LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-07-2006, 04:08 AM   #16
TigerOC
Senior Member
 
Registered: Jan 2003
Location: Devon, UK
Distribution: Debian Etc/kernel 2.6.18-4K7
Posts: 2,380

Rep: Reputation: 49

You might also consider using mod-security from http://www.modsecurity.org . If you apply the various generic rules on their site you will stop a lot of these in their tracks and then not have to worry about continually updating the firewall for various ip addresses.
 
Old 04-07-2006, 08:19 PM   #17
fotoguy
Senior Member
 
Registered: Mar 2003
Location: Brisbane Queensland Australia
Distribution: Custom Debian Live ISO's
Posts: 1,291

Rep: Reputation: 62
Quote:
Originally Posted by piforever
Thnx....I think someone in the past made a patch similar to this (reported in his blog) and we were supposed to patch the iptables first...Do you mean this module became standard now??? And if so, in which version???

Thnx for the tip, where can I have more info about this??
Yes i think most of the 2.4.X kernels did need to be patch for the recent module, but I think most of the 2.6.X kernels now have it as a default module for the kernel. If you are using FC4 then it is already a module of the kernel.

To check just su to root, type at the command line:

modprobe ipt_recent

It should then exit to a new line without displaying anything, the to check to see the loaded modules type:

lsmod

You should get something similar to this:

ipt_recent 10764 0
ip_tables 19456 1 ipt_recent
joydev 9408 0
sg 35744 0
st 38944 0
sd_mod 18576 0
sr_mod 16420 0
scsi_mod 131304 4 sg,st,sd_mod,sr_mod
ipv6 242752 6
hfsplus 75140 0
vfat 12800 0
fat 49692 1 vfat
subfs 7552 1
speedstep_lib 4228 0
freq_table 4612 0
nfsd 223072 5


Your module list will be much longer than this, this is just a snippet of the output from my console. For more info just google for recent module iptables, I think it was written by a person named snowman.
 
Old 04-07-2006, 08:46 PM   #18
haertig
Senior Member
 
Registered: Nov 2004
Distribution: Debian, Ubuntu, LinuxMint, Slackware, SysrescueCD, Raspbian, Arch
Posts: 2,331

Rep: Reputation: 357Reputation: 357Reputation: 357Reputation: 357
You could also check out DenyHosts. http://denyhosts.sourceforge.net/ I have no idea how it compares to other programs that have been suggested. I researched into it a little while back but never got around to using it for real. Add it to your list of potentials, but you'll have to research it yourself.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
unknown activities on Fedora 3 gaddargarson Fedora 2 04-04-2005 07:46 AM
how to track user's all activities? hensonliu Linux - Security 6 12-27-2004 02:09 PM
My network-based activities are slower than XP! rolandus Linux - Networking 2 04-17-2004 12:27 AM
Recording process activities (how?) gary.chan Linux - Software 1 08-16-2003 11:11 PM
track desktop activities rinux Linux - Newbie 1 05-28-2003 06:19 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:02 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration