LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 11-24-2003, 07:40 AM   #1
mudelf
Member
 
Registered: Sep 2003
Distribution: RedHat 8
Posts: 59

Rep: Reputation: 15
Firestarter Non Root Access Trouble


I setup Firestarter on my Debian Woody box and got it configured and running (very nice program).

It runs fine as root but when (following good practice) I try to dial up from a non root account I find that its blocking me from doing normal web access. When I try to load it (as su) it will not start claiming that it is missing libraries (probably a path issue perhaps).

Has anyone else had this trouble?


 
Old 11-24-2003, 05:25 PM   #2
RolledOat
Member
 
Registered: Feb 2003
Location: San Antonio
Distribution: Suse 9.0 Professional
Posts: 843

Rep: Reputation: 30
Hmmm, well, did you
su - root
or just
su

the - is needed to load roots env.

When you configured it, did you select 'start firewall on dialout'?

R.O.
 
Old 11-25-2003, 01:43 AM   #3
mudelf
Member
 
Registered: Sep 2003
Distribution: RedHat 8
Posts: 59

Original Poster
Rep: Reputation: 15
<looks sheepish ....>


errr no ...

Will try tonight though! Had no idea that passing that extra parameter gave root its ENV's and this clears up several other similar issues too.

Thanks a lot!

Regarding the Firestarter configuration - No it does not start automatically on dial up but has to be turned on. I have also found that I cannot even do a ping and basically am limited to being root for ANY kind of internet net access.

My route table and /etc/Resolv.conf file when not root are exactly the same as they are for root so I am pretty certain it has to be a firewall issue but I am not sure.

Any ideas ?


Thanks Again
 
Old 11-25-2003, 09:27 AM   #4
RolledOat
Member
 
Registered: Feb 2003
Location: San Antonio
Distribution: Suse 9.0 Professional
Posts: 843

Rep: Reputation: 30
Well, using kppp as non root
http://wave.prohosting.com/hlrguy/Redhat8.0/kppp.html

In my firestarter setup, I selected 'start the firewall on dialout', which allows regular users to surf, based on the rules. Without this option, nothing, is coming in our out because, the way firestarter works, until it is running (at dialout or when you start it, everything is blocked). A regular user can't start the GUI though. I have a desktop icon that has
su - root -c firestarter
in it, set it up to open in terminal and it prompt for password when I want to see the hits, or change the firewall rules.

R.O.
 
Old 11-25-2003, 09:33 AM   #5
mudelf
Member
 
Registered: Sep 2003
Distribution: RedHat 8
Posts: 59

Original Poster
Rep: Reputation: 15
Brilliant - this 'sounds' exactly like the trouble I am having. I suspected that a default blocking of everything was happening but I did not figure that everything is blanked without Firestarter running and that starting it is was enables traffic to move, but subject to iptable rules.

Will try all of your suggestions tonight after work - Thanks for your help!
 
Old 11-25-2003, 10:05 AM   #6
RolledOat
Member
 
Registered: Feb 2003
Location: San Antonio
Distribution: Suse 9.0 Professional
Posts: 843

Rep: Reputation: 30
FYI, if you open a console and enter
tail -f /var/log/messages
(even as regular user),
you can see all the firewall hits. This is the information I have sent to ISPs when I detect a concerted attempt to scan my machine (i.e. hitting all ports many times/second in a systematic way). Hope it all comes together.

R.O.
 
Old 11-27-2003, 02:39 AM   #7
mudelf
Member
 
Registered: Sep 2003
Distribution: RedHat 8
Posts: 59

Original Poster
Rep: Reputation: 15
Hmmmm - Still having a few problems -

I very clearly set Firestarter to start on Dial Out and close when shut down - The only problem is that it just does not (I check in top and with 'ps') but it only seems to run when specifically started.

Also I also seem to have to enable WWW as a service if I am to be able to resolve anything.

I reckon its also calling some NFS problems too but im not sure about this yet --- scouring google at the moment.
 
Old 12-03-2003, 06:15 AM   #8
littlepeon
LQ Newbie
 
Registered: Oct 2003
Posts: 9

Rep: Reputation: 0
hey there....
am looking for a better solution myself....thus i found your post...
depending on how you installed/configured firestarter for your system, it can still be running in the background on your system thru the use of ipchains(iptables) just the gui interface isnt running (ie. i use debian...firestarter is started in the background during a startup runlevel)

if you goto their site, they have a mailing list fourm w/an archive....in this they touch on the problem of starting the gui--there is no 'clear' soulution...

esentially you have to be root to start the gui....most dialers(kpp,etc) allow you to start scripts upon completion of the ppp process, however the script is run w/your user privileges...thus the problem

the author is working a solution, but it is difficult to fix and not create a root exploit.....

one solution is to add yourself to a sudo group....

personally, i just start the firewall gui......connect to the net via kpp then start the firewall within 3 secs of ppp completion....this works best for me.....

if you are having a pinging/dns problem when using firewall-this is due to the not connected ppp situation: if you have the firewall running while NOT connected to the internet via ppp, then you connect via ppp, you will have to EITHER: put your nameservers ip address into the trusted hosts list or IF ITS ALREADY THEIR before you connected, take it out of the trusted host list---yes i know this is screwy but its how it works if firestarted is already running when ppp connects...

hope this helps
-Peon
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
firestarter must use root Hectic Linux - Software 2 10-17-2004 05:06 AM
access point trouble d4nr General 2 07-30-2004 04:14 PM
writing a script running firestarter automatically with kppp without root priviliges melquiades Linux - Newbie 3 08-11-2003 06:50 AM
No web access, in trouble, please help!! WorldBuilder Linux - Networking 12 04-12-2003 11:49 AM
Help with user access behind Firestarter firewall TigerOC Linux - Networking 0 02-16-2003 08:05 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:49 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration