LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-06-2004, 02:20 PM   #1
vasudevadas
Member
 
Registered: Jul 2003
Location: Bedford, UK
Distribution: Slackware 11.0, LFS 6.1
Posts: 519

Rep: Reputation: 30
Stealthing IDENT port 113


Hi all,

testing my firewall at http://grc.com, my computer failed the port scan because port 113 was closed. All others were stealthed. I have two questions about this:

(1) is this a problem?

(2) if so, what can I attempt to fix it?

I am simply using the default firewall with Mandrake 9.1, set to disallow all incoming connections.
 
Old 01-06-2004, 07:43 PM   #2
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
1: No.
2: You can change your firewall rule from "REJECT" to "DROP" for port 113/tcp, but I wouldn't recommend it. IRC and a number of other services attempt to challenge incoming connections by issuing an IDENT request to their IP. The connection will not be allowed to continue until the IDENT query has either been replied to or times-out. You could be waiting several minutes for the IDENT query to time-out, and in the mean time you might get dropped from the server (or your client might disconnect).

By leaving the rule set to "REJECT" it immediately tells the IRC server (or whatever is trying to IDENT you) that you are refusing the connection. The IRC server then goes on it's merry way and allows you to connect. There was recently a thread on this same forum about this very same question where the user said he had to reject the connection with a specific ICMP type and code. If I were you, I would search the board for "113" and "irc" and see if you can find it.
 
Old 01-07-2004, 03:21 AM   #3
vasudevadas
Member
 
Registered: Jul 2003
Location: Bedford, UK
Distribution: Slackware 11.0, LFS 6.1
Posts: 519

Original Poster
Rep: Reputation: 30
I searched as you recommended, and I think I'll leave it as it is. Thanks!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
port 113 auth ident, not accepting connectiong green4u Linux - Security 1 07-18-2005 08:15 AM
stealthing port 113 danielw Linux - Security 4 12-21-2003 03:53 AM
113 port spank Linux - Newbie 3 12-02-2003 03:54 PM
Stealthing port 113 B McHack Linux - Distributions 1 11-16-2003 05:14 PM
port 113 pangfai Linux - Security 7 06-06-2002 05:53 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:32 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration