亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? 00000143.htm

?? 一份很好的linux入門資料
?? HTM
?? 第 1 頁 / 共 2 頁
字號:
<HTML><HEAD>  <TITLE>BBS水木清華站∶精華區</TITLE></HEAD><BODY><CENTER><H1>BBS水木清華站∶精華區</H1></CENTER>發信人:&nbsp;CuteGuy&nbsp;(被大頭針扎傷※休養中),&nbsp;信區:&nbsp;Linux&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<BR>標&nbsp;&nbsp;題:&nbsp;Enhancing&nbsp;System&nbsp;Security&nbsp;With&nbsp;TCP&nbsp;Wrappers(轉)&nbsp;<BR>發信站:&nbsp;BBS&nbsp;水木清華站&nbsp;(Sun&nbsp;May&nbsp;&nbsp;2&nbsp;12:33:43&nbsp;1999)&nbsp;<BR>&nbsp;<BR>&nbsp;<BR>&nbsp;&nbsp;<BR><A HREF="http://www.performancecomputing.com/Linux-IT/features/9905of1.shtml">http://www.performancecomputing.com/Linux-IT/features/9905of1.shtml</A>&nbsp;<BR>&nbsp;<BR>LINUX-IT&nbsp;-&nbsp;MAY&nbsp;1999&nbsp;<BR>&nbsp;Enhancing&nbsp;System&nbsp;Security&nbsp;With&nbsp;TCP&nbsp;Wrappers&nbsp;<BR>Paul&nbsp;Dunne&nbsp;<BR>TCP&nbsp;Wrappers,&nbsp;written&nbsp;by&nbsp;Wietse&nbsp;Venema,&nbsp;is&nbsp;a&nbsp;tool&nbsp;that&nbsp;filters&nbsp;incoming&nbsp;&nbsp;<BR>connections&nbsp;to&nbsp;network&nbsp;services.&nbsp;This&nbsp;article&nbsp;looks&nbsp;at&nbsp;how&nbsp;TCP&nbsp;Wrappers&nbsp;can&nbsp;&nbsp;<BR>be&nbsp;used&nbsp;to&nbsp;enhance&nbsp;the&nbsp;security&nbsp;of&nbsp;a&nbsp;networked&nbsp;system.&nbsp;The&nbsp;example&nbsp;platform&nbsp;&nbsp;<BR>is&nbsp;Linux,&nbsp;but&nbsp;the&nbsp;information&nbsp;&nbsp;<BR>is&nbsp;applicable&nbsp;to&nbsp;most&nbsp;any&nbsp;UNIX&nbsp;system.&nbsp;<BR>The&nbsp;idea&nbsp;of&nbsp;the&nbsp;package&nbsp;is&nbsp;to&nbsp;provide&nbsp;&quot;wrapper&quot;&nbsp;daemons&nbsp;that&nbsp;can&nbsp;be&nbsp;installed&nbsp;&nbsp;<BR>without&nbsp;any&nbsp;changes&nbsp;to&nbsp;existing&nbsp;software.&nbsp;<BR>&nbsp;<BR>Most&nbsp;TCP/IP&nbsp;applications&nbsp;depend&nbsp;on&nbsp;the&nbsp;client-server&nbsp;model--that&nbsp;is,&nbsp;when&nbsp;a&nbsp;&nbsp;<BR>connection&nbsp;is&nbsp;requested&nbsp;by&nbsp;a&nbsp;client,&nbsp;a&nbsp;server&nbsp;process&nbsp;is&nbsp;started&nbsp;on&nbsp;the&nbsp;host&nbsp;&nbsp;<BR>to&nbsp;deal&nbsp;with&nbsp;it.&nbsp;TCP&nbsp;Wrappers&nbsp;works&nbsp;by&nbsp;interposing&nbsp;an&nbsp;additional&nbsp;layer,&nbsp;or&nbsp;&nbsp;<BR>wrapper,&nbsp;between&nbsp;client&nbsp;&nbsp;<BR>and&nbsp;server.&nbsp;In&nbsp;the&nbsp;basic&nbsp;service,&nbsp;the&nbsp;wrapper&nbsp;logs&nbsp;the&nbsp;name&nbsp;of&nbsp;the&nbsp;client&nbsp;&nbsp;<BR>host&nbsp;and&nbsp;requested&nbsp;service,&nbsp;then&nbsp;hands&nbsp;the&nbsp;communication&nbsp;over&nbsp;to&nbsp;the&nbsp;real&nbsp;&nbsp;<BR>daemon,&nbsp;neither&nbsp;exchanging&nbsp;information&nbsp;with&nbsp;the&nbsp;client&nbsp;or&nbsp;server,&nbsp;nor&nbsp;&nbsp;<BR>imposing&nbsp;overhead&nbsp;on&nbsp;the&nbsp;actual&nbsp;&nbsp;<BR>conversation&nbsp;between&nbsp;the&nbsp;two.&nbsp;Optional&nbsp;features&nbsp;may&nbsp;be&nbsp;enabled,&nbsp;including&nbsp;&nbsp;<BR>access&nbsp;control,&nbsp;client&nbsp;username&nbsp;lookups,&nbsp;and&nbsp;additional&nbsp;protection&nbsp;against&nbsp;&nbsp;<BR>hostname&nbsp;spoofing.&nbsp;<BR>The&nbsp;current&nbsp;version&nbsp;of&nbsp;TCP&nbsp;Wrappers,&nbsp;7.6,&nbsp;can&nbsp;be&nbsp;obtained&nbsp;from&nbsp;&nbsp;<BR><A HREF="ftp://ftp.porcupine.org/pub/security/.">ftp://ftp.porcupine.org/pub/security/.</A>&nbsp;(Note&nbsp;that&nbsp;the&nbsp;old&nbsp;location,&nbsp;&nbsp;<BR><A HREF="ftp://ftp.win.tue.nl/pub/security/,">ftp://ftp.win.tue.nl/pub/security/,</A>&nbsp;was&nbsp;compromised&nbsp;earlier&nbsp;this&nbsp;year&nbsp;and&nbsp;is&nbsp;&nbsp;<BR>no&nbsp;longer&nbsp;maintained.)&nbsp;<BR>Compilation&nbsp;<BR>There&nbsp;are&nbsp;a&nbsp;few&nbsp;decisions&nbsp;to&nbsp;make&nbsp;at&nbsp;compile&nbsp;time.&nbsp;Features&nbsp;can&nbsp;be&nbsp;turned&nbsp;on&nbsp;&nbsp;<BR>or&nbsp;off&nbsp;through&nbsp;definitions.&nbsp;Here&nbsp;is&nbsp;a&nbsp;list,&nbsp;with&nbsp;default&nbsp;values&nbsp;shown&nbsp;where&nbsp;&nbsp;<BR>appropriate:&nbsp;<BR>STYLE&nbsp;=&nbsp;-DPROCESS_OPTIONS&nbsp;<BR>Enables&nbsp;language&nbsp;extensions.&nbsp;This&nbsp;is&nbsp;disabled&nbsp;by&nbsp;default.&nbsp;<BR>FACILITY=LOG_MAIL&nbsp;<BR>Sets&nbsp;the&nbsp;location&nbsp;of&nbsp;log&nbsp;records.&nbsp;I&nbsp;prefer&nbsp;to&nbsp;set&nbsp;this&nbsp;to&nbsp;LOG_DAEMON,&nbsp;and&nbsp;log&nbsp;&nbsp;<BR>stuff&nbsp;into&nbsp;/var/log/daemon.&nbsp;Your&nbsp;mileage&nbsp;may&nbsp;vary.&nbsp;<BR>SEVERITY=&nbsp;LOG_INFO&nbsp;<BR>Sets&nbsp;what&nbsp;level&nbsp;to&nbsp;give&nbsp;to&nbsp;the&nbsp;log&nbsp;message.&nbsp;The&nbsp;default,&nbsp;LOG_INFO,&nbsp;is&nbsp;fine&nbsp;in&nbsp;&nbsp;<BR>most&nbsp;cases.&nbsp;The&nbsp;complete&nbsp;list&nbsp;is,&nbsp;in&nbsp;ascending&nbsp;order&nbsp;of&nbsp;severity,&nbsp;debug,&nbsp;&nbsp;<BR>notice,&nbsp;warning,&nbsp;err,&nbsp;crit,&nbsp;alert,&nbsp;emerg.&nbsp;See&nbsp;the&nbsp;syslog.conf(5)&nbsp;man&nbsp;page&nbsp;for&nbsp;&nbsp;<BR>more&nbsp;details.&nbsp;<BR>HOSTS_ACCESS&nbsp;<BR>When&nbsp;compiled&nbsp;with&nbsp;this&nbsp;option,&nbsp;the&nbsp;wrapper&nbsp;programs&nbsp;support&nbsp;a&nbsp;simple&nbsp;form&nbsp;of&nbsp;&nbsp;<BR>access&nbsp;control.&nbsp;Since&nbsp;this&nbsp;is&nbsp;the&nbsp;reason&nbsp;most&nbsp;people&nbsp;install&nbsp;TCP&nbsp;Wrappers,&nbsp;it&nbsp;&nbsp;<BR>is&nbsp;defined&nbsp;by&nbsp;default.&nbsp;<BR>PARANOID&nbsp;<BR>When&nbsp;compiled&nbsp;with&nbsp;-DPARANOID,&nbsp;the&nbsp;wrappers&nbsp;try&nbsp;to&nbsp;look&nbsp;up&nbsp;and&nbsp;double-check&nbsp;&nbsp;<BR>the&nbsp;client&nbsp;hostname,&nbsp;and&nbsp;will&nbsp;always&nbsp;refuse&nbsp;service&nbsp;in&nbsp;case&nbsp;of&nbsp;a&nbsp;discrepancy&nbsp;&nbsp;<BR>between&nbsp;hostname&nbsp;and&nbsp;IP&nbsp;address.&nbsp;This&nbsp;is&nbsp;a&nbsp;reasonable&nbsp;policy&nbsp;for&nbsp;most&nbsp;&nbsp;<BR>systems.&nbsp;When&nbsp;compiled&nbsp;&nbsp;<BR>without&nbsp;-DPARANOID,&nbsp;the&nbsp;wrappers&nbsp;by&nbsp;default&nbsp;still&nbsp;perform&nbsp;hostname&nbsp;lookup,&nbsp;&nbsp;<BR>but&nbsp;hosts&nbsp;where&nbsp;such&nbsp;lookups&nbsp;give&nbsp;conflicting&nbsp;results&nbsp;for&nbsp;hostname&nbsp;and&nbsp;IP&nbsp;&nbsp;<BR>address&nbsp;are&nbsp;not&nbsp;automatically&nbsp;rejected.&nbsp;They&nbsp;can&nbsp;be&nbsp;matched&nbsp;with&nbsp;the&nbsp;PARANOID&nbsp;&nbsp;<BR>wildcard&nbsp;in&nbsp;the&nbsp;access&nbsp;&nbsp;<BR>files,&nbsp;and&nbsp;a&nbsp;decision&nbsp;can&nbsp;be&nbsp;made&nbsp;on&nbsp;whether&nbsp;to&nbsp;grant&nbsp;access.&nbsp;<BR>DOT=&nbsp;-DAPPEND_DOT&nbsp;<BR>This&nbsp;appends&nbsp;a&nbsp;dot&nbsp;to&nbsp;a&nbsp;domain&nbsp;name.&nbsp;For&nbsp;example,&nbsp;&quot;example.com&quot;&nbsp;becomes&nbsp;&nbsp;<BR>&quot;example.com.&quot;.&nbsp;This&nbsp;is&nbsp;done&nbsp;because&nbsp;typically,&nbsp;the&nbsp;resolver&nbsp;will&nbsp;first&nbsp;&nbsp;<BR>append&nbsp;substrings&nbsp;of&nbsp;the&nbsp;local&nbsp;domain&nbsp;before&nbsp;trying&nbsp;to&nbsp;resolve&nbsp;the&nbsp;name&nbsp;it&nbsp;&nbsp;<BR>has&nbsp;actually&nbsp;been&nbsp;given.&nbsp;Use&nbsp;of&nbsp;&nbsp;<BR>the&nbsp;APPEND_DOT&nbsp;feature&nbsp;stops&nbsp;this&nbsp;waste&nbsp;of&nbsp;time&nbsp;and&nbsp;resources.&nbsp;It&nbsp;is&nbsp;off&nbsp;by&nbsp;&nbsp;<BR>default.&nbsp;<BR>AUTH&nbsp;=&nbsp;-DALWAYS_RFC931&nbsp;<BR>Always&nbsp;attempt&nbsp;remote&nbsp;username&nbsp;lookups.&nbsp;By&nbsp;default,&nbsp;this&nbsp;is&nbsp;off,&nbsp;and&nbsp;the&nbsp;&nbsp;<BR>wrappers&nbsp;look&nbsp;up&nbsp;the&nbsp;remote&nbsp;username&nbsp;only&nbsp;when&nbsp;the&nbsp;access-control&nbsp;rules&nbsp;&nbsp;<BR>require&nbsp;them&nbsp;to&nbsp;do&nbsp;so.&nbsp;Note&nbsp;that&nbsp;for&nbsp;this&nbsp;to&nbsp;be&nbsp;of&nbsp;any&nbsp;use,&nbsp;the&nbsp;remote&nbsp;host&nbsp;&nbsp;<BR>must&nbsp;run&nbsp;a&nbsp;daemon&nbsp;that&nbsp;supports&nbsp;&nbsp;<BR>the&nbsp;finger&nbsp;protocol.&nbsp;Also,&nbsp;such&nbsp;lookups&nbsp;are&nbsp;not&nbsp;possible&nbsp;for&nbsp;UDP-based&nbsp;&nbsp;<BR>connections.&nbsp;<BR>RFC931_TIMEOUT&nbsp;=&nbsp;10&nbsp;<BR>Username&nbsp;lookup&nbsp;timeout.&nbsp;This&nbsp;may&nbsp;not&nbsp;be&nbsp;long&nbsp;enough&nbsp;for&nbsp;slow&nbsp;hosts&nbsp;or&nbsp;&nbsp;<BR>networks,&nbsp;but&nbsp;is&nbsp;enough&nbsp;to&nbsp;irritate&nbsp;PC&nbsp;users.&nbsp;<BR>-DDAEMON_UMASK=022&nbsp;<BR>The&nbsp;is&nbsp;the&nbsp;default&nbsp;file-protection&nbsp;mask&nbsp;for&nbsp;processes&nbsp;run&nbsp;under&nbsp;control&nbsp;of&nbsp;&nbsp;<BR>the&nbsp;wrappers.&nbsp;<BR>ACCESS&nbsp;=&nbsp;-DHOSTS_ACCESS&nbsp;<BR>Sets&nbsp;host&nbsp;access&nbsp;control.&nbsp;This&nbsp;is&nbsp;enabled&nbsp;by&nbsp;default.&nbsp;Note&nbsp;that&nbsp;this&nbsp;can&nbsp;also&nbsp;&nbsp;<BR>be&nbsp;turned&nbsp;off&nbsp;at&nbsp;run&nbsp;time&nbsp;by&nbsp;providing&nbsp;no,&nbsp;or&nbsp;empty,&nbsp;access-control&nbsp;tables.&nbsp;<BR>TABLES&nbsp;=&nbsp;-DHOSTS_DENY=\&quot;/etc/&nbsp;<BR>&nbsp;&nbsp;hosts.deny\&quot;&nbsp;-DHOSTS_&nbsp;<BR>&nbsp;&nbsp;ALLOW=\&quot;/etc/hosts.allow\&quot;&nbsp;<BR>Sets&nbsp;the&nbsp;pathnames&nbsp;for&nbsp;the&nbsp;access-control&nbsp;tables.&nbsp;<BR>HOSTNAME=&nbsp;-DALWAYS_HOSTNAME&nbsp;<BR>Always&nbsp;attempt&nbsp;to&nbsp;look&nbsp;up&nbsp;the&nbsp;client&nbsp;hostname.&nbsp;This&nbsp;is&nbsp;on&nbsp;by&nbsp;default.&nbsp;If&nbsp;this&nbsp;&nbsp;<BR>is&nbsp;disabled,&nbsp;the&nbsp;client&nbsp;hostname&nbsp;lookup&nbsp;is&nbsp;postponed&nbsp;until&nbsp;the&nbsp;name&nbsp;is&nbsp;&nbsp;<BR>required&nbsp;by&nbsp;an&nbsp;access-control&nbsp;rule&nbsp;or&nbsp;by&nbsp;a&nbsp;%letter&nbsp;expansion.&nbsp;If&nbsp;this&nbsp;is&nbsp;what&nbsp;&nbsp;<BR>you&nbsp;want,&nbsp;you&nbsp;must&nbsp;&nbsp;<BR>disable&nbsp;paranoid&nbsp;mode&nbsp;as&nbsp;well.&nbsp;<BR>-DKILL_IP_OPTIONS&nbsp;<BR>This&nbsp;is&nbsp;for&nbsp;protection&nbsp;against&nbsp;hosts&nbsp;that&nbsp;pretend&nbsp;they&nbsp;have&nbsp;someone&nbsp;else's&nbsp;&nbsp;<BR>host&nbsp;address&nbsp;(host&nbsp;address&nbsp;spoofing).&nbsp;This&nbsp;option&nbsp;is&nbsp;not&nbsp;needed&nbsp;on&nbsp;modern&nbsp;&nbsp;<BR>UNIX&nbsp;systems&nbsp;that&nbsp;can&nbsp;stop&nbsp;source-routed&nbsp;traffic&nbsp;in&nbsp;the&nbsp;kernel&nbsp;(for&nbsp;example,&nbsp;&nbsp;<BR>Linux,&nbsp;Solaris&nbsp;2.x,&nbsp;4.4BSD&nbsp;&nbsp;<BR>and&nbsp;derivatives).&nbsp;<BR>-DNETGROUP&nbsp;<BR>Defines&nbsp;if&nbsp;your&nbsp;system&nbsp;has&nbsp;NIS&nbsp;support.&nbsp;Off&nbsp;by&nbsp;default.&nbsp;This&nbsp;is&nbsp;used&nbsp;only&nbsp;in&nbsp;&nbsp;<BR>conjunction&nbsp;with&nbsp;host&nbsp;access&nbsp;control,&nbsp;so&nbsp;if&nbsp;you're&nbsp;not&nbsp;using&nbsp;that,&nbsp;don't&nbsp;&nbsp;<BR>bother&nbsp;about&nbsp;this&nbsp;in&nbsp;any&nbsp;case.&nbsp;<BR>Some&nbsp;definitions&nbsp;are&nbsp;given&nbsp;that&nbsp;work&nbsp;around&nbsp;system&nbsp;bugs&nbsp;(just&nbsp;the&nbsp;basics&nbsp;&nbsp;<BR>here;&nbsp;see&nbsp;Makefile&nbsp;for&nbsp;details).&nbsp;The&nbsp;standard&nbsp;define&nbsp;is:&nbsp;<BR>BUGS&nbsp;=&nbsp;-DGETPEERNAME_BUG&nbsp;-DBROKEN_FGETS&nbsp;-DLIBC_CALLS_STRTOK&nbsp;<BR>Having&nbsp;set&nbsp;the&nbsp;options&nbsp;to&nbsp;your&nbsp;requirements,&nbsp;type&nbsp;make&nbsp;sys-type,&nbsp;where&nbsp;&nbsp;<BR>sys-type&nbsp;is&nbsp;one&nbsp;of&nbsp;the&nbsp;48&nbsp;systems&nbsp;listed&nbsp;in&nbsp;Figure&nbsp;1.&nbsp;As&nbsp;you&nbsp;can&nbsp;see,&nbsp;enough&nbsp;&nbsp;<BR>choices!&nbsp;<BR>If&nbsp;none&nbsp;of&nbsp;these&nbsp;matches&nbsp;your&nbsp;environment,&nbsp;then&nbsp;you&nbsp;will&nbsp;have&nbsp;to&nbsp;edit&nbsp;the&nbsp;&nbsp;<BR>system&nbsp;dependencies&nbsp;sections&nbsp;in&nbsp;the&nbsp;Makefile&nbsp;and&nbsp;do&nbsp;a&nbsp;make&nbsp;other.&nbsp;<BR>Installation&nbsp;<BR>There&nbsp;are&nbsp;two&nbsp;ways&nbsp;to&nbsp;install&nbsp;the&nbsp;software.&nbsp;The&nbsp;easy&nbsp;installation&nbsp;method&nbsp;&nbsp;<BR>requires&nbsp;no&nbsp;changes&nbsp;to&nbsp;existing&nbsp;software&nbsp;or&nbsp;configuration&nbsp;files.&nbsp;You&nbsp;move&nbsp;the&nbsp;&nbsp;<BR>daemons&nbsp;that&nbsp;you&nbsp;want&nbsp;to&nbsp;protect&nbsp;to&nbsp;the&nbsp;directory&nbsp;specified&nbsp;in&nbsp;&nbsp;<BR>REAL_DAEMON_DIR&nbsp;in&nbsp;the&nbsp;Makefile,&nbsp;&nbsp;<BR>replacing&nbsp;them&nbsp;with&nbsp;copies&nbsp;of&nbsp;the&nbsp;tcpd&nbsp;program.&nbsp;For&nbsp;example,&nbsp;for&nbsp;telnet:&nbsp;<BR>mkdir&nbsp;REAL_DAEMON_DIR&nbsp;<BR>mv&nbsp;/sbin/in.telnetd&nbsp;REAL_DAEMON_DIR&nbsp;<BR>cp&nbsp;tcpd&nbsp;/sbin/in.telnetd&nbsp;<BR>That's&nbsp;all&nbsp;there&nbsp;is&nbsp;to&nbsp;it.&nbsp;Note&nbsp;that&nbsp;the&nbsp;wrapper,&nbsp;all&nbsp;files&nbsp;used&nbsp;by&nbsp;the&nbsp;&nbsp;<BR>wrapper,&nbsp;and&nbsp;all&nbsp;directories&nbsp;in&nbsp;the&nbsp;path&nbsp;leading&nbsp;to&nbsp;those&nbsp;files&nbsp;should&nbsp;have&nbsp;&nbsp;<BR>read-&nbsp;or&nbsp;read-and-execute-only&nbsp;access&nbsp;(modes&nbsp;755&nbsp;or&nbsp;555);&nbsp;they&nbsp;must&nbsp;not&nbsp;be&nbsp;&nbsp;<BR>writable.&nbsp;There&nbsp;is&nbsp;no&nbsp;need&nbsp;to&nbsp;&nbsp;<BR>set&nbsp;the&nbsp;wrapper&nbsp;set-uid.&nbsp;<BR>The&nbsp;advanced&nbsp;installation&nbsp;method&nbsp;leaves&nbsp;your&nbsp;daemon&nbsp;executables&nbsp;alone,&nbsp;but&nbsp;&nbsp;<BR>involves&nbsp;simple&nbsp;modifications&nbsp;to&nbsp;the&nbsp;inetd&nbsp;configuration&nbsp;file&nbsp;/etc/inetd.conf.&nbsp;<BR>&nbsp;The&nbsp;changes&nbsp;to&nbsp;inetd.conf&nbsp;are&nbsp;straightforward.&nbsp;For&nbsp;each&nbsp;service&nbsp;to&nbsp;be&nbsp;&nbsp;<BR>protected&nbsp;by&nbsp;wrappers,&nbsp;tcpd&nbsp;&nbsp;<BR>should&nbsp;be&nbsp;executed&nbsp;in&nbsp;place&nbsp;of&nbsp;the&nbsp;original&nbsp;daemon,&nbsp;passing&nbsp;the&nbsp;original&nbsp;&nbsp;<BR>daemon&nbsp;pathname&nbsp;as&nbsp;an&nbsp;argument&nbsp;to&nbsp;tcpd.&nbsp;<BR>Here&nbsp;is&nbsp;a&nbsp;standard&nbsp;inetd.conf&nbsp;record&nbsp;for&nbsp;telnet&nbsp;service:&nbsp;<BR>telnet&nbsp;stream&nbsp;tcp&nbsp;nowait&nbsp;root&nbsp;/sbin/in.telnetd&nbsp;/sbin/in.telnetd&nbsp;<BR>

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
日韩欧美你懂的| 91女人视频在线观看| 一区二区中文字幕在线| 欧美日韩午夜在线视频| 国产一区视频网站| 天天操天天干天天综合网| 国产精品美女久久久久久久久 | 在线观看亚洲a| 国产福利一区二区三区视频| 午夜伊人狠狠久久| 亚洲日韩欧美一区二区在线| 欧美成人激情免费网| 欧美亚洲自拍偷拍| 99久久精品费精品国产一区二区| 美国毛片一区二区| 亚洲成人一二三| 夜夜揉揉日日人人青青一国产精品| 中文字幕国产一区二区| 精品少妇一区二区三区在线视频| 欧美一区永久视频免费观看| 色婷婷综合激情| 色呦呦日韩精品| 99视频精品在线| 麻豆中文一区二区| 亚洲第一福利一区| 亚洲国产综合人成综合网站| 亚洲一区二区美女| 午夜亚洲国产au精品一区二区| 一区二区三区日韩| 国产精品成人午夜| 亚洲国产欧美在线人成| 日日夜夜免费精品视频| 五月综合激情网| 久久国产精品99精品国产| 另类小说综合欧美亚洲| 福利视频网站一区二区三区| 成人亚洲一区二区一| 久久嫩草精品久久久精品| 欧洲人成人精品| 欧美成人一区二区三区| 久久精品免视看| 中文字幕在线视频一区| 性做久久久久久免费观看欧美| 美女mm1313爽爽久久久蜜臀| 黄页网站大全一区二区| 播五月开心婷婷综合| 欧美三级电影在线观看| 国产午夜精品久久| 亚洲成人精品在线观看| 国产一区二区三区美女| 99re这里只有精品视频首页| 欧美亚洲免费在线一区| 国产人妖乱国产精品人妖| 亚洲一区在线视频观看| 激情六月婷婷久久| 欧美在线一二三| 国产亚洲成av人在线观看导航 | 综合自拍亚洲综合图不卡区| 一区二区三区日韩在线观看| 毛片av中文字幕一区二区| 色综合网色综合| 国产欧美视频一区二区| 青青草精品视频| 欧美系列亚洲系列| 国产精品久久久久久久久免费樱桃| 亚洲福利视频导航| 91老师国产黑色丝袜在线| 欧亚洲嫩模精品一区三区| 国产精品欧美久久久久无广告| 免费看欧美美女黄的网站| 欧美写真视频网站| 亚洲精品日韩一| 一本久道中文字幕精品亚洲嫩| 久久久久久一级片| 石原莉奈在线亚洲二区| 99国产欧美另类久久久精品| 久久亚洲综合色一区二区三区| 国产一区二区三区蝌蚪| 精品伦理精品一区| 一区二区三区色| 欧美色综合影院| 亚洲香肠在线观看| 欧美一区二区三区思思人| 一区二区成人在线视频| 欧美日韩国产在线播放网站| 五月天网站亚洲| 日韩精品一区二区在线观看| 精品一区二区久久久| 精品国产91久久久久久久妲己| 久久99国产精品久久| 国产亚洲午夜高清国产拍精品| 成人性生交大片免费看中文网站| 欧美国产成人在线| 欧美日韩亚洲另类| 国产老女人精品毛片久久| 一区免费观看视频| 91精品国产综合久久久蜜臀图片| 精品中文字幕一区二区| 亚洲免费av高清| 日韩女优制服丝袜电影| 99精品视频免费在线观看| 日本成人中文字幕| 1区2区3区欧美| 久久只精品国产| 欧美区一区二区三区| 成人动漫一区二区在线| 午夜精品久久久久久久99樱桃 | 91精品国产乱| 91看片淫黄大片一级在线观看| 免费观看在线色综合| 亚洲影视在线观看| 一区二区中文字幕在线| 色呦呦国产精品| 国产一区二区91| 日韩不卡免费视频| 一区二区在线观看免费| 国产亚洲综合av| 精品国产凹凸成av人网站| 欧美在线看片a免费观看| 成人免费高清在线观看| 国产一区二区精品久久91| 日本欧美在线观看| 三级欧美在线一区| 日韩精品成人一区二区三区| 久久久三级国产网站| 国产精品1区二区.| 久久9热精品视频| 精品亚洲国内自在自线福利| 亚洲一二三四在线| 樱桃国产成人精品视频| 亚洲欧美成人一区二区三区| 老司机一区二区| 黄一区二区三区| 激情综合色播激情啊| 国产一区二区三区在线观看免费视频 | 一区二区三区四区av| 午夜在线电影亚洲一区| 日韩主播视频在线| 国产成人免费在线观看| 成人午夜av电影| 在线观看视频一区二区| 日韩一区二区三区视频| 日韩精品一区二区三区老鸭窝| 日韩一级成人av| 中文字幕日韩精品一区| 中文字幕佐山爱一区二区免费| 亚洲成a人在线观看| 国产精品亚洲第一区在线暖暖韩国| 成人av小说网| 日韩欧美在线网站| 国产女主播视频一区二区| 亚洲国产成人高清精品| 精品一区二区三区的国产在线播放| 国产成人丝袜美腿| 欧美一区二区三区播放老司机| 国产清纯美女被跳蛋高潮一区二区久久w| 国产精品久久久久久久久免费丝袜| 亚洲精品第一国产综合野| 国产精品自拍一区| 69成人精品免费视频| 国产精品不卡视频| 国产福利一区二区三区视频| 欧美日韩日日骚| 国产精品夫妻自拍| 成人性生交大片免费| 91久久线看在观草草青青| www激情久久| 九一久久久久久| 欧美一级精品在线| 亚洲成人自拍网| 欧美日韩欧美一区二区| 一区二区三区美女视频| 91女神在线视频| 在线观看精品一区| 精品少妇一区二区三区在线播放| 亚洲成人综合网站| 欧美在线一二三四区| 亚洲一区二区三区中文字幕| 色老综合老女人久久久| 国产精品欧美一区二区三区| 成人免费观看视频| 自拍偷在线精品自拍偷无码专区| 国产jizzjizz一区二区| 国产三级欧美三级日产三级99| 精品在线观看视频| 欧美sm极限捆绑bd| 精品亚洲国内自在自线福利| 日韩免费看的电影| 国产伦精品一区二区三区在线观看| 日韩精品中文字幕在线不卡尤物 | 久久夜色精品国产噜噜av| 国产91丝袜在线播放0| 亚洲女厕所小便bbb| 欧美三级电影一区| 国产老女人精品毛片久久| 国产精品传媒入口麻豆| 欧美日韩午夜精品| 成人18精品视频| 日本不卡的三区四区五区| 久久久久久久精|