LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-08-2007, 06:56 PM   #16
GeneralDark
Member
 
Registered: Nov 2007
Location: Sweden
Distribution: Gentoo 2007
Posts: 32

Original Poster
Rep: Reputation: 15

Can it be something else, now my log is filled with:
(MAC with zz= the hardware router thats connected to the WAN interface on the gentoobox)
The other MAC I have no clue I'm afraid. Checked all the MACs I could think of.
Code:
Nov  8 22:21:12 firewall INPUT DROP: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:yy:yy:yy:yy:yy:yy:yy:yy SRC=192.168.0.2 DST=192.168.0.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=22439 PROTO=UDP SPT=137 DPT=137 LEN=58
Nov  8 22:21:12 firewall INPUT DROP: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:yy:yy:yy:yy:yy:yy:yy:yy SRC=192.168.0.2 DST=192.168.0.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=23183 PROTO=UDP SPT=137 DPT=137 LEN=58
Nov  8 22:21:13 firewall INPUT DROP: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:yy:yy:yy:yy:yy:yy:yy:yy SRC=192.168.0.2 DST=192.168.0.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=23896 PROTO=UDP SPT=137 DPT=137 LEN=58
Nov  8 22:21:16 firewall INPUT DROP: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:yy:yy:yy:yy:yy:yy:yy:yy SRC=192.168.0.2 DST=192.168.0.255 LEN=202 TOS=0x00 PREC=0x00 TTL=128 ID=26576 PROTO=UDP SPT=138 DPT=138 LEN=182
Nov  8 22:21:16 firewall INPUT DROP: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:yy:yy:yy:yy:yy:yy:yy:yy SRC=192.168.0.2 DST=192.168.0.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=26577 PROTO=UDP SPT=137 DPT=137 LEN=58
Nov  8 22:21:17 firewall INPUT DROP: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:yy:yy:yy:yy:yy:yy:yy:yy SRC=192.168.0.2 DST=192.168.0.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=27280 PROTO=UDP SPT=137 DPT=137 LEN=58
Nov  8 22:21:17 firewall INPUT DROP: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:yy:yy:yy:yy:yy:yy:yy:yy SRC=192.168.0.2 DST=192.168.0.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=28049 PROTO=UDP SPT=137 DPT=137 LEN=58
Nov  8 22:21:18 firewall INPUT DROP: IN=eth1 OUT= MAC=01:00:5e:00:00:01:zz:zz:zz:zz:zz:zz:08:00 SRC=192.168.0.1 DST=224.0.0.1 LEN=28 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=2
Nov  8 22:21:20 firewall INPUT DROP: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:yy:yy:yy:yy:yy:yy:yy:yy SRC=192.168.0.2 DST=192.168.0.255 LEN=202 TOS=0x00 PREC=0x00 TTL=128 ID=30893 PROTO=UDP SPT=138 DPT=138 LEN=182
Nov  8 22:21:20 firewall INPUT DROP: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:yy:yy:yy:yy:yy:yy:yy:yy SRC=192.168.0.2 DST=192.168.0.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=30894 PROTO=UDP SPT=137 DPT=137 LEN=58
Nov  8 22:21:21 firewall INPUT DROP: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:yy:yy:yy:yy:yy:yy:yy:yy SRC=192.168.0.2 DST=192.168.0.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=31679 PROTO=UDP SPT=137 DPT=137 LEN=58
Nov  8 22:21:22 firewall INPUT DROP: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:yy:yy:yy:yy:yy:yy:yy:yy SRC=192.168.0.2 DST=192.168.0.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=32459 PROTO=UDP SPT=137 DPT=137 LEN=58
Nov  8 22:21:24 firewall INPUT DROP: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:yy:yy:yy:yy:yy:yy:yy:yy SRC=192.168.0.2 DST=192.168.0.255 LEN=211 TOS=0x00 PREC=0x00 TTL=128 ID=35145 PROTO=UDP SPT=138 DPT=138 LEN=191
Nov  8 22:23:24 firewall INPUT DROP: IN=eth1 OUT= MAC=01:00:5e:00:00:01:zz:zz:zz:zz:zz:zz:08:00 SRC=192.168.0.1 DST=224.0.0.1 LEN=28 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=2
Nov  8 22:25:31 firewall INPUT DROP: IN=eth1 OUT= MAC=01:00:5e:00:00:01:zz:zz:zz:zz:zz:zz:08:00 SRC=192.168.0.1 DST=224.0.0.1 LEN=28 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=2
Nov  8 22:27:37 firewall INPUT DROP: IN=eth1 OUT= MAC=01:00:5e:00:00:01:zz:zz:zz:zz:zz:zz:08:00 SRC=192.168.0.1 DST=224.0.0.1 LEN=28 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=2
Nov  8 22:28:07 firewall INPUT DROP: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:zz:zz:zz:zz:zz:zz:08:00 SRC=192.168.0.1 DST=255.255.255.255 LEN=576 TOS=0x00 PREC=0x00 TTL=64 ID=0 PROTO=UDP SPT=67 DPT=68 LEN=556
Nov  8 22:29:14 firewall INPUT DROP: IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:zz:zz:zz:zz:zz:zz:08:00 SRC=192.168.0.1 DST=255.255.255.255 LEN=576 TOS=0x00 PREC=0x00 TTL=64 ID=0 PROTO=UDP SPT=67 DPT=68 LEN=556
Nov  8 22:29:44 firewall INPUT DROP: IN=eth1 OUT= MAC=01:00:5e:00:00:01:zz:zz:zz:zz:zz:zz:08:00 SRC=192.168.0.1 DST=224.0.0.1 LEN=28 TOS=0x00 PREC=0x00 TTL=1 ID=0 DF PROTO=2
That happend after I unplugged the cable to my workstation in eth0 on gentoobox.
This is the last entries of the log however. So it stopped doing, whatever its doing, to now (01.55 AM). How come? What packets is this?
Atleast it tries to connect on the right interface, but it still isnt working. Port 138 UDP is netbios, but since I dont have a samba server I cant see why its trying to use the netbios service.
I know it getting boring, sry for that.
Thanks for the help so far
And thanks in advanced for the (hopefully) incoming answers

Last edited by GeneralDark; 11-08-2007 at 07:10 PM.
 
Old 12-01-2007, 01:54 PM   #17
nowshining
Member
 
Registered: Dec 2007
Distribution: Ibex
Posts: 93

Rep: Reputation: 15
have u tried out arno-iptables-firewall it blocks all inbound and to configure it u use/etc/arno-iptables-firewall/firewall.conf

easy to read and understand and there is a place in ther to block outbound ports if u can find, u can intsert ur own firewall fules in custom-rules - same folder to restart the firewall open up a terminal type

sudo /etc/init.d/arno-iptables-firewall restart



http://rocky.eld.leidenuniv.nl/

http://rocky.eld.leidenuniv.nl/iptables-firewall/

Last edited by nowshining; 12-01-2007 at 01:55 PM.
 
Old 12-03-2007, 03:17 PM   #18
GeneralDark
Member
 
Registered: Nov 2007
Location: Sweden
Distribution: Gentoo 2007
Posts: 32

Original Poster
Rep: Reputation: 15
Thx alot
By skipping the "blocking almost all outgoig trafic" rules it was much easier
Thx for the arno script! Working like a charm
 
Old 12-04-2007, 04:36 PM   #19
nowshining
Member
 
Registered: Dec 2007
Distribution: Ibex
Posts: 93

Rep: Reputation: 15
ur welcome
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
blocking an IP using iptables picox Linux - Security 7 12-10-2010 02:00 PM
Blocking an IP with iptables asif2k Linux - Security 4 04-18-2006 11:22 PM
iptables blocking traffic JJX Linux - Networking 4 11-07-2005 05:36 AM
Blocking squid through iptables jomy Linux - Networking 1 12-20-2004 09:24 AM
Iptables blocking certain websites?? Ikik Linux - Security 3 09-29-2003 02:39 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:05 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration