LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-29-2009, 06:28 PM   #1
PopeInnocent
LQ Newbie
 
Registered: Oct 2003
Posts: 2

Rep: Reputation: 0
Angry SecurityMetrics scan of CentOS 5 web server is "inconclusive"


I am trying to figure out if I have some sort of port scan blocking configured on my web server. This may be a long post - sorry.

I have a CentOS 5/Apache web server sitting behind a firewall with TCP port 80 NAT'd from the firewall to the server. My company has an account with SecurityMetrics that includes quarterly scans against the network. The scans fail randomly. The single failing item reports:

"There is a high probability that some type of firewall or scan-detection software is blocking us from accurately scanning your server. Please configure any firewall or software that would interfere with our scans to allow all traffic from SecurityMetrics."

According to a SecurityMetrics support technician, port 80 is initially visible, then disappears at some point. Since all of the other Internet services (provided by different servers) do not have problems, I'm left to wonder if there is a problem with the web server.

So, on to questions:

1) What, if anything, would be running or configured on a stock RHEL/CentOS server that would detect an intrusion attempt? This server is behind a firewall, so the ONLY port that the outside world can touch is TCP/80.
2) I can image a scenario where a scan causes some kind of crash or denial of service. What could I look at to see if the server is being overwhelmed?

Thanks!
 
Old 05-29-2009, 07:36 PM   #2
stress_junkie
Senior Member
 
Registered: Dec 2005
Location: Massachusetts, USA
Distribution: Ubuntu 10.04 and CentOS 5.5
Posts: 3,873

Rep: Reputation: 335Reputation: 335Reputation: 335Reputation: 335
Do you have fail2ban running on the web server?

http://www.fail2ban.org/wiki/index.php/Main_Page
 
Old 06-01-2009, 07:35 AM   #3
PopeInnocent
LQ Newbie
 
Registered: Oct 2003
Posts: 2

Original Poster
Rep: Reputation: 0
fail2ban doesn't appear to be installed. Attached is the output of "yum list installed". (I realize it's long and you probably have better things to do with your time.)

Thanks!
Attached Files
File Type: txt yum-list-installed.txt (31.4 KB, 9 views)
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Yet another "which distro should I choose" thread, 500 MHz web server fudam Linux - General 4 09-03-2007 12:17 PM
Can I run a port scan to a "target" machine from the internet? NuxIT Linux - Networking 9 05-18-2006 06:20 AM
Web server Debian "Sarge" Worksman Linux - Newbie 12 08-08-2005 05:41 AM
difference between "Web server local URL" and "IPv4 address"? kpachopoulos Linux - General 2 09-17-2004 01:30 PM
Mandrake 10: Issues with "higher" security setting and web server maverick106 Mandriva 6 04-26-2004 10:39 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:50 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration