LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-06-2008, 11:22 PM   #1
nkutty
Member
 
Registered: Aug 2005
Posts: 34

Rep: Reputation: 15
Smile Block all download software


Hi..

i am using REHEL4 with squid proxy for internet sharing

and also potables firewall i wan to block all the downloading software

like flash get, web zip, get right, web ripper using this all are missing

using the internet how to Block downloading through software

please help ME dears


With regards
Kutty N
 
Old 10-07-2008, 05:20 AM   #2
htnakirs
Member
 
Registered: Mar 2007
Posts: 239

Rep: Reputation: 34
It will be hard to find and block all downloading apps. If your concern is high data transfer, it is much easier to setup quotas for each user. I think. This will automatically prevent large downloads from being saved.
 
Old 10-07-2008, 10:58 PM   #3
nkutty
Member
 
Registered: Aug 2005
Posts: 34

Original Poster
Rep: Reputation: 15
How to fine port

Other way is how to fine port for these downloadmnagers
 
Old 10-07-2008, 11:06 PM   #4
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Maybe you could use the browser ACL to allow access only for your browser's User-Agent string(s).

That is, assuming the download managers don't do any User-Agent spoofing.

Last edited by win32sux; 10-07-2008 at 11:07 PM.
 
Old 10-07-2008, 11:17 PM   #5
nkutty
Member
 
Registered: Aug 2005
Posts: 34

Original Poster
Rep: Reputation: 15
Smile Find port

hi..

if we are able to find listen port number for these flash get, web zip, web ripper, free download manger we can drop these port through iptables

can say the port numbers or tell me how find the ports
 
Old 10-07-2008, 11:19 PM   #6
billymayday
LQ Guru
 
Registered: Mar 2006
Location: Sydney, Australia
Distribution: Fedora, CentOS, OpenSuse, Slack, Gentoo, Debian, Arch, PCBSD
Posts: 6,678

Rep: Reputation: 122Reputation: 122
Set up wireshark on the server and fire the products up and see what ports they use.
 
Old 10-07-2008, 11:24 PM   #7
nkutty
Member
 
Registered: Aug 2005
Posts: 34

Original Poster
Rep: Reputation: 15
port

i am not clear what Your saying.. this there any way through Net to fine
 
Old 10-07-2008, 11:39 PM   #8
billymayday
LQ Guru
 
Registered: Mar 2006
Location: Sydney, Australia
Distribution: Fedora, CentOS, OpenSuse, Slack, Gentoo, Debian, Arch, PCBSD
Posts: 6,678

Rep: Reputation: 122Reputation: 122
Wireshark lets you look at packets that pass through an ethernet port. You can see what the source and destination ports are, protocol, IPs etc. Set it up (it should be in one of the RH repos) and start the various applications you are concerned about on a computer attached to the server. You'll soon see ewhat ports the applications are requesting.

I fact, you could just install wireshark on a client and watch there. There are Windows and Linux versions.
 
Old 10-08-2008, 04:15 PM   #9
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
The destination ports would be useless, as they will be the same ports anything else uses. You won't be able to differentiate between program Foo and program Bar by using destination ports. You could use source ports, but who's to say the programs limit themselves to a specific range which doesn't overlap with what your browser (for example) uses? This kind of stuff is simply not something iptables is a good choice for half the time.

Last edited by win32sux; 10-08-2008 at 04:24 PM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Block any download type of file in squid....... farrukhndm Linux - Server 0 09-02-2008 06:29 AM
block *.* file download using squid soumalya Linux - Security 6 12-21-2006 02:51 AM
how to block software downloading through sqiud rameshk_tvm Linux - Software 1 11-12-2006 01:50 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:18 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration