1 (edytowany przez Skajper4 2014-02-19 00:57:04)

Temat: Transmission i spam w logach

Witam, otóż jest taki problem nad którym sobie siedzę przy herbatce i rozkminiam. Log jest cały "zapchany" przez transmission errorami.
Port jest otwarty (wg tutoriala), z ciekawości też przekierowałem.

Wed Feb 19 00:40:46 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 28 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:40:46 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 28 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:11 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 22 to 2001:0:5ef5:79fb:340b:3906:a9ef:730, port 44192 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:11 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 22 to 2001:0:5ef5:79fb:340b:3906:a9ef:730, port 44192 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:57 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:9d38:6ab8:4f2:3915:4109:e44b, port 33377 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:57 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:9d38:6ab8:4f2:3915:4109:e44b, port 33377 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:57 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:9d38:6ab8:34a3:ae27:b16f:d47b, port 50802 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:57 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:9d38:6ab8:34a3:ae27:b16f:d47b, port 50802 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:57 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:41:57 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:18 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 35 to 2001:0:9d38:6abd:2cdc:234f:ace8:d160, port 40000 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:18 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 35 to 2001:0:9d38:6abd:2cdc:234f:ace8:d160, port 40000 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:23 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 35 to 2001:0:5ef5:79fd:819:2289:a104:5ae5, port 12578 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:23 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 35 to 2001:0:5ef5:79fd:819:2289:a104:5ae5, port 12578 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:24 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 35 to 2001:0:5ef5:79fb:340b:3906:a9ef:730, port 44192 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:24 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 35 to 2001:0:5ef5:79fb:340b:3906:a9ef:730, port 44192 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:38 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 25 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:42:38 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 25 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:43:22 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 29 to 2001:0:9d38:6ab8:4f2:3915:4109:e44b, port 33377 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:43:22 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 29 to 2001:0:9d38:6ab8:4f2:3915:4109:e44b, port 33377 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:43:41 2014 daemon.err transmission-daemon[999]: Gravity (2013)[1080p.BRRip.x264.DTS.AC3][Dual Audio][Lektor i Napisy PL] Piece 67, which was just downloaded, failed its checksum test (torrent.c:3251)
Wed Feb 19 00:43:46 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:5ef5:79fb:340b:3906:a9ef:730, port 44192 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:43:46 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 21 to 2001:0:5ef5:79fb:340b:3906:a9ef:730, port 44192 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:44:00 2014 kern.notice kernel: [  316.384000] EXT4-fs (sda3): error count: 1
Wed Feb 19 00:44:00 2014 kern.notice kernel: [  316.388000] EXT4-fs (sda3): initial error at 16: ext4_lookup:1437: inode 47
Wed Feb 19 00:44:00 2014 kern.notice kernel: [  316.392000] EXT4-fs (sda3): last error at 16: ext4_lookup:1437: inode 47
Wed Feb 19 00:44:12 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 28 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)
Wed Feb 19 00:44:12 2014 daemon.err transmission-daemon[999]: Couldn't connect socket 28 to 2001:0:5ef5:79fb:1c28:3434:d1f0:2465, port 10146 (errno 1 - Operation not permitted) (net.c:288)

Router:

root@OpenWrt:~# cat /etc/config/firewall

config redirect
        option target 'DNAT'
        option src 'wan'
        option dest 'lan'
        option proto 'tcp'
        option dest_ip '192.168.2.1'
        option dest_port '80'
        option name 'GATEWAY'
        option src_dport '50'

config redirect
        option target 'DNAT'
        option src 'wan'
        option dest 'lan'
        option proto 'tcp'
        option src_dport '52'
        option dest_ip '192.168.2.1'
        option dest_port '22'
        option name 'ssh1'

config redirect
        option target 'DNAT'
        option src 'wan'
        option dest 'lan'
        option proto 'tcp'
        option dest_ip '192.168.2.2'
        option dest_port '80'
        option name 'WEBSERVER'
        option src_dport '60'

config redirect
        option target 'DNAT'
        option src 'wan'
        option dest 'lan'
        option proto 'tcp udp'
        option dest_ip '192.168.2.2'
        option dest_port '21'
        option name 'FTP'
        option src_dport '61'

config redirect
        option target 'DNAT'
        option src 'wan'
        option dest 'lan'
        option proto 'tcp'
        option dest_ip '192.168.2.2'
        option dest_port '22'
        option src_dport '62'
        option name 'ssh2'

config redirect
        option target 'DNAT'
        option src 'wan'
        option dest 'lan'
        option proto 'tcp udp'
        option dest_ip '192.168.2.2'
        option dest_port '9091'
        option name 'Transmission'
        option src_dport '65'

config defaults
        option syn_flood '1'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'REJECT'

config zone
        option name 'lan'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        option network 'lan'

config zone
        option name 'wan'
        option output 'ACCEPT'
        option masq '1'
        option mtu_fix '1'
        option network 'wan'
        option forward 'REJECT'
        option input 'REJECT'

config forwarding
        option src 'lan'
        option dest 'wan'

config rule
        option name 'Allow-DHCP-Renew'
        option src 'wan'
        option proto 'udp'
        option dest_port '68'
        option target 'ACCEPT'
        option family 'ipv4'

config rule
        option name 'Allow-Ping'
        option src 'wan'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-DHCPv6'
        option src 'wan'
        option proto 'udp'
        option src_ip 'fe80::/10'
        option src_port '547'
        option dest_ip 'fe80::/10'
        option dest_port '546'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Input'
        option src 'wan'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        list icmp_type 'router-solicitation'
        list icmp_type 'neighbour-solicitation'
        list icmp_type 'router-advertisement'
        list icmp_type 'neighbour-advertisement'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Forward'
        option src 'wan'
        option dest '*'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config include
        option path '/etc/firewall.user'

config rule
        option name 'transmission'
        option src 'wan'
        option target 'ACCEPT'
        option proto 'tcp'
        option dest_port '51413'

config redirect
        option target 'DNAT'
        option src 'wan'
        option dest 'lan'
        option proto 'tcp udp'
        option src_dport '51413'
        option dest_ip '192.168.2.2'
        option dest_port '51413'
        option name 'Transmission_zew_port'

serwer:

root@OpenWrt:~# cat /etc/config/firewall

config defaults
        option syn_flood '1'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'

config zone
        option name 'lan'
        list network 'lan'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'

config zone
        option name 'wan'
        list network 'wan'
        list network 'wan6'
        option output 'ACCEPT'
        option masq '1'
        option mtu_fix '1'
        option input 'ACCEPT'
        option forward 'ACCEPT'

config forwarding
        option src 'lan'
        option dest 'wan'

config rule
        option name 'Allow-DHCP-Renew'
        option src 'wan'
        option proto 'udp'
        option dest_port '68'
        option target 'ACCEPT'
        option family 'ipv4'

config rule
        option name 'Allow-Ping'
        option src 'wan'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-DHCPv6'
        option src 'wan'
        option proto 'udp'
        option src_ip 'fe80::/10'
        option src_port '547'
        option dest_ip 'fe80::/10'
        option dest_port '546'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Input'
        option src 'wan'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        list icmp_type 'router-solicitation'
        list icmp_type 'neighbour-solicitation'
        list icmp_type 'router-advertisement'
        list icmp_type 'neighbour-advertisement'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Forward'
        option src 'wan'
        option dest '*'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config include
        option path '/etc/firewall.user'

config rule
        option name 'transmission'
        option target 'ACCEPT'
        option dest_port '51413'
        option proto 'all'
        option src '*'

config rule
        option enabled '1'
        option target 'ACCEPT'
        option proto 'tcp udp'
        option dest_port '55'
        option name 'transmission2'
        option src 'lan'

2

Odp: Transmission i spam w logach

Skajper4 napisał/a:

Gravity (2013)[1080p.BRRip.x264.DTS.AC3][Dual Audio][Lektor i Napisy PL]

[OT]Lektor? Do tych stęków Sandry? Słaby film, nie polecam, wynudziłem się...[/OT]

3

Odp: Transmission i spam w logach

pepe2k napisał/a:
Skajper4 napisał/a:

Gravity (2013)[1080p.BRRip.x264.DTS.AC3][Dual Audio][Lektor i Napisy PL]

[OT]Lektor? Do tych stęków Sandry? Słaby film, nie polecam, wynudziłem się...[/OT]

Dziękuję za opinię big_smile, już anuluję tongue (w sumie pobieram tylko po to aby mieć ten spam w logach wink )

4

Odp: Transmission i spam w logach

Transmissin tak sieje jak nie może się do hostów dobić. W sumie to "normalnie".


OT: nie astronautka a doktor i dlatego wszystkie trzy stacje rozwaliła.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

5

Odp: Transmission i spam w logach

pepe2k napisał/a:
Skajper4 napisał/a:

Gravity (2013)[1080p.BRRip.x264.DTS.AC3][Dual Audio][Lektor i Napisy PL]

[OT]Lektor? Do tych stęków Sandry? Słaby film, nie polecam, wynudziłem się...[/OT]

+1 Wiecej sie wkurzylem z jej kocich ruchów jak poogladałem filmu

RB760iGS + RB260GS / Ryzen 5 2660 / 16G DDR4 / MiniITX - Inea 1G (https://i.imgur.com/TLbJVDw.png)
RB951-2HnD / Celeron J1900 / 4G DDR3 / MiniITX - Satpol 100M

6

Odp: Transmission i spam w logach

Odświeżę trochę temat, bo też mnie wkurzały te zapchane logi.
Od paru dni używam Gargoyle by Obsy i zauważyłem podobne byki w logach jak w pierwszym poście. Wcześniej korzystałem z własnej starej kompilacji OpenWRT na x86 z jakąś archaiczną wersją transmission i takich kwiatków nie miałem.
Żeby się tego pozbyć wystarczy w konfigu transmission przestawić opcję message_level na 0. Oczywiście pewnie pozbawi nas to też informacji w logach w przypadku wystąpienia innych błędów związanych z transmission, więc w razie potrzeby trzeba sobie to z powrotem włączyć.

7

Odp: Transmission i spam w logach

Przekompiluj transmisison i wywal z niego jakiekolwik logowanie informacji.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.