LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-18-2006, 02:05 PM   #1
hansmast
LQ Newbie
 
Registered: Jan 2006
Posts: 11

Rep: Reputation: 0
Firestarter


I have Firestarter installed on FC4 with a very simple ruleset: block everything but 80, 22, and 10000 (HTTP, SSH, and Webmin). However, when I do an nmap scan of my server, I get this:

Code:
G:\Apps\nmap>nmap -v 209.31.xxx.xxx

Starting Nmap 4.01 ( http://www.insecure.org/nmap ) at 2006-02-18 14:48 Eastern
Standard Time
DNS resolution of 1 IPs took 0.02s. Mode: Async [#: 1, OK: 1, NX: 0, DR: 0, SF:
0, TR: 1, CN: 0]
Initiating SYN Stealth Scan against engineer.xxxx.org.xxx.31.209.in-addr.arpa (2
09.31.146.79) [1672 ports] at 14:48
Discovered open port 554/tcp on 209.31.xxx.xxx
Discovered open port 22/tcp on 209.31.xxx.xxx
Discovered open port 1723/tcp on 209.31.xxx.xxx
Discovered open port 80/tcp on 209.31.xxx.xxx
Discovered open port 21/tcp on 209.31.xxx.xxx
Discovered open port 10000/tcp on 209.31.xxx.xxx
SYN Stealth Scan Timing: About 7.94% done; ETC: 14:54 (0:05:49 remaining)
Discovered open port 6666/tcp on 209.31.xxx.xxx
Discovered open port 6667/tcp on 209.31.xxx.xxx
Discovered open port 1720/tcp on 209.31.xxx.xxx
Discovered open port 6668/tcp on 209.31.xxx.xxx
SYN Stealth Scan Timing: About 47.26% done; ETC: 14:51 (0:01:44 remaining)
Discovered open port 7070/tcp on 209.31.xxx.xxx
Discovered open port 2000/tcp on 209.31.xxx.xxx
Discovered open port 1755/tcp on 209.31.xxx.xxx
The SYN Stealth Scan took 151.36s to scan 1672 total ports.
Host engineer.xxxx.org.xxx.31.209.in-addr.arpa (209.31.xxx.xxx) appears to be up
... good.
Interesting ports on engineer.xxxx.org.xxx.31.209.in-addr.arpa (209.31.xxx.xxx):
(The 1659 ports scanned but not shown below are in state: filtered)
PORT      STATE SERVICE
21/tcp    open  ftp
22/tcp    open  ssh
80/tcp    open  http
554/tcp   open  rtsp
1720/tcp  open  H.323/Q.931
1723/tcp  open  pptp
1755/tcp  open  wms
2000/tcp  open  callbook
6666/tcp  open  irc-serv
6667/tcp  open  irc
6668/tcp  open  irc
7070/tcp  open  realserver
10000/tcp open  snet-sensor-mgmt

Nmap finished: 1 IP address (1 host up) scanned in 152.109 seconds
               Raw packets sent: 6687 (294KB) | Rcvd: 134 (6524B)

G:\Apps\nmap>
What's up?

Last edited by hansmast; 02-18-2006 at 02:08 PM.
 
Old 02-18-2006, 02:42 PM   #2
quintessence
LQ Newbie
 
Registered: Feb 2006
Location: Bulgaria
Distribution: Slackware-Current
Posts: 4

Rep: Reputation: 0
does u nmap urself from ur machine ?!ask some ur friend to nmap u .. ports may be opened,but stealthed ..
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Anyone use Firestarter? aquaboot Linux - Security 4 08-30-2005 08:53 AM
FIreStarter webwolf70 Linux - Security 2 06-01-2005 02:05 PM
Firestarter help gazza Linux - Software 1 07-11-2004 06:51 AM
firestarter ? BajaNick Linux - Software 6 08-04-2003 09:56 PM
Firestarter Nexer Linux - Security 4 05-18-2003 10:37 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration