ss="markdown_views prism-atom-one-light">
ss
是Socket Statistics
的缩写,用来替代旧的netstat
工具,功能更强大,执行更快。它用于查看系统的ss="tags" href="/tags/WangLuo.html" title=网络>网络连接情况,包括TCP
、UDP
等协议的信息。
一. 命令解析:
ss="prism language-bash">ss="token function">sudo ss ss="token parameter variable">-tulwnp
ss (Socket Statistics)
:替代 netstat
的工具,用于查看ss="tags" href="/tags/WangLuo.html" title=网络>网络连接、路由表、接口统计等。
-t
:显示 TCP 套接字。
-u
:显示 UDP 套接字。
-l
:仅显示监听(LISTEN)状态的套接字。
-w
:显示 RAW 套接字(较少使用)。
-n
:禁用域名解析,直接显示 IP 和ss="tags" href="/tags/DuanKou.html" title=端口>端口号。
-p
:显示关联的进程信息(需 sudo 权限)。
sudo
:提升权限以查看所有进程的ss="tags" href="/tags/WangLuo.html" title=网络>网络信息。
二. 输出结果
ss="prism language-bash">Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port Process
icmp6 UNCONN ss="token number">0 ss="token number">0 *:58 *:* users:ss="token variable">ss="token punctuation">(("NetworkManager"ss="token punctuation">,pidss="token operator">=ss="token number">1230ss="token punctuation">,fdss="token operator">=ss="token number">21ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">127.0.0.53%lo:53 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("systemdss="token operator">-resolve"ss="token punctuation">,pidss="token operator">=ss="token number">1161ss="token punctuation">,fdss="token operator">=ss="token number">12ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">10.68.133.100%wlp2s0:33001 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">41ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">172.19.0.1%br-67610ac5d589:33001 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">40ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">172.18.0.1%br-7f68d848895d:33001 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">39ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">172.17.0.1%docker0:33001 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">38ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">127.0.0.1:33001 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">53ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">0.0.0.0:33785 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("avahiss="token operator">-daemon"ss="token punctuation">,pidss="token operator">=ss="token number">1220ss="token punctuation">,fdss="token operator">=ss="token number">14ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">224.0.0.251:5353 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("chrome"ss="token punctuation">,pidss="token operator">=ss="token number">6862ss="token punctuation">,fdss="token operator">=ss="token number">85ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">224.0.0.251:5353 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("chrome"ss="token punctuation">,pidss="token operator">=ss="token number">6913ss="token punctuation">,fdss="token operator">=ss="token number">53ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">0.0.0.0:5353 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("avahiss="token operator">-daemon"ss="token punctuation">,pidss="token operator">=ss="token number">1220ss="token punctuation">,fdss="token operator">=ss="token number">12ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">10.68.133.100%wlp2s0:38828 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">37ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">172.19.0.1%br-67610ac5d589:38828 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">36ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">172.18.0.1%br-7f68d848895d:38828 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">35ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">172.17.0.1%docker0:38828 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">34ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">10.68.133.100%wlp2s0:44616 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">33ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">172.19.0.1%br-67610ac5d589:44616 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">32ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">172.18.0.1%br-7f68d848895d:44616 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">31ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">172.17.0.1%docker0:44616 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">26ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token number">127.0.0.1:19081 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("nautilus"ss="token punctuation">,pidss="token operator">=ss="token number">1943297ss="token punctuation">,fdss="token operator">=ss="token number">25ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token punctuation">[::ss="token punctuation">]:60031 ss="token punctuation">[::ss="token punctuation">]:* users:ss="token variable">ss="token punctuation">(("avahiss="token operator">-daemon"ss="token punctuation">,pidss="token operator">=ss="token number">1220ss="token punctuation">,fdss="token operator">=ss="token number">15ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token punctuation">[ss="token number">2001:da8:b801:4c:275f:65a0:4a02:cf69ss="token punctuation">]%wlp2s0:33001 ss="token punctuation">[::ss="token punctuation">]:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">61ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token punctuation">[fe80::2774:a098:7839:13c2ss="token punctuation">]%wlp2s0:546 ss="token punctuation">[::ss="token punctuation">]:* users:ss="token variable">ss="token punctuation">(("NetworkManager"ss="token punctuation">,pidss="token operator">=ss="token number">1230ss="token punctuation">,fdss="token operator">=ss="token number">24ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token punctuation">[::ss="token punctuation">]:5353 ss="token punctuation">[::ss="token punctuation">]:* users:ss="token variable">ss="token punctuation">(("avahiss="token operator">-daemon"ss="token punctuation">,pidss="token operator">=ss="token number">1220ss="token punctuation">,fdss="token operator">=ss="token number">13ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token punctuation">[ss="token number">2001:da8:b801:4c:275f:65a0:4a02:cf69ss="token punctuation">]%wlp2s0:38828 ss="token punctuation">[::ss="token punctuation">]:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">43ss="token punctuation">))
udp UNCONN ss="token number">0 ss="token number">0 ss="token punctuation">[ss="token number">2001:da8:b801:4c:275f:65a0:4a02:cf69ss="token punctuation">]%wlp2s0:44616 ss="token punctuation">[::ss="token punctuation">]:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">42ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">128 ss="token number">127.0.0.1:55831 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5095ss="token punctuation">,fdss="token operator">=ss="token number">8ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">5 ss="token number">127.0.0.1:23119 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("zoteross="token operator">-bin"ss="token punctuation">,pidss="token operator">=ss="token number">2927689ss="token punctuation">,fdss="token operator">=ss="token number">103ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">16 ss="token number">127.0.0.1:19645 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("python3"ss="token punctuation">,pidss="token operator">=ss="token number">2110ss="token punctuation">,fdss="token operator">=ss="token number">11ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">128 ss="token number">127.0.0.1:51321 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">6ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">4096 ss="token number">127.0.0.53%lo:53 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("systemdss="token operator">-resolve"ss="token punctuation">,pidss="token operator">=ss="token number">1161ss="token punctuation">,fdss="token operator">=ss="token number">13ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">100 ss="token number">127.0.0.1:5151 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("python"ss="token punctuation">,pidss="token operator">=ss="token number">1935176ss="token punctuation">,fdss="token operator">=ss="token number">7ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">128 ss="token number">127.0.0.1:36899 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkCapturer"ss="token punctuation">,pidss="token operator">=ss="token number">5093ss="token punctuation">,fdss="token operator">=ss="token number">9ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">10 ss="token number">127.0.0.1:4301 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("qq"ss="token punctuation">,pidss="token operator">=ss="token number">2521049ss="token punctuation">,fdss="token operator">=ss="token number">160ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">10 ss="token number">127.0.0.1:4310 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("qq"ss="token punctuation">,pidss="token operator">=ss="token number">2521049ss="token punctuation">,fdss="token operator">=ss="token number">170ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">128 ss="token number">127.0.0.1:33691 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkCapturer"ss="token punctuation">,pidss="token operator">=ss="token number">5091ss="token punctuation">,fdss="token operator">=ss="token number">9ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">5 ss="token number">127.0.0.1:631 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("cupsd"ss="token punctuation">,pidss="token operator">=ss="token number">15795ss="token punctuation">,fdss="token operator">=ss="token number">7ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">10 ss="token number">127.0.0.1:4001 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("qq"ss="token punctuation">,pidss="token operator">=ss="token number">2521049ss="token punctuation">,fdss="token operator">=ss="token number">198ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">10 ss="token number">127.0.0.1:35600 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("ToDesk_Service"ss="token punctuation">,pidss="token operator">=ss="token number">3429ss="token punctuation">,fdss="token operator">=ss="token number">6ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">5 ss="token number">127.0.0.1:48267 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("python"ss="token punctuation">,pidss="token operator">=ss="token number">1568095ss="token punctuation">,fdss="token operator">=ss="token number">4ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">4096 ss="token number">127.0.0.1:42959 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("mongod"ss="token punctuation">,pidss="token operator">=ss="token number">1568181ss="token punctuation">,fdss="token operator">=ss="token number">11ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">100 ss="token number">127.0.0.1:9000 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("python"ss="token punctuation">,pidss="token operator">=ss="token number">1567887ss="token punctuation">,fdss="token operator">=ss="token number">36ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">100 ss="token number">127.0.0.1:9001 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("python"ss="token punctuation">,pidss="token operator">=ss="token number">1567887ss="token punctuation">,fdss="token operator">=ss="token number">14ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">100 ss="token number">127.0.0.1:9002 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("python"ss="token punctuation">,pidss="token operator">=ss="token number">1567887ss="token punctuation">,fdss="token operator">=ss="token number">10ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">100 ss="token number">127.0.0.1:9003 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("python"ss="token punctuation">,pidss="token operator">=ss="token number">1567887ss="token punctuation">,fdss="token operator">=ss="token number">12ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">100 ss="token number">127.0.0.1:9004 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("python"ss="token punctuation">,pidss="token operator">=ss="token number">1567887ss="token punctuation">,fdss="token operator">=ss="token number">23ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">511 ss="token number">127.0.0.1:9210 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("qq"ss="token punctuation">,pidss="token operator">=ss="token number">2521049ss="token punctuation">,fdss="token operator">=ss="token number">114ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">100 ss="token number">127.0.0.1:41611 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("python"ss="token punctuation">,pidss="token operator">=ss="token number">1567887ss="token punctuation">,fdss="token operator">=ss="token number">28ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">4096 ss="token number">127.0.0.1:11434 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("ollama"ss="token punctuation">,pidss="token operator">=ss="token number">3426ss="token punctuation">,fdss="token operator">=ss="token number">3ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">50 ss="token punctuation">[::ffff:127.0.0.1ss="token punctuation">]:19080 *:* users:ss="token variable">ss="token punctuation">(("nutstore"ss="token punctuation">,pidss="token operator">=ss="token number">4814ss="token punctuation">,fdss="token operator">=ss="token number">41ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">64 *:34642 *:* users:ss="token variable">ss="token punctuation">(("nutstore"ss="token punctuation">,pidss="token operator">=ss="token number">4814ss="token punctuation">,fdss="token operator">=ss="token number">45ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">5 ss="token punctuation">[::1ss="token punctuation">]:631 ss="token punctuation">[::ss="token punctuation">]:* users:ss="token variable">ss="token punctuation">(("cupsd"ss="token punctuation">,pidss="token operator">=ss="token number">15795ss="token punctuation">,fdss="token operator">=ss="token number">6ss="token punctuation">))
2.1. 输出结果字段解释:
Netid
:协议类型(如 tcp
, udp
, icmp6
)。
State
:套接字状态(如 LISTEN
表示监听中,UNCONN
表示未连接)。
Recv-Q/Send-Q
:接收/发送队列大小(单位:字节)。
Local Address:Port
:本地地址和ss="tags" href="/tags/DuanKou.html" title=端口>端口。
Peer Address:Port
:对端地址和ss="tags" href="/tags/DuanKou.html" title=端口>端口(UDP 通常为 0.0.0.0:*)。
Process
:关联的进程名称、PID 和文件描述符(FD)。
2.2. 关键输出分析:
2.2.1. 系统服务:
- DNS 解析:systemd-resolved 在 127.0.0.53:53 处理 DNS 请求。
ss="prism language-bash">udp UNCONN ss="token number">0 ss="token number">0 ss="token number">127.0.0.53%lo:53 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("systemdss="token operator">-resolve"ss="token punctuation">,pidss="token operator">=ss="token number">1161ss="token punctuation">,fdss="token operator">=ss="token number">12ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">4096 ss="token number">127.0.0.53%lo:53 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("systemdss="token operator">-resolve"ss="token punctuation">,pidss="token operator">=ss="token number">1161ss="token punctuation">,fdss="token operator">=ss="token number">13ss="token punctuation">))
- 打印服务:cupsd 在 631 ss="tags" href="/tags/DuanKou.html" title=端口>端口提供打印服务。
ss="prism language-bash">tcp LISTEN ss="token number">0 ss="token number">5 ss="token number">127.0.0.1:631 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("cupsd"ss="token punctuation">,pidss="token operator">=ss="token number">15795ss="token punctuation">,fdss="token operator">=ss="token number">7ss="token punctuation">))
- IPV6邻居发现:
ss="prism language-bash">icmp6 UNCONN ss="token number">0 ss="token number">0 *:58 *:* users:ss="token variable">ss="token punctuation">(("NetworkManager"ss="token punctuation">,pidss="token operator">=ss="token number">1230ss="token punctuation">,fdss="token operator">=ss="token number">21ss="token punctuation">))
- NetworkManager 处理 ICMPv6 邻居发现协议(ss="tags" href="/tags/DuanKou.html" title=端口>端口 58)。
2.2.2. 用户应用程序:
- RayLinkService:RayLinkService 在多个接口(如无线网卡
wlp2s0
、Docker 网桥 docker0
)监听 UDP 33001
ss="tags" href="/tags/DuanKou.html" title=端口>端口,TCP 51321
ss="tags" href="/tags/DuanKou.html" title=端口>端口可能用于控制连接。ss="prism language-bash">udp UNCONN ss="token number">0 ss="token number">0 ss="token number">10.68.133.100%wlp2s0:33001 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">41ss="token punctuation">))
tcp LISTEN ss="token number">0 ss="token number">128 ss="token number">127.0.0.1:51321 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("RayLinkService"ss="token punctuation">,pidss="token operator">=ss="token number">5084ss="token punctuation">,fdss="token operator">=ss="token number">6ss="token punctuation">))
- 数据库服务:
mongod
在 42959
ss="tags" href="/tags/DuanKou.html" title=端口>端口运行 MongoDB 数据库。ss="prism language-bash">tcp LISTEN ss="token number">0 ss="token number">4096 ss="token number">127.0.0.1:42959 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("mongod"ss="token punctuation">,pidss="token operator">=ss="token number">1568181ss="token punctuation">,fdss="token operator">=ss="token number">11ss="token punctuation">))
2.2.3. 其他服务:
- mDNS(局域网服务发现):Chrome 和
avahi-daemon
使用 5353
ss="tags" href="/tags/DuanKou.html" title=端口>端口支持 mDNS(如设备发现)。ss="prism language-bash">udp UNCONN ss="token number">0 ss="token number">0 ss="token number">224.0.0.251:5353 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("chrome"ss="token punctuation">,pidss="token operator">=ss="token number">6862ss="token punctuation">,fdss="token operator">=ss="token number">85ss="token punctuation">))
- 远程控制工具:
ss="prism language-bash">tcp LISTEN ss="token number">0 ss="token number">10 ss="token number">127.0.0.1:35600 ss="token number">0.0.0.0:* users:ss="token variable">ss="token punctuation">(("ToDesk_Service"ss="token punctuation">,pidss="token operator">=ss="token number">3429ss="token punctuation">,fdss="token operator">=ss="token number">6ss="token punctuation">))
- ToDesk 在
35600
ss="tags" href="/tags/DuanKou.html" title=端口>端口提供远程控制服务。
总结:
- 用途:快速定位系统中所有监听ss="tags" href="/tags/DuanKou.html" title=端口>端口的进程,用于排查ss="tags" href="/tags/DuanKou.html" title=端口>端口冲突、识别不明服务或监控ss="tags" href="/tags/WangLuo.html" title=网络>网络活动。
- 重点关注:
- 监听在 0.0.0.0(所有接口)或公网 IP 的ss="tags" href="/tags/DuanKou.html" title=端口>端口,可能存在安全风险。
- 未知进程或非预期ss="tags" href="/tags/DuanKou.html" title=端口>端口,需进一步检查是否为恶意软件。