LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-03-2006, 10:46 PM   #1
badmofo666
Member
 
Registered: Mar 2004
Location: Texas, USA
Distribution: Ubuntu 12 (notebook), Debian Squeeze (home server), OpenSuse 12 (desktop)
Posts: 96

Rep: Reputation: 15
Sheilds up shows opened ports with Firestarter?


I just made my old computer into a Router/Firewall using Firestarter. I checked the firewall with the Shields Up website and it showed just a few "stealthed" ports, about 3 opened ports, and all the rest showed "closed." It said that all the ports should be "stealthed."

The opened ports really worried me. It showed OpenSSH(which I use locally), DNS(not sure if I need), and some unknown port in the 800's as opened. The only ports I have open in firestarter are port forwarded to my other pc, and that's just azureus, limewire, and a game(these were the only stealthed ports). I also set firestarter to always accept connection from my local IP.

I thought firestarter is supposed to block all inbound connections unless they're specifically allowed?

After this, I did set it to block all ICMP services and ran sheilds up again, and this time it showed everything as "stealthed." I don't know if this will cause any problems or not though? Is my system now firewalled or not?
 
Old 10-04-2006, 02:38 AM   #2
//////
Member
 
Registered: Nov 2005
Location: Land of Linux :: Finland
Distribution: Arch Linux && OpenBSD 7.4 && Pop!_OS && Kali && Qubes-Os
Posts: 824

Rep: Reputation: 350Reputation: 350Reputation: 350Reputation: 350
I wouldn't trust grc so much, there is lots of better scans around.

Nessus scan:
http://www.it-sec.de/vulchke.htm

Different pings and Dos packets.
http://www.pcflank.com/scanner1s.htm

Normal tcp - udp scan.
http://scan.sygate.com/

Test with these if you have any open ports.

Last edited by //////; 10-04-2006 at 02:39 AM.
 
Old 10-05-2006, 07:24 AM   #3
badmofo666
Member
 
Registered: Mar 2004
Location: Texas, USA
Distribution: Ubuntu 12 (notebook), Debian Squeeze (home server), OpenSuse 12 (desktop)
Posts: 96

Original Poster
Rep: Reputation: 15
Those all said I passed too. But...

I don't see how just filtering ICMP would close my open ports?

Or were these ports really open?
 
Old 01-01-2007, 10:37 PM   #4
addux
Member
 
Registered: Dec 2006
Location: In the middle of the ocean.
Distribution: Ubuntu 12.04, Debian Squeeze, Windows 7
Posts: 67

Rep: Reputation: 16
**I'm a neWb plz bear with me**

This isn't directly related to the thread and related problem but includes issues with Firestarter, open ports, security, and ultimately Azureus.

I use Firestarter despite the understanding that Ubuntu (my current *nix), by default, closes all incoming ports. I have opened port 6881 for Azureus although Firestarter 'warns' it is open to anyone. At night I leave my torrents on the net to be seeded and on numerous occasions I wake up to see that various high numbered, random ports are open as an active connection ("unkown" apps/service), including various connections, as expected, on port 6881. Finally, they, according to Firestarter, stay active after Azureus is terminated. Is this a serious problem? Any ideas as to why the ports stay open? Related at all to exploits or bugs in Azureus?
 
Old 01-02-2007, 01:53 AM   #5
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Quote:
Originally Posted by badmofo666
Those all said I passed too. But...

I don't see how just filtering ICMP would close my open ports?

Or were these ports really open?
Because it blocked the out-bound "ICMP port unreachable" errors. It's not any more secure, it just made the scanner happy.

You should check your firewall configuration to see what it's set to block and allow. If SSH is really opened from the Internet, that might not be what you wanted.
 
  


Reply

Tags
better



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Machine compromised, now have ports opened tvn Linux - Security 4 09-21-2005 03:04 AM
How to check what ports are opened Mic Q SUSE / openSUSE 6 08-23-2005 09:04 PM
newly opened terminal shows bash-2.05$ instead of path jang Linux - General 6 01-18-2004 05:21 PM
Which ports should be opened? ivanatora Linux - Security 8 09-28-2003 08:24 AM
Ports that are already opened? ksoma Linux - Newbie 3 06-29-2003 08:13 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:31 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration