LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Fedora
User Name
Password
Fedora This forum is for the discussion of the Fedora Project.

Notices


Reply
  Search this Thread
Old 12-13-2003, 12:17 PM   #1
cpv204
Member
 
Registered: Mar 2003
Location: Tribeca, NYC
Distribution: Slackware 9.0, Fedora Core 1
Posts: 111

Rep: Reputation: 15
which iptables to modify? I have 3.


I'm just learning about security and did a port scan at grc.com. I got a "Stealth" status except for one thing, my machine will reply to pings. They say most firewalls can be configured to ignore pings.

I think this needs to be done my modifying my iptables script. The thing is, I have three of them on my Fedora distribution:

/var/lock/subsys/iptables
/etc/sysconfig/iptables
/etc/rc.d/init.d/iptables

None of them are symlinks to another.

So, which iptables script should I modify and, for bonus points, does anyone know how to set my machine to ignore pings?

Thanks.
 
Old 12-13-2003, 12:25 PM   #2
david_ross
Moderator
 
Registered: Mar 2003
Location: Scotland
Distribution: Slackware, RedHat, Debian
Posts: 12,047

Rep: Reputation: 79
Just run:
echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_all
echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_broadcasts
 
Old 12-13-2003, 12:37 PM   #3
cpv204
Member
 
Registered: Mar 2003
Location: Tribeca, NYC
Distribution: Slackware 9.0, Fedora Core 1
Posts: 111

Original Poster
Rep: Reputation: 15
Thanks, that certainly did the trick!

For Fedora users (possibly Red Hat users) what is the "proper" place to stick these two lines so they automatically run at startup?
 
Old 12-13-2003, 01:06 PM   #4
david_ross
Moderator
 
Registered: Mar 2003
Location: Scotland
Distribution: Slackware, RedHat, Debian
Posts: 12,047

Rep: Reputation: 79
You can put the commands at the end of rc.local or configure the directives in /etc/sysctl.conf
 
Old 12-14-2003, 03:48 AM   #5
/bin/bash
Senior Member
 
Registered: Jul 2003
Location: Indiana
Distribution: Mandrake Slackware-current QNX4.25
Posts: 1,802

Rep: Reputation: 47
Actually responding to a ping is a requirement or RFC_1122. So not many distros will supply you with a non-compliant firewall. But they will give you the option to not-comply, if you so choose. Don't let the port scanners scare you, replying to a ping does not make your computer any more vulnerable to an attack than not replying.

There is a good discussion on the subject here.
 
Old 12-14-2003, 06:40 AM   #6
cpv204
Member
 
Registered: Mar 2003
Location: Tribeca, NYC
Distribution: Slackware 9.0, Fedora Core 1
Posts: 111

Original Poster
Rep: Reputation: 15
Very interesting, /bin/bash. Nice to hear the straight dope from someone who knows. I know next to nothing about security and want to open up port 80 to run a web server for the first time, so I'm trying to learn all I can before doing so. Thanks!
 
Old 12-14-2003, 09:35 AM   #7
david_ross
Moderator
 
Registered: Mar 2003
Location: Scotland
Distribution: Slackware, RedHat, Debian
Posts: 12,047

Rep: Reputation: 79
Although it doesn't help security much it does deter some viruses. Viruses like the MS Blaster virus used pings to find out which machines were responding then flooded them with more traffic. Although Linux will be immune to Microsoft viruses it will still push extra traffic in your direction.
 
Old 12-14-2003, 12:44 PM   #8
/bin/bash
Senior Member
 
Registered: Jul 2003
Location: Indiana
Distribution: Mandrake Slackware-current QNX4.25
Posts: 1,802

Rep: Reputation: 47
Quote:
Nice to hear the straight dope from someone who knows.
I hope you are referring to the author of the article I linked to.

I had never heard that side of the argument before and I thought it was logical. I have since become less concerned about getting all green blocks on www.grc.com.

And I think the attacks david_ross is referring to are usually aimed at bigger fish that me e.g. Microsoft.com or better yet SCO.com
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to modify fstab? SLAY3R Linux - Newbie 7 09-18-2004 11:03 AM
Modify IP Address? VBAHole22 Linux - Networking 1 07-06-2004 03:16 PM
How to modify the library path variable?modify the Electronkz Linux - Newbie 1 04-13-2004 06:18 AM
modify file access & modify timestamps i2itstud Linux - General 1 05-20-2003 03:34 AM
shorewall - no X, where do i modify? bkeating Linux - Security 1 01-17-2003 11:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Fedora

All times are GMT -5. The time now is 06:19 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration