&nbsp;line and add new interface like below.</p>



<pre class="wp-block-preformatted"># By default exim.conf file like below #
# nano /etc/exim.conf
remote_smtp:
  driver = smtp
  interface = ${if exists {/etc/mailips}{${lookup{$original_domain}lsearch{/etc/mailips}{$value}{${lookup{$sender_address_domain}lsearch{/etc/mailips}{$value}{${lookup{${perl{get_sender_from_uid}}}lsearch*{/etc/mailips}{$value}{}}}}}}}}
  helo_data = ${if exists {/etc/mailhelo}{${lookup{$original_domain}lsearch{/etc/mailhelo}{$value}{${lookup{$sender_address_domain}lsearch{/etc/mailhelo}{$value}{${lookup{${perl{get_sender_from_uid}}}lsearch*{/etc/mailhelo}{$value}{$primary_hostname}}}}}}}{$primary_hostname}}

# Make Change into exim.conf file #
# nano /etc/exim.conf
remote_smtp:
  driver = smtp
  interface = xxx.xx.xx.xx
</pre>



<h4 class="wp-block-heading">4) Adding RDNS</h4>



<p>Ask your Provider to create RDNS for your IP and assign the same to&nbsp;<strong>/etc/mail_reverse_dns</strong>&nbsp;file. Normally it will take 24-48 hours its purely depends upon your DNS provider. Add your RDNS with below format. So that all the domain Outbound mails will delivery properly or else some of the top provider reject your email due to RDNS. RDNS should be your server hostname.</p>



<pre class="wp-block-preformatted"># Adding RDNS entry #
# nano /etc/mail_reverse_dns
xxx.xx.xx.xx: server.2daygeek.com
</pre>



<h4 class="wp-block-heading">5) Changing file attribute</h4>



<p>Use the below command to change files attribute, so that it wont get reset to default automatically.</p>



<pre class="wp-block-preformatted"># Making copy of exim.conf file #
# chattr +aui /etc/exim.conf

# Rebuilding exim.conf file #
# chattr +aui /etc/mailips
</pre>



<h4 class="wp-block-heading">6) Restart exim</h4>



<p>Use the below command to restart exim and send test mail then verify the header you can see new IP address.</p>



<pre class="wp-block-preformatted"># Restart exim service #
# service exim restart
</pre>



<p>Hope you are in SAFE.</p>The post <a href="https://www.sahinkuru.com.tr/2020/05/01/reverse-dns-does-not-match-smtp-banner.html">How to change Exim mail server IP address in cpanel server</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.sahinkuru.com.tr/2020/05/01/reverse-dns-does-not-match-smtp-banner.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1194</post-id>	</item>
		<item>
		<title>DELL İdrac Uzaktan Erişim Portları</title>
		<link>https://www.sahinkuru.com.tr/2019/07/02/dell-idrac-uzaktan-erisim-portlari.html</link>
					<comments>https://www.sahinkuru.com.tr/2019/07/02/dell-idrac-uzaktan-erisim-portlari.html#respond</comments>
		
		<dc:creator><![CDATA[M. Şahin KURU]]></dc:creator>
		<pubDate>Mon, 01 Jul 2019 23:17:33 +0000</pubDate>
				<category><![CDATA[Cloud (Bulut Bilişim)]]></category>
		<category><![CDATA[Güvenlik]]></category>
		<category><![CDATA[İnformation Technology]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Server Systems]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">https://www.sahinkuru.com.tr/?p=1184</guid>

					<description><![CDATA[<p>Merhaba; Bu yazımda DELL İdrac&#8217;inizi bir firewall arkasından internete çıkarmak isterseniz gerekli olan portları paylaşacağım. (Genel olarak uzaktan erişim cihazlarınızı internete çıkarmamanızı tavsiye ederim, ama&#8230;</p>
The post <a href="https://www.sahinkuru.com.tr/2019/07/02/dell-idrac-uzaktan-erisim-portlari.html">DELL İdrac Uzaktan Erişim Portları</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></description>
										<content:encoded><![CDATA[<p>Merhaba;</p>



<p>Bu yazımda DELL İdrac&#8217;inizi bir firewall arkasından internete çıkarmak isterseniz gerekli olan portları paylaşacağım. (Genel olarak uzaktan erişim cihazlarınızı internete çıkarmamanızı tavsiye ederim, ama bazen ihtiyaç olabiliyor. </p>



<p>Umarım faydası olur.</p>



<p></p>



<ul class="wp-block-list"><li>22 SSH</li><li> 23 Telnet</li><li> 80 HTTP</li><li> 443 HTTPS</li><li> 161 SNMP</li><li> 3668 Virtual Media server</li><li> 5869 Remote racadm server</li><li> 5900-5901 Console Redirection</li></ul>The post <a href="https://www.sahinkuru.com.tr/2019/07/02/dell-idrac-uzaktan-erisim-portlari.html">DELL İdrac Uzaktan Erişim Portları</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.sahinkuru.com.tr/2019/07/02/dell-idrac-uzaktan-erisim-portlari.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1184</post-id>	</item>
		<item>
		<title>The remote session was disconnected because there are no Remote Desktop License Servers available to provide a license</title>
		<link>https://www.sahinkuru.com.tr/2018/06/16/the-remote-session-was-disconnected-because-there-are-no-remote-desktop-license-servers-available-to-provide-a-license.html</link>
					<comments>https://www.sahinkuru.com.tr/2018/06/16/the-remote-session-was-disconnected-because-there-are-no-remote-desktop-license-servers-available-to-provide-a-license.html#respond</comments>
		
		<dc:creator><![CDATA[M. Şahin KURU]]></dc:creator>
		<pubDate>Sat, 16 Jun 2018 13:28:04 +0000</pubDate>
				<category><![CDATA[Cloud (Bulut Bilişim)]]></category>
		<category><![CDATA[Güvenlik]]></category>
		<category><![CDATA[Haberler]]></category>
		<category><![CDATA[İnformation Technology]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Server Systems]]></category>
		<category><![CDATA[Windows]]></category>
		<guid isPermaLink="false">https://www.sahinkuru.com.tr/?p=1124</guid>

					<description><![CDATA[<p>Remote Desktop Services Session Host rolü herhangi bir lisans sunucu olmadan 120 gün süre ile kesintisiz olarak hizmet verebilir. Bu zaman zarfı içerisinde ya sunucunuzu&#8230;</p>
The post <a href="https://www.sahinkuru.com.tr/2018/06/16/the-remote-session-was-disconnected-because-there-are-no-remote-desktop-license-servers-available-to-provide-a-license.html">The remote session was disconnected because there are no Remote Desktop License Servers available to provide a license</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></description>
										<content:encoded><![CDATA[<p>Remote Desktop Services Session Host rolü herhangi bir lisans sunucu olmadan 120 gün süre ile kesintisiz olarak hizmet verebilir. Bu zaman zarfı içerisinde ya sunucunuzu lisanslamalı yada merkezi bir lisans sunucunuz varsa (KMS gibi) bu sunucu üzerine lisansı girmeli  bu sunucuyu Remote Desktop Sunucunuza göstermelisiniz. Verilen zaman aralığında sunucuya lisans anahtarı girilmezse bu sürenin bitimi ile beraber sunucuya logon olurken aşağıdaki gibi bir hata mesajı ile karşılaşabilirsiniz.</p>
<p>&nbsp;</p>
<p><a href="https://www.sahinkuru.com.tr/wp-content/uploads/error-no-licence.png"><img fetchpriority="high" decoding="async" data-attachment-id="1126" data-permalink="https://www.sahinkuru.com.tr/2018/06/16/the-remote-session-was-disconnected-because-there-are-no-remote-desktop-license-servers-available-to-provide-a-license.html/error-no-licence" data-orig-file="https://www.sahinkuru.com.tr/wp-content/uploads/error-no-licence.png" data-orig-size="562,145" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="error-no-licence" data-image-description="" data-image-caption="" data-large-file="https://www.sahinkuru.com.tr/wp-content/uploads/error-no-licence.png" class="aligncenter size-full wp-image-1126" src="https://www.sahinkuru.com.tr/wp-content/uploads/error-no-licence.png" alt="" width="562" height="145" srcset="https://www.sahinkuru.com.tr/wp-content/uploads/error-no-licence.png 562w, https://www.sahinkuru.com.tr/wp-content/uploads/error-no-licence-300x77.png 300w" sizes="(max-width: 562px) 100vw, 562px" /></a></p>
<p>Yukarıda bulunan hata mesajına ek olarak sunucu üzerinde bulunan Event Viewer (Olay Günlüğü) içerisinde de aşağıdaki gibi bir hata mesajı ile karşılaşabilirsiniz.</p>
<p>Event ID:1128</p>
<p>Source:TerminalServices-RemoteConnectionManager</p>
<p>&nbsp;</p>
<p><a href="https://www.sahinkuru.com.tr/wp-content/uploads/1128eventid.png"><img decoding="async" data-attachment-id="1127" data-permalink="https://www.sahinkuru.com.tr/2018/06/16/the-remote-session-was-disconnected-because-there-are-no-remote-desktop-license-servers-available-to-provide-a-license.html/1128eventid" data-orig-file="https://www.sahinkuru.com.tr/wp-content/uploads/1128eventid.png" data-orig-size="640,445" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="1128eventid" data-image-description="" data-image-caption="" data-large-file="https://www.sahinkuru.com.tr/wp-content/uploads/1128eventid.png" class="aligncenter size-full wp-image-1127" src="https://www.sahinkuru.com.tr/wp-content/uploads/1128eventid.png" alt="" width="640" height="445" srcset="https://www.sahinkuru.com.tr/wp-content/uploads/1128eventid.png 640w, https://www.sahinkuru.com.tr/wp-content/uploads/1128eventid-300x209.png 300w" sizes="(max-width: 640px) 100vw, 640px" /></a></p>
<p>Bazı durumlarda sunucuya lisans anahtarı girmek yada lisans sunucusunu göstermek yerine bu süreyi yeniden başlatmak isteyebilirsiniz.</p>
<p>&nbsp;</p>
<p><a href="https://www.sahinkuru.com.tr/wp-content/uploads/regkey.png"><img decoding="async" data-attachment-id="1129" data-permalink="https://www.sahinkuru.com.tr/2018/06/16/the-remote-session-was-disconnected-because-there-are-no-remote-desktop-license-servers-available-to-provide-a-license.html/regkey" data-orig-file="https://www.sahinkuru.com.tr/wp-content/uploads/regkey.png" data-orig-size="867,566" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="regkey" data-image-description="" data-image-caption="" data-large-file="https://www.sahinkuru.com.tr/wp-content/uploads/regkey.png" class="aligncenter size-full wp-image-1129" src="https://www.sahinkuru.com.tr/wp-content/uploads/regkey.png" alt="" width="867" height="566" srcset="https://www.sahinkuru.com.tr/wp-content/uploads/regkey.png 867w, https://www.sahinkuru.com.tr/wp-content/uploads/regkey-300x196.png 300w, https://www.sahinkuru.com.tr/wp-content/uploads/regkey-768x501.png 768w" sizes="(max-width: 867px) 100vw, 867px" /></a></p>
<p>Bu durumda <strong>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\RCM\GracePeriod</strong> altında bulunan L$RTMTIMEBOMB_ registry değerini silmelisiniz. Bu registry değerini silmek için ilgili registry kaydı üzerinde admin haklarına sahip olmalısınız. İlgili registry değerini sildikten sonra sunucuyu yeniden başlatmalısınız. Sunucu yeniden başlatıldıktan sonra bu süre yeniden başlayacaktır.</p>
<p>Faydalı Olması Dileğiyle …</p>The post <a href="https://www.sahinkuru.com.tr/2018/06/16/the-remote-session-was-disconnected-because-there-are-no-remote-desktop-license-servers-available-to-provide-a-license.html">The remote session was disconnected because there are no Remote Desktop License Servers available to provide a license</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.sahinkuru.com.tr/2018/06/16/the-remote-session-was-disconnected-because-there-are-no-remote-desktop-license-servers-available-to-provide-a-license.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1124</post-id>	</item>
		<item>
		<title>Windows 10 Fall Creators güncellemesinden sonra ağdaki paylaşılan klasöre erişememe hatası</title>
		<link>https://www.sahinkuru.com.tr/2018/06/09/windows-10-fall-creators-guncellemesinden-sonra-agdaki-paylasilan-klasore-erisememe-hatasi.html</link>
					<comments>https://www.sahinkuru.com.tr/2018/06/09/windows-10-fall-creators-guncellemesinden-sonra-agdaki-paylasilan-klasore-erisememe-hatasi.html#respond</comments>
		
		<dc:creator><![CDATA[M. Şahin KURU]]></dc:creator>
		<pubDate>Sat, 09 Jun 2018 20:38:10 +0000</pubDate>
				<category><![CDATA[Güvenlik]]></category>
		<category><![CDATA[Haberler]]></category>
		<category><![CDATA[İnformation Technology]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Server Systems]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[bilgisayarınızı ağ üzerindeki güvenli olmayan veya kötü amaçlı cihazlardan korumanıza yardımcı olur.]]></category>
		<category><![CDATA[kimliği doğrulanmamış konuk erişimini engellediğinden bu paylaşılan klasöre erişemezsiniz. Bu ilkeler]]></category>
		<category><![CDATA[Kuruluşunuzun güvenlik ilkeleri]]></category>
		<guid isPermaLink="false">https://www.sahinkuru.com.tr/?p=1120</guid>

					<description><![CDATA[<p>Ağ da paylaşılan bir disk yada nas cihazı kullanıyorsanız, ve güncelleme sonrası guest olarak bağlanmaya çalıştığınızda; &#8220;Kuruluşunuzun güvenlik ilkeleri, kimliği doğrulanmamış konuk erişimini engellediğinden bu&#8230;</p>
The post <a href="https://www.sahinkuru.com.tr/2018/06/09/windows-10-fall-creators-guncellemesinden-sonra-agdaki-paylasilan-klasore-erisememe-hatasi.html">Windows 10 Fall Creators güncellemesinden sonra ağdaki paylaşılan klasöre erişememe hatası</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></description>
										<content:encoded><![CDATA[<p>Ağ da paylaşılan bir disk yada nas cihazı kullanıyorsanız, ve güncelleme sonrası guest olarak bağlanmaya çalıştığınızda;</p>
<p class="">&#8220;Kuruluşunuzun güvenlik ilkeleri, kimliği doğrulanmamış konuk erişimini engellediğinden bu paylaşılan klasöre erişemezsiniz. Bu ilkeler, bilgisayarınızı ağ üzerindeki güvenli olmayan veya kötü amaçlı cihazlardan korumanıza yardımcı olur. &#8220;</p>
<p>hatası alıyorsanız çözüm;</p>
<p>Çalıştır kısmına &#8220;gpedit.msc&#8221; yazarak ulaşabilirsiniz</p>
<p class="">&#8220;Yerel Grup İlkesi / Bilgisayar yapılandırması / Yönetim şablonları / Ağ / Ağ bağlantıları /</p>
<p>Lanman iş istasyonu / &#8220;Güvenli olmayan konuk oturum açma işlemlerini etkinleştir&#8221; &lt;<strong>Etkin</strong>&gt;&#8221;</p>
<p>Örnek Resim;</p>
<p><a href="https://www.sahinkuru.com.tr/wp-content/uploads/gpedit.jpg"><img decoding="async" data-attachment-id="1121" data-permalink="https://www.sahinkuru.com.tr/2018/06/09/windows-10-fall-creators-guncellemesinden-sonra-agdaki-paylasilan-klasore-erisememe-hatasi.html/gpedit" data-orig-file="https://www.sahinkuru.com.tr/wp-content/uploads/gpedit.jpg" data-orig-size="942,530" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="gpedit" data-image-description="" data-image-caption="" data-large-file="https://www.sahinkuru.com.tr/wp-content/uploads/gpedit.jpg" class="size-full wp-image-1121 alignleft" src="https://www.sahinkuru.com.tr/wp-content/uploads/gpedit.jpg" alt="" width="942" height="530" srcset="https://www.sahinkuru.com.tr/wp-content/uploads/gpedit.jpg 942w, https://www.sahinkuru.com.tr/wp-content/uploads/gpedit-300x169.jpg 300w, https://www.sahinkuru.com.tr/wp-content/uploads/gpedit-768x432.jpg 768w" sizes="(max-width: 942px) 100vw, 942px" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>İyi çalışmalar.</p>The post <a href="https://www.sahinkuru.com.tr/2018/06/09/windows-10-fall-creators-guncellemesinden-sonra-agdaki-paylasilan-klasore-erisememe-hatasi.html">Windows 10 Fall Creators güncellemesinden sonra ağdaki paylaşılan klasöre erişememe hatası</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.sahinkuru.com.tr/2018/06/09/windows-10-fall-creators-guncellemesinden-sonra-agdaki-paylasilan-klasore-erisememe-hatasi.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1120</post-id>	</item>
		<item>
		<title>Portspoof ile Network Scanner’ları Yanıtlamak (Centos 7)</title>
		<link>https://www.sahinkuru.com.tr/2017/09/03/portspoof-ile-network-scannerlari-yanitlamak-centos-7.html</link>
					<comments>https://www.sahinkuru.com.tr/2017/09/03/portspoof-ile-network-scannerlari-yanitlamak-centos-7.html#respond</comments>
		
		<dc:creator><![CDATA[M. Şahin KURU]]></dc:creator>
		<pubDate>Sun, 03 Sep 2017 01:22:01 +0000</pubDate>
				<category><![CDATA[Cloud (Bulut Bilişim)]]></category>
		<category><![CDATA[Güvenlik]]></category>
		<category><![CDATA[Haberler]]></category>
		<category><![CDATA[İnformation Technology]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Server Systems]]></category>
		<guid isPermaLink="false">https://www.sahinkuru.com.tr/?p=1094</guid>

					<description><![CDATA[<p>Portspoof, bir network scanner uygulaması kullanarak sunucular üzerinde çalışan servisleri tespit etmek isteyen saldırganların işlerini zorlaştırmak ve tarama sonucunu manupule etmek sureti ile onları yanıltmak&#8230;</p>
The post <a href="https://www.sahinkuru.com.tr/2017/09/03/portspoof-ile-network-scannerlari-yanitlamak-centos-7.html">Portspoof ile Network Scanner’ları Yanıtlamak (Centos 7)</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></description>
										<content:encoded><![CDATA[<p class="p1"><span class="s1"><a href="https://www.sahinkuru.com.tr/wp-content/uploads/cover1.jpg"><img decoding="async" data-attachment-id="1096" data-permalink="https://www.sahinkuru.com.tr/2017/09/03/portspoof-ile-network-scannerlari-yanitlamak-centos-7.html/cover1" data-orig-file="https://www.sahinkuru.com.tr/wp-content/uploads/cover1.jpg" data-orig-size="3248,1380" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;Victoria - Fotolia&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cover1" data-image-description="" data-image-caption="" data-large-file="https://www.sahinkuru.com.tr/wp-content/uploads/cover1-1024x435.jpg" class="alignleft wp-image-1096 size-medium" src="https://www.sahinkuru.com.tr/wp-content/uploads/cover1-300x127.jpg" alt="" width="300" height="127" srcset="https://www.sahinkuru.com.tr/wp-content/uploads/cover1-300x127.jpg 300w, https://www.sahinkuru.com.tr/wp-content/uploads/cover1-768x326.jpg 768w, https://www.sahinkuru.com.tr/wp-content/uploads/cover1-1024x435.jpg 1024w" sizes="(max-width: 300px) 100vw, 300px" /></a>Portspoof</span><span class="s2">, bir network scanner uygulaması kullanarak sunucular üzerinde çalışan servisleri tespit etmek isteyen saldırganların işlerini zorlaştırmak ve tarama sonucunu manupule etmek sureti ile onları yanıltmak üzere geliştirilmiş enteresan bir uygulamadır.</span></p>
<p class="p1"><span class="s2">Bildiğiniz gibi network scanner uygulamalarının uzaktaki bir sistemde çalışan servisleri tespit etmeleri için kullandıkları bir takım teknikler vardır. Bu tekniklerden en tipik olanı ise TCP’nin üçlü el sıkışma prensibinden hareketle uzak sunucunun tüm portlarına (ya da ilgilenilen portlarına) birer SYN paketi göndermek ve alınacak cevaba göre ilgili servisin mevcudiyeti ya da durumu ile ilgili karara varmaktır. Örnek olarak üzerinde bir web sunucusu çalıştığını bildiğiniz uzaktaki bir sistemin 80. portuna bir SYN paketi gönderirseniz ve uzak sunucudaki bu servis çalışır durumdaysa -ayrıca herhangi bir engelleme yoksa- cevap olarak SYN+ACK paketi alırsınız. Bu şekilde ilgili servisin çalışır vaziyette olduğu uzaktan tespit edilir ve örneğin nmap ilgili port’u OPEN olarak bildirir. Aynı şekilde gönderilen SYN paketine RST paketi dönerse, uzak sunucuda ilgili portu dinleyen bir servis olmadığı anlaşılır ve scanner uygulaması durumu CLOSED olarak değerlendirir. Eğer uzak sunucu bir firewall üzerinden korunuyorsa ve SYN paketini gönderdiğiniz porta erişim izniniz yoksa ilgili paket -genel olarak- drop edilir bu nedenle de geriye herhangi bir paket döndürülmez. Bu durumda da network scanner uygulaması durumu FILTERED olarak bildirir, bu şekilde de uzaktaki sistemin bir firewall’a sahip olduğunu tespit edebilirsiniz.</span><span id="more-1094"></span></p>
<p class="p1"><span class="s2">İşte </span><span class="s1">portspoof</span><span class="s2"> bu tip yöntemler kullanarak sunucunuz üzerindeki servisler hakkında bilgi almak isteyen saldırganların işini zorlaştırmak için gönderilen her SYN paketine SYN+ACK döndürerek tüm portların açıkmış gibi görünmesini sağlamaktadır. Bu durum saldırganın hangi portun ucunda gerçekten hangi servisin olduğunu tespit edebilmesini doğrudan zorlaştıracaktır. Ayrıca elinizde tüm portları açık görünen bir sistem varsa, gerçekten hangi portta hangi servisin çalıştığını tespit etmek için ilgili portlar üzerinde versiyon tespiti (probing) yapmanız gerekir. Nmap gibi uygulamaların version tespiti için spesifik servislere ait fingerprint’lerin tutulduğu database’leri olduğundan normal şartlarda bu tespit işlemi fazla uzun sürmeyecektir ancak </span><span class="s1">portspoof</span><span class="s2"> gelen her versiyon tespit taraması için bir sahte bir fingerprint döner, bu nedenle saldırgan servis tespiti için gerçekten uzun süreler harcamak zorunda kalacaktır. (Ben denemedim ama </span><span class="s1">portspoof</span><span class="s2">’un sitesinde tüm portlar -65535 adet- version detection için yaklaşık 8 saat gerekeceği yazmakta.)</span></p>
<p class="p1"><span class="s2">İşte yukarıda bahsedilen bu durumlardan ötürü sistemlerinizde </span><span class="s1">portspoof</span><span class="s2"> kullanmak isteyebilirsiniz. Böyle bir ihtiyaç için CentOS 7 üzerinde kurulum ve yapılandırma aşamaları aşağıdaki gibidir:</span></p>
<p class="p1"><span class="s2">Öncelikli olarak gereksinim paketlerini kuruyoruz. (Bunun için ben EPEL reposunu da kuruyorum.)</span></p>
<blockquote>
<p class="p3"><span class="s2"># rpm -Uvh http://mirror.vit.com.tr/mirror/Epel/7/x86_64/epel-release-7-1.noarch.rpm</span></p>
<p class="p3"><span class="s2"># yum install gcc gcc-c++ unzip</span></p>
</blockquote>
<p class="p1"><span class="s2">Gereksinim paketletinin kurulumundan sonra portspoof uygulamasını indiriyoruz:</span></p>
<blockquote>
<p class="p3"><span class="s2"># wget https://github.com/drk1wi/portspoof/archive/master.zip</span></p>
</blockquote>
<p class="p1"><span class="s2">ve kurulum aşamasına geçiyoruz:</span></p>
<blockquote>
<p class="p3"><span class="s2"># unzip master.zip</span></p>
<p class="p3"><span class="s2"># cd portspoof-master</span></p>
<p class="p3"><span class="s2"># ./configure &#8211;sysconfdir=/etc/</span></p>
<p class="p3"><span class="s2"># make &amp;&amp; make install</span></p>
</blockquote>
<p class="p1"><span class="s2">Bu adımın ardında, sisteme gelen tüm istekleri portspoof’a yönlendirmek için gerekli firewalld (iptables) kuralını ekleyeceğiz. Portspoof öntanımlı olarak tcp 4444 portunu dinliyor ve tüm bağlantı isteklerini portspoof üzerinden geçirmek için tüm portlara gelen bağlantı isteklerini 4444’e yani portspoof’a forward etmeniz gerekiyor. Bu noktada yönlendirme işlemini yapmadan önce portspoof’un araya girmesini istemediğiniz spesifik servisleriniz varsa bunlar için yönlendirme yapmamanız gerekiyor. Örnek olarak tcp 22’de ssh ve tcp 80’de web sunucu calistiran bir sistem için bu portlar haricinde kalan tüm diğer portlar için yönlendirme şu şekilde yapılmakta:</span></p>
<blockquote>
<p class="p3"><span class="s2"># firewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-forward-port=port=1-21:proto=tcp:toport=4444</span></p>
<p class="p3"><span class="s2"># firewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-forward-port=port=23-79:proto=tcp:toport=4444</span></p>
<p class="p3"><span class="s2"># firewall-cmd &#8211;permanent &#8211;zone=public &#8211;add-forward-port=port=81-65535:proto=tcp:toport=4444</span></p>
<p class="p3"><span class="s2"># systemctl restart firewalld</span></p>
</blockquote>
<p class="p1"><span class="s2"><b>Not:</b> Eğer klasik iptables kullanıyorsanız (CentOS 6.x sürümü vs.) kuralları aşağıdaki şekilde ekleyebilirsiniz:</span></p>
<blockquote>
<p class="p3"><span class="s2"># iptables -t nat -A PREROUTING -i eth0 -p tcp -m tcp -m multiport &#8211;dports 1:21,23:79,81:65535 -j REDIRECT &#8211;to-ports 4444</span></p>
<p class="p3"><span class="s2"># iptables-restore &lt; iptables-config</span></p>
</blockquote>
<p class="p1"><span class="s2">Yönlendirme işi de tamamlandıktan sonra portspoof’u çalıştırıyoruz. Bu noktada portspoof’un iki farklı modu’u bulunuyor. Tüm potların açık olarak gösterilmesini sağlayan mode’un yanu sıra version tespiti denemelerinde sahte finger print göndermek üzere kullanılan bir diğer modu bulunuyor. Ben saldırgan için işleri iyice çığırından çıkarmak için ikinci modu tercih ediyorum:</span></p>
<blockquote>
<p class="p3"><span class="s2"># portspoof -c /etc/portspoof.conf -s /etc/portspoof_signatures -D</span></p>
</blockquote>
<p class="p1"><span class="s2">Bu şekilde sisteminizin örnek olarak ilk 50 portunu tarayıp servis versiyonu tespit etmek isterseniz nmap’i aşağıdaki şekilde kullanabilirsiniz:</span></p>
<blockquote>
<p class="p3"><span class="s2"># nmap -sV -p 1.50 uzaksistem-ipsi </span></p>
</blockquote>
<p class="p1"><span class="s2">Sonuç aşağıdakine benzer şekilde eğlenceli olacaktır:</span></p>
<blockquote>
<p class="p3"><span class="s2"># nmap -sV -p 1-50 192.168.16.162</span></p>
<p class="p3"><span class="s2">Starting Nmap 6.40 ( http://nmap.org ) at 2014-08-30 22:33 EEST</span></p>
<p class="p3"><span class="s2">Nmap scan report for 192.168.16.162</span></p>
<p class="p3"><span class="s2">Host is up (0.00024s latency).</span></p>
<p class="p3"><span class="s2">PORT <span class="Apple-converted-space">  </span>STATE SERVICE VERSION</span></p>
<p class="p3"><span class="s2">1/tcp<span class="Apple-converted-space">  </span>open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0000000000000000000000000000000000000000000000000000000)</span></p>
<p class="p3"><span class="s2">2/tcp<span class="Apple-converted-space">  </span>open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0000000000000000000000000000000000000000000000000000000)</span></p>
<p class="p3"><span class="s2">3/tcp<span class="Apple-converted-space">  </span>open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0000000000000000000000000000000000000000000000000000000)</span></p>
<p class="p3"><span class="s2">4/tcp<span class="Apple-converted-space">  </span>open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0000000000000000000000000000000000000000000000000000000)</span></p>
<p class="p3"><span class="s2">5/tcp<span class="Apple-converted-space">  </span>open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0000000000000000000000000000000000000000000000000000000)</span></p>
<p class="p3"><span class="s2">6/tcp<span class="Apple-converted-space">  </span>open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ffffffffffffffffffffffffffffffffffffffffffffffffffff00)</span></p>
<p class="p3"><span class="s2">7/tcp<span class="Apple-converted-space">  </span>open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffffffffffff777778887777777777cffffffffffffffffffff00)</span></p>
<p class="p3"><span class="s2">8/tcp<span class="Apple-converted-space">  </span>open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffffffffff8000000000000000008888887cfcfffffffffffff00)</span></p>
<p class="p3"><span class="s2">9/tcp<span class="Apple-converted-space">  </span>open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ffffffffff80000088808000000888800000008887ffffffffff00)</span></p>
<p class="p3"><span class="s2">10/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffffffff70000088800888800088888800008800007ffffffff00)</span></p>
<p class="p3"><span class="s2">11/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffffffff000088808880000000000000088800000008fffffff00)</span></p>
<p class="p3"><span class="s2">12/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ffffffff80008808880000000880000008880088800008ffffff00)</span></p>
<p class="p3"><span class="s2">13/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ffffffff000000888000000000800000080000008800007fffff00)</span></p>
<p class="p3"><span class="s2">14/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffffff8000000000008888000000000080000000000007fffff00)</span></p>
<p class="p3"><span class="s2">15/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ffffff70000000008cffffffc0000000080000000000008fffff00)</span></p>
<p class="p3"><span class="s2">16/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ffffff8000000008ffffff007f8000000007cf7c80000007ffff00)</span></p>
<p class="p3"><span class="s2">17/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffff7880000780f7cffff7800f8000008fffffff80808807fff00)</span></p>
<p class="p3"><span class="s2">18/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fff78000878000077800887fc8f80007fffc7778800000880cff00)</span></p>
<p class="p3"><span class="s2">19/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ff70008fc77f7000000f80008f8000007f0000000000000888ff00)</span></p>
<p class="p3"><span class="s2">20/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ff0008f00008ffc787f70000000000008f000000087fff8088cf00)</span></p>
<p class="p3"><span class="s2">21/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0f7000f800770008777000000000000000f80008f7f70088000cf00)</span></p>
<p class="p3"><span class="s2">22/tcp open<span class="Apple-converted-space">  </span>ssh <span class="Apple-converted-space">    </span>OpenSSH 6.4 (protocol 2.0)</span></p>
<p class="p3"><span class="s2">23/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0f8008707ff07ff8000008088ff800000000f7000000f800808ff00)</span></p>
<p class="p3"><span class="s2">24/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0f7000f888f8007ff7800000770877800000cf780000ff00807ff00)</span></p>
<p class="p3"><span class="s2">25/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ff0808800cf0000ffff70000f877f70000c70008008ff8088fff00)</span></p>
<p class="p3"><span class="s2">26/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ff70800008ff800f007fff70880000087f70000007fcf7007fff00)</span></p>
<p class="p3"><span class="s2">27/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fff70000007fffcf700008ffc778000078000087ff87f700ffff00)</span></p>
<p class="p3"><span class="s2">28/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ffffc000000f80fff700007787cfffc7787fffff0788f708ffff00)</span></p>
<p class="p3"><span class="s2">29/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffff7000008f00fffff78f800008f887ff880770778f708ffff00)</span></p>
<p class="p3"><span class="s2">30/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ffffff8000007f0780cffff700000c000870008f07fff707ffff00)</span></p>
<p class="p3"><span class="s2">31/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ffffcf7000000cfc00008fffff777f7777f777fffffff707ffff00)</span></p>
<p class="p3"><span class="s2">32/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0cccccff0000000ff000008c8cffffffffffffffffffff807ffff00)</span></p>
<p class="p3"><span class="s2">33/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffffff70000000ff8000c700087fffffffffffffffcf808ffff00)</span></p>
<p class="p3"><span class="s2">34/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ffffffff800000007f708f000000c0888ff78f78f777c008ffff00)</span></p>
<p class="p3"><span class="s2">35/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffffffff800000008fff7000008f0000f808f0870cf7008ffff00)</span></p>
<p class="p3"><span class="s2">36/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ffffffffff7088808008fff80008f0008c00770f78ff0008ffff00)</span></p>
<p class="p3"><span class="s2">37/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffffffffffc8088888008cffffff7887f87ffffff800000ffff00)</span></p>
<p class="p3"><span class="s2">38/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffffffffffff7088888800008777ccf77fc777800000000ffff00)</span></p>
<p class="p3"><span class="s2">39/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffffffffffffff800888880000000000000000000800800cfff00)</span></p>
<p class="p3"><span class="s2">40/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffffffffffffffff70008878800000000000008878008007fff00)</span></p>
<p class="p3"><span class="s2">41/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffffffffffffffffff700008888800000000088000080007fff00)</span></p>
<p class="p3"><span class="s2">42/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffffffffffffffffffffc800000000000000000088800007fff00)</span></p>
<p class="p3"><span class="s2">43/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffffffffffffffffffffff7800000000000008888000008ffff00)</span></p>
<p class="p3"><span class="s2">44/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0fffffffffffffffffffffffff7878000000000000000000cffff00)</span></p>
<p class="p3"><span class="s2">45/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ffffffffffffffffffffffffffffffc880000000000008ffffff00)</span></p>
<p class="p3"><span class="s2">46/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ffffffffffffffffffffffffffffffffff7788888887ffffffff00)</span></p>
<p class="p3"><span class="s2">47/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0ffffffffffffffffffffffffffffffffffffffffffffffffffff00)</span></p>
<p class="p3"><span class="s2">48/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0000000000000000000000000000000000000000000000000000000)</span></p>
<p class="p3"><span class="s2">49/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0000000000000000000000000000000000000000000000000000000)</span></p>
<p class="p3"><span class="s2">50/tcp open<span class="Apple-converted-space">  </span>smtp<span class="Apple-converted-space">    </span>Unrecognized SMTP service (12345 0000000000000000000000000000000000000000000000000000000)</span></p>
</blockquote>
<p class="p1"><span class="s2">Portspoof ile ilgil tüm diğer detayları https://github.com/drk1wi/portspoof adresinden alabilirsiniz.</span></p>The post <a href="https://www.sahinkuru.com.tr/2017/09/03/portspoof-ile-network-scannerlari-yanitlamak-centos-7.html">Portspoof ile Network Scanner’ları Yanıtlamak (Centos 7)</a> first appeared on <a href="https://www.sahinkuru.com.tr">M. Şahin KURU</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.sahinkuru.com.tr/2017/09/03/portspoof-ile-network-scannerlari-yanitlamak-centos-7.html/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1094</post-id>	</item>
	</channel>
</rss>
