mirror of
https://github.com/bytedance/deer-flow.git
synced 2026-04-25 11:18:22 +00:00
ATT&CK矩阵ID:T1059.004 数据来源:进程启动触发检测 告警原因:该进程的命令行显示出反弹shelI的特征 命令行:timeout 1 bash -c exec 3<>/dev/tcp/127.0.0.1/2024 进程路径:/usr/bin/timeout 进程链:-[337650] /usr/sbin/sshd -D -[397971] /usr/sbin/sshd -D -R -[397977]-bash -[398903] make dev -[398920] bash ./scripts/serve.sh --dev -[399037]bash ./scripts/wait-for-port.sh 2024 60 LangGraph
57 lines
1.4 KiB
Bash
Executable File
57 lines
1.4 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
#
|
|
# wait-for-port.sh - Wait for a TCP port to become available
|
|
#
|
|
# Usage: ./scripts/wait-for-port.sh <port> [timeout_seconds] [service_name]
|
|
#
|
|
# Arguments:
|
|
# port - TCP port to wait for (required)
|
|
# timeout_seconds - Max seconds to wait (default: 60)
|
|
# service_name - Display name for messages (default: "Service")
|
|
#
|
|
# Exit codes:
|
|
# 0 - Port is listening
|
|
# 1 - Timed out waiting
|
|
|
|
PORT="${1:?Usage: wait-for-port.sh <port> [timeout] [service_name]}"
|
|
TIMEOUT="${2:-60}"
|
|
SERVICE="${3:-Service}"
|
|
|
|
elapsed=0
|
|
interval=1
|
|
|
|
is_port_listening() {
|
|
if command -v lsof >/dev/null 2>&1; then
|
|
if lsof -nP -iTCP:"$PORT" -sTCP:LISTEN -t >/dev/null 2>&1; then
|
|
return 0
|
|
fi
|
|
fi
|
|
|
|
if command -v ss >/dev/null 2>&1; then
|
|
if ss -ltn "( sport = :$PORT )" 2>/dev/null | tail -n +2 | grep -q .; then
|
|
return 0
|
|
fi
|
|
fi
|
|
|
|
if command -v netstat >/dev/null 2>&1; then
|
|
if netstat -ltn 2>/dev/null | awk '{print $4}' | grep -Eq "(^|[.:])${PORT}$"; then
|
|
return 0
|
|
fi
|
|
fi
|
|
|
|
return 1
|
|
}
|
|
|
|
while ! is_port_listening; do
|
|
if [ "$elapsed" -ge "$TIMEOUT" ]; then
|
|
echo ""
|
|
echo "✗ $SERVICE failed to start on port $PORT after ${TIMEOUT}s"
|
|
exit 1
|
|
fi
|
|
printf "\r Waiting for %s on port %s... %ds" "$SERVICE" "$PORT" "$elapsed"
|
|
sleep "$interval"
|
|
elapsed=$((elapsed + interval))
|
|
done
|
|
|
|
printf "\r %-60s\r" "" # clear the waiting line
|