Javier Valladares 23045 #####Utilizando httpie, hagan una solicitud de HTTP al servidor#### javiervalladares@Javiers-MacBook-Pro-2 ~ % http http://nrywhite.lat HTTP/1.1 301 Moved Permanently CF-RAY: 91106d347dedcc74-TPA Connection: keep-alive Content-Type: text/html Date: Wed, 12 Feb 2025 23:40:56 GMT Location: https://nrywhite.lat/ NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800} Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Qr3OaV%2FCYbPFB4LRZ0K8dhLl9ULimXAiBUG7Pjpfs98WBf7gx7Hsg80Fbf9EjL%2F627%2BJ9zZ%2FQti8YHJI1Q61X2vZ%2FOSbGO3uYlvDK1b4sMrupDaAYmOwNj%2Byzj%2BuhiI%3D"}],"group":"cf-nel","max_age":604800} Server: cloudflare Transfer-Encoding: chunked alt-svc: h3=":443"; ma=86400 cf-cache-status: DYNAMIC server-timing: cfL4;desc="?proto=TCP&rtt=35560&min_rtt=35560&rtt_var=17780&sent=1&recv=3&lost=0&retrans=0&sent_bytes=0&recv_bytes=133&delivery_rate=0&cwnd=249&unsent_bytes=0&cid=0000000000000000&ts=0&x=0" 301 Moved Permanently

301 Moved Permanently


nginx/1.24.0 (Ubuntu)
####Utilizando curl, hagan una solicitud de HTTP al servidor### javiervalladares@Javiers-MacBook-Pro-2 ~ % curl -v http://nrywhite.lat * Host nrywhite.lat:80 was resolved. * IPv6: (none) * IPv4: 104.21.32.1, 104.21.48.1, 104.21.64.1, 104.21.80.1, 104.21.112.1, 104.21.16.1, 104.21.96.1 * Trying 104.21.32.1:80... * Connected to nrywhite.lat (104.21.32.1) port 80 > GET / HTTP/1.1 > Host: nrywhite.lat > User-Agent: curl/8.7.1 > Accept: */* > * Request completely sent off < HTTP/1.1 301 Moved Permanently < Date: Wed, 12 Feb 2025 23:43:07 GMT < Content-Type: text/html < Transfer-Encoding: chunked < Connection: keep-alive < Location: https://nrywhite.lat/ < cf-cache-status: DYNAMIC < Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Zk813HZCFjwkv%2FHvQvWvHLRcDdF5HqHA477GSxcqn6TBav0Q0%2Bbwb%2Bk69nMHwNAl6%2FI46l5HcNW4QSfQV7tEuXAALYw2ROlVuC6akcWd21ZygwQy92DBGACWYY55VVM%3D"}],"group":"cf-nel","max_age":604800} < NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800} < Server: cloudflare < CF-RAY: 91107065bb3f4986-MIA < alt-svc: h3=":443"; ma=86400 < server-timing: cfL4;desc="?proto=TCP&rtt=33570&min_rtt=33570&rtt_var=16785&sent=1&recv=3&lost=0&retrans=0&sent_bytes=0&recv_bytes=75&delivery_rate=0&cwnd=247&unsent_bytes=0&cid=0000000000000000&ts=0&x=0" < 301 Moved Permanently

301 Moved Permanently


nginx/1.24.0 (Ubuntu)
* Connection #0 to host nrywhite.lat left intact ####Utilizando ps y grep identifiquen qué procesos está corriendo amazon dentro del servidor##### ps aux | grep -i amazon root 542 0.0 1.2 1759116 12400 ? Ssl Feb12 0:02 /snap/amazon-ssm-agent/9881/amazon-ssm-agent root 914 0.0 1.9 1850868 18816 ? Sl Feb12 0:08 /snap/amazon-ssm-agent/9881/ssm-agent-worker ubuntu 55845 0.0 0.2 6944 2176 pts/7 S+ 00:08 0:00 grep --color=auto --exclude-dir=.bzr --exclude-dir=CVS --exclude-dir=.git --exclude-dir=.hg --exclude-dir=.svn -i amazon #####Utilizando dig dentro del servidor, obtengan la ip que resuelve al hacer un dns lookup uvg.edu.gt#### dig uvg.edu.gt +short 45.223.56.41 45.223.155.41 ####Cuanta memoria RAM, total usada y libre, tiene el servidor? (su respuesta debe estar en MB)##### free -m total used free shared buff/cache available Mem: 957 525 140 48 510 432 Swap: 0 0 0 ####Cuanta espacio de disco, total usado y disponible, tiene el servidor? (su respuesta debe estar en MB)##### df -m Filesystem 1M-blocks Used Available Use% Mounted on /dev/root 28691 8645 20030 31% / tmpfs 479 48 431 10% /dev/shm tmpfs 192 2 191 1% /run tmpfs 5 0 5 0% /run/lock /dev/xvda16 881 76 744 10% /boot /dev/xvda15 105 7 99 6% /boot/efi tmpfs 96 1 96 1% /run/user/1000 #####Utilizando el comando ip obtengan la ip del servidor##### ip addr show 1: lo: mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever inet6 ::1/128 scope host noprefixroute valid_lft forever preferred_lft forever 2: enX0: mtu 9001 qdisc fq_codel state UP group default qlen 1000 link/ether 0a:ff:d6:c1:6d:a5 brd ff:ff:ff:ff:ff:ff inet 172.31.31.175/20 metric 100 brd 172.31.31.255 scope global dynamic enX0 valid_lft 3244sec preferred_lft 3244sec inet6 fe80::8ff:d6ff:fec1:6da5/64 scope link valid_lft forever preferred_lft forever 3: docker0: mtu 1500 qdisc noqueue state UP group default link/ether 02:42:b0:10:3a:1f brd ff:ff:ff:ff:ff:ff inet 172.17.0.1/16 brd 172.17.255.255 scope global docker0 valid_lft forever preferred_lft forever inet6 fe80::42:b0ff:fe10:3a1f/64 scope link valid_lft forever preferred_lft forever 5: veth3e2c6fb@if4: mtu 1500 qdisc noqueue master docker0 state UP group default link/ether de:40:60:4d:bf:ef brd ff:ff:ff:ff:ff:ff link-netnsid 0 inet6 fe80::dc40:60ff:fe4d:bfef/64 scope link valid_lft forever preferred_lft forever #####lsof lista los archivos abiertos. Identifiquen los archivos abiertos por el protocolo TCP en el puerto 80### sudo lsof -i TCP:80 COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME nginx 10095 root 5u IPv4 39888 0t0 TCP *:http (LISTEN) nginx 10095 root 7u IPv6 39890 0t0 TCP *:http (LISTEN) nginx 39429 www-data 3u IPv4 168923 0t0 TCP ip-172-31-31-175.ec2.internal:http->172.68.76.131:16102 (ESTABLISHED) nginx 39429 www-data 5u IPv4 39888 0t0 TCP *:http (LISTEN) nginx 39429 www-data 7u IPv6 39890 0t0 TCP *:http (LISTEN) #####Utilizando netstat, listen los puertos por los que está escuchando el servidor. Deben filtrar usando las siguientes opciones de netsta##### sudo netstat -tulpn Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 127.0.0.54:53 0.0.0.0:* LISTEN 309/systemd-resolve tcp 0 0 127.0.0.53:53 0.0.0.0:* LISTEN 309/systemd-resolve tcp 0 0 0.0.0.0:90 0.0.0.0:* LISTEN 1136/docker-proxy tcp6 0 0 :::10 :::* LISTEN 1/init tcp6 0 0 :::90 :::* LISTEN 1143/docker-proxy udp 0 0 127.0.0.1:323 0.0.0.0:* 613/chronyd udp 0 0 127.0.0.54:53 0.0.0.0:* 309/systemd-resolve udp 0 0 127.0.0.53:53 0.0.0.0:* 309/systemd-resolve udp 0 0 172.31.31.175:68 0.0.0.0:* 480/systemd-network udp6 0 0 ::1:323 :::* 613/chronyd #####Utilizando ss, listen los puertos por los que está escuchando el servidor. Deben filtrar usando las siguientes opciones de ss##### sudo ss -s -t state established -n -m -i -p Total: 240 TCP: 15 (estab 9, closed 1, orphaned 0, timewait 0) Transport Total IP IPv6 RAW 1 0 1 UDP 5 4 1 TCP 14 4 10 INET 20 8 12 FRAG 0 0 0 Recv-Q Send-Q Local Address:Port Peer Address:Port Process 0 0 172.31.31.175:59150 67.220.251.145:443 users:(("ssm-agent-worke",pid=914,fd=14)) skmem:(r0,rb131072,t0,tb87040,f0,w0,o0,bl0,d0) cubic wscale:6,7 rto:204 rtt:3.955/0.813 ato:40 mss:1460 pmtu:9001 rcvmss:1460 advmss:8961 cwnd:10 bytes_sent:14996 bytes_acked:14997 bytes_received:16297 segs_out:1588 segs_in:1281 data_segs_out:322 data_segs_in:326 send 29532238bps lastsnd:425 lastrcv:422 lastack:422 pacing_rate 59058872bps delivery_rate 8118624bps delivered:323 app_limited busy:1272ms rcv_space:56575 rcv_ssthresh:56575 minrtt:1.793 snd_wnd:59776 0 0 [::ffff:172.31.31.175]:10 [::ffff:190.14.11.2]:53465 users:(("sshd",pid=52774,fd=4),("sshd",pid=52704,fd=4)) skmem:(r0,rb131072,t0,tb87040,f0,w0,o0,bl0,d10) cubic wscale:6,7 rto:318 rtt:117.281/44.587 ato:42 mss:1448 pmtu:9001 rcvmss:1448 advmss:8949 cwnd:19 bytes_sent:114278 bytes_retrans:72 bytes_acked:114206 bytes_received:94773 segs_out:2644 segs_in:4936 data_segs_out:2542 data_segs_in:2538 send 1876655bps lastsnd:807048 lastrcv:807048 lastack:806867 pacing_rate 3753296bps delivery_rate 2492136bps delivered:2543 app_limited busy:54876ms retrans:0/2 dsack_dups:2 rcv_rtt:58 rcv_space:56575 rcv_ssthresh:56575 minrtt:52.515 rcv_ooopack:52 snd_wnd:130944 0 0 [::ffff:172.31.31.175]:10 [::ffff:190.14.11.2]:51723 users:(("sshd",pid=51964,fd=4),("sshd",pid=51917,fd=4)) skmem:(r0,rb131072,t0,tb87040,f0,w0,o0,bl0,d0) cubic wscale:8,7 rto:272 rtt:71.937/11.595 ato:66 mss:1460 pmtu:9001 rcvmss:1432 advmss:8961 cwnd:10 bytes_sent:39498 bytes_acked:39498 bytes_received:34985 segs_out:949 segs_in:1056 data_segs_out:945 data_segs_in:876 send 1623643bps lastsnd:1647649 lastrcv:1647649 lastack:1647596 pacing_rate 3247280bps delivery_rate 887624bps delivered:946 app_limited busy:31577ms rcv_space:56575 rcv_ssthresh:56575 minrtt:52.688 snd_wnd:64512 0 632 [::ffff:172.31.31.175]:10 [::ffff:190.56.194.12]:49226 users:(("sshd",pid=55146,fd=4),("sshd",pid=54988,fd=4)) skmem:(r0,rb131072,t0,tb87040,f2696,w9592,o0,bl0,d0) cubic wscale:6,7 rto:257 rtt:56.86/1.44 ato:40 mss:1448 pmtu:9001 rcvmss:1448 advmss:8949 cwnd:10 bytes_sent:94322 bytes_acked:93690 bytes_received:78441 segs_out:2096 segs_in:3941 data_segs_out:2076 data_segs_in:1969 send 2037285bps lastrcv:3 lastack:3 pacing_rate 4074544bps delivery_rate 2041696bps delivered:2067 app_limited busy:43789ms unacked:10 rcv_rtt:60 rcv_space:56575 rcv_ssthresh:56575 minrtt:54.014 snd_wnd:131072 0 0 [::ffff:172.31.31.175]:10 [::ffff:190.14.11.2]:49348 users:(("sshd",pid=50024,fd=4),("sshd",pid=49968,fd=4)) skmem:(r0,rb131072,t0,tb87040,f0,w0,o0,bl0,d0) cubic wscale:6,7 rto:269 rtt:68.899/12.377 ato:40 mss:1448 pmtu:9001 rcvmss:1448 advmss:8949 cwnd:10 bytes_sent:101710 bytes_acked:101710 bytes_received:15040 segs_out:418 segs_in:521 data_segs_out:371 data_segs_in:269 send 1681302bps lastsnd:1304925 lastrcv:32909 lastack:32909 pacing_rate 3362584bps delivery_rate 2685744bps delivered:372 busy:12762ms rcv_space:56575 rcv_ssthresh:56575 minrtt:55.993 snd_wnd:145536 0 0 [::ffff:172.31.31.175]:10 [::ffff:181.209.179.43]:50404 users:(("sshd",pid=49705,fd=4),("sshd",pid=49648,fd=4)) skmem:(r0,rb2148477,t0,tb87040,f0,w0,o0,bl0,d1) cubic wscale:7,7 rto:278 rtt:76.32/6.476 ato:40 mss:1398 pmtu:9001 rcvmss:1208 advmss:8949 cwnd:21 ssthresh:16 bytes_sent:2336490 bytes_retrans:860 bytes_acked:2335630 bytes_received:1327078 segs_out:36584 segs_in:39684 data_segs_out:36135 data_segs_in:34887 send 3077358bps lastsnd:348731 lastrcv:348731 lastack:348674 pacing_rate 3692824bps delivery_rate 3627432bps delivered:36126 app_limited busy:742754ms retrans:0/11 dsack_dups:5 reord_seen:1 rcv_rtt:50117.9 rcv_space:87588 rcv_ssthresh:153215 minrtt:53.413 snd_wnd:64256 0 0 [::ffff:172.31.31.175]:10 [::ffff:181.209.179.43]:55046 users:(("sshd",pid=58039,fd=4),("sshd",pid=57977,fd=4)) skmem:(r0,rb2089676,t0,tb1122816,f0,w0,o0,bl0,d0) cubic wscale:7,7 rto:271 rtt:70.702/14.91 ato:40 mss:1448 pmtu:9001 rcvmss:1448 advmss:8949 cwnd:31 ssthresh:129 bytes_sent:1053242 bytes_retrans:200 bytes_acked:1053042 bytes_received:122225 segs_out:4030 segs_in:4158 data_segs_out:4009 data_segs_in:3291 send 5079121bps lastsnd:37519 lastrcv:37519 lastack:37421 pacing_rate 10158200bps delivery_rate 16917320bps delivered:4010 busy:68994ms rwnd_limited:484ms(0.7%) retrans:0/1 dsack_dups:1 reordering:6 reord_seen:1 rcv_rtt:38665.9 rcv_space:62681 rcv_ssthresh:56575 minrtt:53.658 snd_wnd:1645824 0 144 [::ffff:172.31.31.175]:10 [::ffff:181.209.179.43]:58808 users:(("sshd",pid=54689,fd=4),("sshd",pid=54633,fd=4)) skmem:(r0,rb1371127,t0,tb87040,f368,w3728,o0,bl0,d0) cubic wscale:7,7 rto:286 rtt:83.326/14.381 ato:42 mss:1398 pmtu:9001 rcvmss:1208 advmss:8949 cwnd:29 bytes_sent:680158 bytes_retrans:636 bytes_acked:679378 bytes_received:625234 segs_out:17076 segs_in:19798 data_segs_out:16589 data_segs_in:17133 send 3892375bps lastsnd:3 lastrcv:3 lastack:3 pacing_rate 7784744bps delivery_rate 3894352bps delivered:16583 app_limited busy:345436ms unacked:4 retrans:0/9 dsack_dups:8 rcv_rtt:33676.3 rcv_space:62698 rcv_ssthresh:90399 minrtt:53.68 rcv_ooopack:10 snd_wnd:64256 0 0 [::ffff:172.31.31.175]:10 [::ffff:190.56.194.12]:50944 users:(("sshd",pid=58829,fd=4),("sshd",pid=58753,fd=4)) skmem:(r0,rb131072,t0,tb87040,f0,w0,o0,bl0,d0) cubic wscale:7,7 rto:256 rtt:55.188/0.435 ato:51 mss:1448 pmtu:9001 rcvmss:768 advmss:8949 cwnd:15 bytes_sent:27294 bytes_acked:27294 bytes_received:5922 segs_out:172 segs_in:237 data_segs_out:164 data_segs_in:100 send 3148511bps lastsnd:6377 lastrcv:6802 lastack:6322 pacing_rate 6296992bps delivery_rate 2271128bps delivered:165 busy:6498ms rcv_space:56575 rcv_ssthresh:56575 minrtt:53.693 snd_wnd:64128