LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-04-2015, 12:03 AM   #1
Peter_APIIT
Member
 
Registered: Dec 2006
Posts: 606

Rep: Reputation: 31
Open Port Security


Dear All, I wonder any security problem with this configuration:

unbound - dnscrypt-proxy
Squid
dhcp
ntpd


Quote:
Active Internet Connection (including servers)

Proto Recv-Q Send-Q Local Address Foreign Address (State)
ip 0 0 *.* *.* 1

tcp 0 0 127.0.0.1:53 *.* LISTEN
tcp 172.16.1.1:53 *.* LISTEN
tcp 127.0.0.1:443 *.* LISTEN
tcp 127.0.0.1:3128 *.* LISTEN
tcp 127.0.0.1:3129 *.* LISTEN

udp *.514 *.*
udp *.* *.*
Thanks.
 
Old 08-04-2015, 06:31 PM   #2
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,649
Blog Entries: 4

Rep: Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934Reputation: 3934
There is not, per se, any "intrinsic vulnerability" associated with a particular TCP/IP port being "open," to access by particular range(s) of TCP/IP addresses that you are aware-of and intend.

You simply need to practice "the principle of least access." A firewall is your stupidest, therefore "first and most basic," line of defense. (Never try to reason with a Troll.) Therefore, be sure that you allow access to "nothing and no-one else but" "the minimal Scope Of The Universe that is required."

For instance: dhcpd. Who, exactly, might this daemon need to provide internet-addresses to? Or, ntpd? Who, exactly, might legitimately ask this daemon for the time-of-day?

And so it goes. . .
 
Old 08-04-2015, 08:59 PM   #3
Peter_APIIT
Member
 
Registered: Dec 2006
Posts: 606

Original Poster
Rep: Reputation: 31
Quote:
Originally Posted by sundialsvcs View Post
There is not, per se, any "intrinsic vulnerability" associated with a particular TCP/IP port being "open," to access by particular range(s) of TCP/IP addresses that you are aware-of and intend.

You simply need to practice "the principle of least access." A firewall is your stupidest, therefore "first and most basic," line of defense. (Never try to reason with a Troll.) Therefore, be sure that you allow access to "nothing and no-one else but" "the minimal Scope Of The Universe that is required."

For instance: dhcpd. Who, exactly, might this daemon need to provide internet-addresses to? Or, ntpd? Who, exactly, might legitimately ask this daemon for the time-of-day?

And so it goes. . .
dhcpd - Only Internal Interface
unbound/dnscrypt-proxy - localhost and Internal Network
ntpd - localhost only
squid - Internal network
 
1 members found this post helpful.
Old 08-24-2015, 12:43 AM   #4
Peter_APIIT
Member
 
Registered: Dec 2006
Posts: 606

Original Poster
Rep: Reputation: 31
Problem solved.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Need to open up port 21 for ftp xfers in RH9 on high security orange400 Linux - Networking 9 05-27-2004 05:29 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:00 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration