LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-05-2001, 12:57 PM   #1
glumpkin
LQ Newbie
 
Registered: Apr 2001
Posts: 1

Rep: Reputation: 0
Lightbulb Denial of Traffic


This is a real Linux Newbie question, so please bare with me.

I work in the IT department of a local Civil Engineering firm. We are a Microsoft shop after migrating away from Novell. A mistake in my opinion, but that's another conversation altogether.

I have a Linux server at home and I have RedHat on a laptop which I think is pretty cool in itself.

OK, here it is: We had two users double-click on the gone.scr file in their in-boxes yesterday and I spent much of my day cleaning up the network and their workstations. Norton AntiVirus didn't have the signatures updated in time. Not an uncommon occurrence unfortunately. We use a Cisco PIX firewall.

I was wondering (and here's where my lack of knowledge shows), is there a way to deny entry if a packet contains certain attributes? In other words, if a person outside our network sends an e-mail to an internal user with gone.scr attached, can a Linux firewall be configured to reject it altogether?

Just curious...
 
Old 12-05-2001, 03:04 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Iptables has some (rudimentary?) form of filtering, but Im not familiar with that, maybe someone else can come up with the gory details :-]
Snort, an IDS package ,allows you to filter for strings like this CodeRed entry shows:
alert TCP $EXTERNAL any -> $INTERNAL 80 (msg: "CodeRed/Index Server - Generic"; content:".ida?";)
but this ain't what you're looking for.
The keyword is email since that is the only infection vector (transport layer) I know of; you'll need to look into mail filtering.

If you're mailhost is running a Linux MTA like sendmail you could either add rules to the /etc/sendmail.cf (or use libmilter, inflex, possibly ripmime or any other filters). An example of what sendmail can filter is here (Melissa). Possibly cert.org, sans.org and/or securityfocus.com already have prefab rules out for filtering.

If OTOH its running the very leet Microsuck Xchange S3rv3r, there's another good reason to convert to Linux :-]

Last edited by unSpawn; 12-05-2001 at 03:07 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
permission denial while udp_sendmsg alwaysrookie Programming 2 11-04-2005 12:42 PM
Execution Denial on FAT32 pymehta Linux - Security 1 01-22-2004 11:31 PM
Denial Of Service Attacks Ozzman Mandriva 13 11-13-2003 12:59 AM
denial of services ?? johnyy Linux - Security 5 09-28-2003 10:15 AM
DHCPD Denial htimst Linux - Networking 8 02-01-2002 09:45 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 10:57 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration