??????????????

??????????????????·????????豸??????????????80?????web???????????????????????????????????????????????????????????????????????????????telnet??

$ telnet 10.1.2.5 80
Trying 10.1.2.5...
telnet: Unable to connect to remote host: Connection refused

????????????????????????????????????????????????Apacheδ????????????????????????????????????????????????????????????telnet????????????????λ?????????????????????????????????web?????????????????????????????????web1???Apache?????web?????????????鶴???????????????????????

???????????telnet??????????????nmap?????ж????????????????????????????????????????а??nmap??????????????????????????nmap??????????web1???в???????????????????
$ nmap -p 80 10.1.2.5
Starting Nmap 4.62 ( http://nmap.org ) at 2009-02-05 18:49 PST
Interesting ports on web1 (10.1.2.5):
PORT STATE SERVICE
80/tcp filtered http

????nmap?????????????????????????ν"??????"?????????????????????????????????????????????£?nmap????????????????"???"????????????????????"????"?????????????????????????"????"????ζ??????з???????????????????????????????????????????????????10.1.1.1?????web1??????????????????????80????????????

???????????????????

??????????????????????????????????????????????Χ??С????????????????????????????????????????????????????????????????????в????????80?????á?

??????????????

??????????web1????????????????????80??????????????????????netstat -lnp???????г????д??????????????????????????????????????????????????????????????????????Ч????????????????grep?????????80??????????
$ sudo netstat -lnp | grep :80
tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN 919/apache

??????????????????????????????Э?顣???????????????????????????У?????????????????0???????????????????????У???????г???????????????????????????0.0.0.0??80??????????????????????ж??80??????????IP?й??????????Apache?????web1??????????????????????????п???10.1.2.5??80??

???????????????????????????????????????????????????????е?Apache??????????????????????????netstat??????????п????????????????????Apache????????

?????????????

????????????????????????????80?????????????web1??????????????????????????????????iptables?????г???????з???????????????????????????????????????????????
$  sudo /sbin/iptables -L
Chain INPUT (policy ACCEPT)
target     prot opt source               destination
Chain FORWARD (policy ACCEPT)
target     prot opt source               destination
Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination

??????????????????????ACCEPT?????????????????????????????п????????????????????????????????????????????????????????????
$  sudo /sbin/iptables -L
Chain INPUT (policy DROP)
target     prot opt source               destination
Chain FORWARD (policy DROP)
target     prot opt source               destination
Chain OUTPUT (policy DROP)
target     prot opt source               destination