LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-01-2006, 12:15 PM   #1
yawe_frek
Member
 
Registered: Sep 2005
Distribution: feather 0.72-usb, DSL,CentOS,Ubuntu, Redhat 9
Posts: 144

Rep: Reputation: 15
trojans and flooders


I was made to understand that trojans and flooders have ports, where can i get the full list of this trojans and flooders and their ports numders so that i can block them with iptables.

thanks.
 
Old 12-01-2006, 12:20 PM   #2
live_dont_exist
Member
 
Registered: Aug 2004
Location: India
Distribution: Redhat 9.0,FC3,FC5,FC10
Posts: 257

Rep: Reputation: 30
It is not possible to do so. You will grow old blocking all the trojans . There are ports required for software to work but which trojans also use. What would you do then? Its not possssible to block off port 80 ? Sure no work would enter through port 80 but no one would be able to reach your webserver either.

Heres a list of the ports though for a guide:
http://www.iana.org/assignments/port-numbers

However what you should rather be doing is allowing all you want on your firewall/router/blocking device and blocking everything else with a "deny all" rule right at the end.

Cheers
Arvind
 
Old 12-01-2006, 12:27 PM   #3
yawe_frek
Member
 
Registered: Sep 2005
Distribution: feather 0.72-usb, DSL,CentOS,Ubuntu, Redhat 9
Posts: 144

Original Poster
Rep: Reputation: 15
trojans and flooders

I was made to understand that trojans and flooders have ports, where can i get the full list of this trojans and flooders and their ports numders so that i can block them with iptables.

thanks.
 
Old 12-01-2006, 02:20 PM   #4
MensaWater
LQ Guru
 
Registered: May 2005
Location: Atlanta Georgia USA
Distribution: Redhat (RHEL), CentOS, Fedora, CoreOS, Debian, FreeBSD, HP-UX, Solaris, SCO
Posts: 7,831
Blog Entries: 15

Rep: Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669
No such thing as a "full list". Any port that is open is liable for attack. Rather than trying to figure out what to exclude you should figure out what to include. That is to say use iptables to turn off ALL ports then modify it to turn on only those you need. So if you don't have a web application (e.g. Apache) on the box there is no reason to open port 8080 or 443. If you do then you'd open the specific port needed.

Also be sure to turn off unecessary/insecure services. (e.g. telnet - use ssh instead, or ftp - use scp/sftp instead).
 
Old 12-01-2006, 04:37 PM   #5
osor
HCL Maintainer
 
Registered: Jan 2006
Distribution: (H)LFS, Gentoo
Posts: 2,450

Rep: Reputation: 78
Am I going crazy, or are posts 1 and 3 exactly the same?
 
Old 12-01-2006, 04:41 PM   #6
MensaWater
LQ Guru
 
Registered: May 2005
Location: Atlanta Georgia USA
Distribution: Redhat (RHEL), CentOS, Fedora, CoreOS, Debian, FreeBSD, HP-UX, Solaris, SCO
Posts: 7,831
Blog Entries: 15

Rep: Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669
I suspect a moderator merged duplicate postings.

Of course the fact that you are seeing the same post twice doesn't prove you aren't crazy.
 
Old 12-01-2006, 05:07 PM   #7
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Indeed they are, here's the notice to the OP: Please post your thread in only one forum and only once. Posting a single thread in the most relevant forum will make it easier for members to help you and will keep the discussion in one place. These threads have been merged because they are duplicates.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
trojans and viruses bondoq Linux - Networking 4 07-11-2006 05:12 PM
Trojans or backdoors? linuxgamer Linux - Newbie 7 01-04-2004 09:42 PM
Spyware/Trojans/Adware PionexUser Linux - Newbie 9 07-21-2003 04:57 AM
get rid of trojans after being hacked? frasier642 Linux - Security 4 07-06-2003 03:12 PM
Open source, trojans, other thoughts Pres Linux - Security 4 11-03-2002 01:03 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:52 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration