LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-26-2004, 12:38 PM   #1
Nic-MDKman
Member
 
Registered: Feb 2004
Location: Sacramento, CA, USA
Distribution: Mandrake 9.2
Posts: 159

Rep: Reputation: 30
weird server issue


I have a server set up on a Mandrake 9.2 system with the secure kernel. Whenever anyone tries to access services such as ssh, or pop, they get a connection refused, and in my syslog I get a line that says something like "connection to (service) blocked by tcpwrappers" or something like that, I cant recall the exact wording.

I think that this is something with the hosts.allow and hosts.deny, which I tried messing with. I tried adding ALL : ALL : ALLOW to the hosts.allow, but surprisingly that didnt make a difference, however, when I removed the line that says ALL : ALL except 127.0.0.1 : DENY from the hosts.deny, anyone can connect to the services. From what I read, I was under the impression that hosts.allow supercedes the hosts.deny, so adding the ALLOW line in hosts.allow should have basically eliminated what the hosts.deny file was showing. Now, I would just edit the hosts.deny, but I dont know exactly what to put, and even if I did, Mandrake seems to reset that file every 15 minutes or so.

I tried editing the access stuff in the webmin module xinetd, which now says to allow all for the services I have running, but that doesnt seem to help either. I have also installed a firewall and allowed access to the ports for the services to see if that would make a difference, it did not. The only services that people are able to connect to are HTTP, FTP, and webmin on port 10000

How do I fix this?
 
Old 04-26-2004, 04:46 PM   #2
Nic-MDKman
Member
 
Registered: Feb 2004
Location: Sacramento, CA, USA
Distribution: Mandrake 9.2
Posts: 159

Original Poster
Rep: Reputation: 30
Ok, I fixed the problem. I am not sure why the system wasnt reading what I was entering in the hosts.allow, but it is reading it now. The steps I took were, one, adding a firewall, and two, manually stopping xinetd and restarting it.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Weird Modules Issue mattp Linux - Software 1 11-30-2005 06:46 PM
Weird Gaim Issue...Please Help! br00tal Linux - Software 10 09-13-2005 05:40 PM
a weird issue about which jiawj Red Hat 2 04-26-2005 09:06 AM
VSFTP having a weird issue bad_lemming Linux - Newbie 2 10-04-2004 08:58 AM
Weird NVIDIA Issue cmckay Linux - Hardware 2 04-03-2003 07:38 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:24 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration