LinuxQuestions.org
View the Most Wanted LQ Wiki articles.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 10-01-2002, 06:40 AM   #1
darookee
LQ Newbie
 
Registered: Sep 2002
Location: Long Beach, CA.
Distribution: Lunar, gentoo, SuSE
Posts: 3

Rep: Reputation: 0
Securing a companies Webserver


Howdy everybody!

I have to secure our companies webserver with iptables so I searched for HowTos but I only found some which described how to set up a router or something like that ...

so now I played a bit around with that stuff and managed to set up some basic rules ... ports for web/secure-web, ftp/ftp-data, smtp, pop3 and IRC-proxy ( o_O ) are open to the public and mysql and ldap are only open for localhost ...
so far so good but now, if I connect via ftp it is much slower than if every port is open ... and with pop3 it is the same thing ( sometimes it 'hangs' for more than 3 minutes ... )
I think that he tries to connect to some other ports after he connected to the 'main' port is that right ?
so i tried out with a
iptables -A INPUT -m tcp -p tcp --tcp-flags ALL SYN,ACK -j ACCEPT
but there was no change ...
even with a --state ESTABLISHED,RELATED
not ...

( hmm ... well ... i'm a nubie ^^ )

has someone a good howto for webserver iptables security ? or maybe a good script ?

thanks in advance
darookee
 
Old 10-01-2002, 07:02 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 21,610
Blog Entries: 47

Rep: Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413Reputation: 1413
Could you search both the security and networking forum?
Next to specifics on how to solve security and networking problems there's tons of links to HOWTO's, security sites etc etc.
security+howto
security+links
security+basics
security+reference

If you have problems with iptables, include a general rule that will log traffic so you can see what get's denied so you can try to solve it, and/or post your script.

CERT's Techtips, especially the "UNIX Computer Security Checklist",
CERT, root compromise, part F,
LASG: Linux Administrator's Security Guide,
Security Quick-Start HOWTO for Linux,
Armoring Linux,
SAG: The Linux System Administrator's Guide,
The SANS Reading room: Linux issues,
Bastille Linux Hardening System,
Elementary security for your Linux box,
Securityfocus.com vulnerabilities by Bugtraq/CVE ID,
CERT,
Sans Reading Room (reach tru Google cache!),
SecFocus UNIX,
LinuxSecurity.com,
ISS,

The rest of my (old) security reference list is in the second reply here: "possibly a dumb(..)".
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Do you know of any companies using Fedora? argos333 Fedora 6 06-22-2005 03:46 PM
Porting Companies nny0000 Linux - Games 1 12-14-2003 08:03 PM
hosting companies enzo250gto General 1 10-14-2003 11:25 AM
Can't see WebServer from outside... Can see WebServer locally as http://localhost friddick Linux - Networking 13 08-19-2003 06:27 PM
Let the Hardware Companies Know Crashed_Again Linux - General 14 04-30-2003 09:51 PM


All times are GMT -5. The time now is 11:23 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration