LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-06-2006, 11:08 PM   #1
unixguru
LQ Newbie
 
Registered: May 2006
Posts: 2

Rep: Reputation: 0
first 1024 ports blocked for normal user


I am using archlinux and i am unable to use azureus because the first 1024 ports are blocked for normal user. My isp blocks all other ports except a few in the first 1024(20,21,22,81 etc) so i can't use any other port. i installed firestarter and unblocked port 81 but no effect for non-root user. i get permisson denied when i do the firewall test but everything works fine as root. also when i test another port beyond 1024 i get the nat error and not the permission denied error. A firewall test(shields up) shows that every port except 81 is stealthed as it should be. I have no idea what's wrong.
 
Old 05-07-2006, 02:13 AM   #2
btmiller
Senior Member
 
Registered: May 2004
Location: In the DC 'burbs
Distribution: Arch, Scientific Linux, Debian, Ubuntu
Posts: 4,290

Rep: Reputation: 378Reputation: 378Reputation: 378Reputation: 378
The first 1024 ports on any *nix system are considered privileged and only the superuser can bind to them. I thought that there was a sysctl somewhere that could change this, but grepping around I don't see it right off. However, this article gives some other ideas to work around this which you might be interested in. Using iptables to redirect incoming port 81 to some other port looks like a good solution. I would not run azureus as root through sudo, unless there's some way it can be made to drop privileges after it has bound to the port.
 
Old 05-07-2006, 02:28 AM   #3
jschiwal
LQ Guru
 
Registered: Aug 2001
Location: Fargo, ND
Distribution: SuSE AMD64
Posts: 15,733

Rep: Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682Reputation: 682
If you use a NAT router, you may be able to translate the port in the routers setup. It may be referred to in the router setup as port triggering.
 
Old 05-07-2006, 06:45 AM   #4
unixguru
LQ Newbie
 
Registered: May 2006
Posts: 2

Original Poster
Rep: Reputation: 0
I just figured that port 5000 and 6000 are opened by my isp, so i am using those.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how to tell what ports are being blocked? metallica1973 Linux - Security 2 12-18-2005 07:19 PM
Ports Blocked spaceballs Slackware 4 05-02-2005 09:42 PM
giving a user the ability to use ports below 1024 surreal Linux - Networking 2 12-17-2003 01:55 PM
getting by blocked ports niehls Linux - Networking 1 07-06-2003 03:00 PM
Ports below 1024 peo66 Linux - Networking 4 06-14-2003 05:04 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:42 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration