LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-21-2003, 08:38 PM   #1
benjithegreat98
Senior Member
 
Registered: Dec 2003
Location: Shelbyville, TN, USA
Distribution: Fedora Core, CentOS
Posts: 1,019

Rep: Reputation: 45
iptables and open ports


I ran nmap from a remote computer and got this:

Host <my ip>chartertn.net <my ip> appears to be up ... good.
Initiating SYN Stealth Scan against <my ip>chartertn.net <my ip> at 20:10
Adding open port 21/tcp
Adding open port 25/tcp
The SYN Stealth Scan took 24 seconds to scan 1657 ports.
Interesting ports on <my ip>chartertn.net <my ip>:
(The 1640 ports scanned but not shown below are in state: closed)
PORT STATE SERVICE
21/tcp open ftp
25/tcp open smtp
135/tcp filtered msrpc
136/tcp filtered profile
137/tcp filtered netbios-ns
138/tcp filtered netbios-dgm
139/tcp filtered netbios-ssn
397/tcp filtered mptn
445/tcp filtered microsoft-ds
593/tcp filtered http-rpc-epmap
1723/tcp filtered pptp
5050/tcp filtered mmcc
5190/tcp filtered aol
6667/tcp filtered irc
7000/tcp filtered afs3-fileserver
12345/tcp filtered NetBus
31337/tcp filtered Elite

I have an iptables entry to REJECT all new incoming packets, and when I run netstat on my computer it tells me I don't have anything running on port 21 or 25. Sendmail is not running and I chose not to install an ftp server on there.

Also, if a port is in a state filtered is it as good as closed? Should I worry?
BTW this is a Slack9.1 installation

Any help would be appreciated!
 
Old 12-22-2003, 12:42 AM   #2
DavidPhillips
LQ Guru
 
Registered: Jun 2001
Location: South Alabama
Distribution: Fedora / RedHat / SuSE
Posts: 7,163

Rep: Reputation: 58
instead of DROP use REJECT to fix the filtered issue if you want to.

if 21 and 25 do not show up in the output of netstat they are most likely another computer.

to see what machine it's running on try this..


telnet ipaddress 25

example:

[david@zeus david]$ telnet dcphillips.net 25
Trying 68.63.15.139...
Connected to mail.dcphillips.net (68.63.15.139).
Escape character is '^]'.
220 mail.dcphillips.net ESMTP Wassup! Welcome to the mail shredder.

Last edited by DavidPhillips; 12-22-2003 at 01:35 AM.
 
Old 12-22-2003, 08:07 AM   #3
benjithegreat98
Senior Member
 
Registered: Dec 2003
Location: Shelbyville, TN, USA
Distribution: Fedora Core, CentOS
Posts: 1,019

Original Poster
Rep: Reputation: 45
I have attempted to telnet and I get nothing, no connection. I've tried remotely and locally and I get zilch. I will try the REJECT command however.
 
Old 12-22-2003, 10:19 PM   #4
DavidPhillips
LQ Guru
 
Registered: Jun 2001
Location: South Alabama
Distribution: Fedora / RedHat / SuSE
Posts: 7,163

Rep: Reputation: 58
What do you have in your ruleset for tcp
 
Old 12-23-2003, 06:44 AM   #5
moonloader
Member
 
Registered: Nov 2003
Location: linuxquestions.org
Distribution: Linux and BSD
Posts: 229

Rep: Reputation: 30
I think you're using portsentry,because portsentry opens or filters by default.if you don't want those ports opens or filters just try to configure portsentry didn't help just uninstall portsentry and all ports will be closed those portsentry opens or filters by default.open ports intrest sure the intruder or scanner usuall they would like to know what runs on that port?mostly trojan seekers or port flooders,but if a port closed or stealth from outside then it won't be attacked!

Last edited by moonloader; 12-23-2003 at 06:52 AM.
 
Old 12-23-2003, 08:12 AM   #6
benjithegreat98
Senior Member
 
Registered: Dec 2003
Location: Shelbyville, TN, USA
Distribution: Fedora Core, CentOS
Posts: 1,019

Original Poster
Rep: Reputation: 45
I don't have the computer in front of me but basically if the connection is not ESTABLISHED then I tell it to reject. I am on a cable connection and I had the crazy idea that the cable modem provided by Charter would have open ports on it.... Like to send back a report to Charter or something of that nature. This is a computer I'm trying to turn into a router so I've only been testing eth0 (external port) I'm going to scan my eth1 and see what it turns up. If eth0 has ports 21 and 25 closed then I'll pretend they are really closed.

Does that sound crazy to anybody?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How can I open up ports in iptables? ekerik Linux - Networking 13 10-07-2009 11:00 AM
Open All Ports - iptables Artik Linux - Networking 2 06-21-2005 03:17 PM
ports open with iptables saugato Linux - Security 3 04-19-2005 01:31 AM
open ports with iptables? tykkea811 Linux - Networking 2 12-12-2004 01:43 AM
Iptables: Open some ports! Abomm Linux - Networking 2 05-31-2002 01:49 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 05:07 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration