LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 02-11-2003, 02:28 PM   #1
ghight
Member
 
Registered: Jan 2003
Location: Indiana
Distribution: Centos, RedHat Enterprise, Slackware
Posts: 524

Rep: Reputation: 30
Removing PortSentry address blocking


I just installed PortSentry on a test server and then tried to attack it from another workstation. PortSentry performed well and blocked all the scans there-after by adding a line the portsentry.blocked file and adding an iptables rule. (I'm using the standard PortSentry conf file.)

I'm not running iptables on this server so I know that had no effect, but I've tried to remove the entry in the portsentry.blocked file and it still won't allow me access to the server again from my workstation. I restarted portsentry afterwards and it still didn't reallow access. Only restarting the entire server would allow me to work from the attacking workstation again. What do I need to do to reallow access in the future without restarting the entire server?

I've read plenty about PortSentry, but nothing on how to remove accidental IP blocks .

Thanks in advance,
 
Old 02-11-2003, 03:54 PM   #2
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
I hope you won't bite me for this, but...

did you restart iptables after removing the rule? This will make it flush the rules and reread them

service iptables restart

You can always do
iptables -nL --line-numbers
to get a list of current rules to make sure they are no longer being used.
If they are, you can delete the respective line with
iptables -D INPUT 3
for example
 
Old 02-11-2003, 04:05 PM   #3
ghight
Member
 
Registered: Jan 2003
Location: Indiana
Distribution: Centos, RedHat Enterprise, Slackware
Posts: 524

Original Poster
Rep: Reputation: 30
I'm pretty sure I have a good grip on that biting thing.

I didn't think to restart because I knew I didn't have iptables running. As a check I did try to flush the new rule, but as expected, it just threw an errer about iptables not running.

The iptables rule is just part of the sample portsentry.conf file that I just didn't remove.

Do you have portsentry experience?
 
Old 02-12-2003, 01:26 AM   #4
m0rl0ck
Member
 
Registered: Nov 2002
Distribution: A totally 133t distro :)
Posts: 358

Rep: Reputation: 31
If it isnt iptables its either hosts.deny or the port sentry blocked file thats the problem.

Check hosts.deny for the address and then restart portsentry after adding the address ranges you want to allow to your portsentry.ignore file.
 
Old 02-12-2003, 06:55 AM   #5
ghight
Member
 
Registered: Jan 2003
Location: Indiana
Distribution: Centos, RedHat Enterprise, Slackware
Posts: 524

Original Poster
Rep: Reputation: 30
I went through hosts.deny, the portsentry blocking file, and tried to flush the iptables rules and the portsentry file was the only one that had been changed so I know the only thing that was blocking the address was portsentry. I did delete the entry and tried to restart but no luck. Still blocked.
 
Old 02-12-2003, 04:03 PM   #6
EventLevel
LQ Newbie
 
Registered: Feb 2003
Location: Georgia, USA
Distribution: RedHat 7.3, 8.0
Posts: 2

Rep: Reputation: 0
Take a look at your routing table. PortSentry can also add a bogus route to misdirect the offending address.

You can also look in (at least on RedHat) in /usr/local/psionic/portsentry at your blocked files, ignore files and history file.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
blocking a address in sendmail roopunix Linux - Networking 1 08-25-2005 03:51 AM
portsentry replacement? (automated ip address based host blocking) hlslaughter Linux - Security 1 08-08-2005 07:45 PM
blocking mac address and NAT com90185 Linux - Security 6 03-07-2005 06:37 PM
how to change notification email for portsentry and how to test portsentry roorings Linux - Security 1 11-04-2003 10:36 AM
blocking connection through MAC address shahriars Linux - Security 7 06-02-2003 01:45 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 04:57 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration