LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-29-2003, 05:43 PM   #1
odious1
Member
 
Registered: Jun 2003
Location: Virginia, USA
Distribution: Slackware
Posts: 252

Rep: Reputation: 30
limit hosts


What can be done to prevent unauthorized hosts from getting access to my network? In other words what would prevent someone from plugging into my hub and getting an ip? I could give ips to only certain hardware addresses but couldn't someone set a static on within an acceptable range?

In samba i could set hosts allow, but that just limits access based on ip's = hostname in lmhosts; correct? I think a machine with the an acceptable ip would get access even if the netbios name did not match.

ideas? RH7.2, Samba with windows xp and 98 clients
 
Old 10-29-2003, 06:47 PM   #2
frogman
Member
 
Registered: Sep 2003
Distribution: Mandrake, Slack, Debian and PicoBSD
Posts: 181

Rep: Reputation: 31
Short answer - given time and opportunity, bugger all.

But..... you can make it difficult.

Replace the hub(s) with a layer 3 switch (es) and read up on ACLs.

Restrict each (switch) port to a specific MAC address and block unused ports (so to spoof a MAC address, they have to pull something off the network - your users _may_ notice when someone nicks their connection.)

You could set the ACLs so that the MAC address can't reconnect to the port within a certain period of time (1/2 hr ?), but this is flaky if J Random Luser reboots his machine a lot.

Unfortunately, in XP and 2000 you can change the MAC address on your machine to whatever you want, so an ACL based around MAC addresses is breakable, but not too bad.
 
Old 10-30-2003, 10:16 AM   #3
aqoliveira
Member
 
Registered: Dec 2001
Location: Portugal
Distribution: /Red Hat/Fedora/Solaris
Posts: 622

Rep: Reputation: 30
Howzit

If your server is running as a DHCP server as well, then u could creat rules that only those MAC are accpeted by the DHCP server and all others will not get a addr. To get these addr and MAC addr try using the cmd arp -a

chow
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Limit internet access for certain hosts during certain time i16978 Linux - Newbie 2 05-05-2005 12:19 AM
limit number of hosts behind Proxy anoopshukla Linux - Networking 0 02-04-2005 04:32 AM
Practical limit to the number of hosts on Apache? JimBass Linux - Newbie 3 11-09-2004 09:46 PM
Adding shell commands to hosts.deny and hosts.allow ridertech Linux - Security 3 12-29-2003 03:52 PM
Quota issue, hard limit doesn't limit users Gratz Linux - Software 2 09-16-2003 07:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:05 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration