Old 09-08-2003, 07:48 AM   #1
Registered: Apr 2003
Location: nottingham england
Distribution: Gentoo
Posts: 2,672

Rep: Reputation: 47
please rate me security settings

Hi, im a newb to security....
so could some1 who knows a little rate my systems security, here's the relevent info...

Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT all -- localhost.localdomain localhost.localdomain
DROP tcp -- anywhere anywhere tcp dpts:0:1024
DROP udp -- anywhere anywhere udp dpts:0:1024
DROP tcp -- anywhere anywhere tcp dpt:x11

Chain FORWARD (policy ACCEPT)
target prot opt source destination

Chain OUTPUT (policy ACCEPT)
target prot opt source destination

Starting nmap V. 3.00 ( )
Interesting ports on (
(The 1025 ports scanned but not shown below are in state: filtered)
Port State Service
Nmap run completed -- 1 IP address (1 host up) scanned in 131 seconds
Old 09-08-2003, 08:43 AM   #2
Registered: Feb 2003
Location: Somewhere, UK
Distribution: Slack, OpenBSD, Debian, SuSE
Posts: 189

Rep: Reputation: 30
try again from either an internal machine on your network or from the host your scanning itself scanning the loopback (ie., also try 'netstat -lap'
Old 09-09-2003, 04:28 AM   #3
Registered: May 2001
Posts: 27,017
Blog Entries: 54

Rep: Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764Reputation: 2764
could some1 who knows a little rate my systems security, here's the relevent info...
// First of all, if you're able to edit your first post and slash everything between "1026/tcp closed LSA-or-nterm" and "61441/tcp closed netprowler-sensor" that would make your post readable. You could've simply said all ports in the unprivileged port range where closed...

Wrt your firewall, I would like to suggest
- changing your default policy to DROP. You'll then have to add a line for each local service you want remote clients to connect to but it will not *by default* allow rogue servers to be run on high ports like you do now,
- changing the x11 line. X11 ain't a port, it's a port range, aprox 6000:6020 (IIRC),
- look at the first thread in this forum. It's got a section on Netfilter firewalling, and you're missing a lot like DROP rules for packets with bad flags, rate limiting, logging etc etc.
- scan your box from a remote one. There's some threads in this forum that list websites. (use search)

But, firewall != security. Please look at the first thread in this forum, the first post. Read two or three of "Checklists", "Securing", then move on to distro-specific stuff.

In broad lines you could say "securing and hardening" a box means taking away/investigating risks by
- installing only what you need,
- running only what you need,
- restricting local system users' processes and access ("nologin" shells, configuration issues like service anti-DOS features, running services as lesser-privileged users, chroots etc etc),
- restricting local and remote (human users' processes and) access (PAM login/limits, good passwds, sudo, no telnet but ssh, process restrictions like in or LIDS, service allow/deny files etc etc),
- performing auditing on a regular basis (system integrity checks like Aide, Samhain or tripwire, Tiger, Lsat, COPS, Chkrootkit, env_audit),
- performing continuous traffic/loganalysis (process table and connection tracking tools, IDS, logparsing tools etc etc) and
- performing maintenance (updates, configuration) on a regular basis.


