LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-19-2003, 02:45 PM   #1
C8H10N4O2
Member
 
Registered: Dec 2002
Location: Australia
Distribution: SuSE, Vector Linux
Posts: 51

Rep: Reputation: 15
Securing SuSE 8.2


I have just installed SuSE 8.2 Pro, downloaded all the patches, and configured my firewall with the YaST2 Control Centre (blocking everything since I'm not a server). To see how things went I did an nmap scan and found some open ports. Every tutorial I read said that in order to close them I just type:

iptables -A INPUT -p tcp --dport 21 -j REJECT (replacing '21' with whatever port I want closed)

Anyway I did all that, no error messages, no feedback of any kind, so I did another nmap scan ('nmap -sS localhost' is correct to do that right?) and all the ports were still open. Can someone tell me how I would go about closing them?

Thanks.
 
Old 06-19-2003, 07:46 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
1. There's a difference between REJECT and DROP. REJECT allows for control messages (ICMP) to travel back to the remote host, while DROP just does what it sez: drop the packet and not bother with it.
2. I find results from scanning from a remote host more trustworthy. If you can't, Google for "nmap yashi" or securityspace or dslreports for basic free scans.
3. Read up on default policies.
 
Old 06-20-2003, 06:06 PM   #3
george441
LQ Newbie
 
Registered: Jun 2003
Posts: 2

Rep: Reputation: 0
GUI

If your having problems setting up the iptables then you might like a gui with help function.

Have a look here: http://users.pandora.be/stes/ipmenu.html

Good luck
 
Old 06-21-2003, 01:19 PM   #4
C8H10N4O2
Member
 
Registered: Dec 2002
Location: Australia
Distribution: SuSE, Vector Linux
Posts: 51

Original Poster
Rep: Reputation: 15
Thanks for that. i used those sites and it seems that I'm not as vulnerable as I feared.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
securing script Ammad Linux - General 3 08-15-2005 07:02 AM
Securing SSH ZilverZtream Linux - Security 5 12-10-2004 03:33 PM
Securing Passwd Obie Linux - Security 5 05-31-2004 06:36 PM
Securing DNS hookooekoo Linux - Networking 1 12-26-2003 04:03 AM
securing FTP radnix Linux - Security 3 09-16-2002 01:46 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:45 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration