LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-15-2002, 11:47 AM   #1
bluehz
LQ Newbie
 
Registered: Jul 2002
Posts: 12

Rep: Reputation: 0
gShield - default drop ????


I have a new install of Slackware 8.1 and I decided with this new install I would try using gShield as my firewall. The Linux box sits inside a LAN that runs off a single cable connection through a Linksys router. I have opened up most service ports to the Linux box as I use that for a DNS caching server, mail, server, etc. I have noticed that my syslog is indicating a lot of activity in the firewall. I just wanted to make sure this is safe. I assue the "default drop" listed below means the access was denied to the Incoming IP. Is this correct? Note the Linux box LAN IP is 192.168.1.130 as listed below.

Jul 14 13:30:14 linux kernel: gShield (default drop) IN=eth0 OUT= MAC=<deleted for privacy> SRC=167.181.31.35 DST=192.168.1.130 LEN=40 TOS=0x00 PREC=0x00 TTL=46 ID=65155 PROTO=TCP SPT=443 DPT=49200 WINDOW=0 RES=0x00 ACK RST URGP=0
 
Old 07-16-2002, 06:07 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Guess you're right, haven't looked at Gshield too close but I guess grepping its (output?) script for the policies (-P) should tell what it's default policies are.

*Btw, MAC addresses are unique, but don't carry beyond the LAN, so stripping 'em ain't really necessary. Stripping non-LAN IP addresses is good if you wanna.
 
Old 07-16-2002, 07:11 PM   #3
mikek147
Member
 
Registered: Mar 2002
Location: Elyria, Ohio
Distribution: Debian, Nothing else required
Posts: 141

Rep: Reputation: 15
Obviously, how gShield handles intruders depends on how you've setup /etc/firewall/gShield.conf. But in this case, 167.181.31.35's inquiry was dropped with no response from your box going back to him. If you need to look at iptables rules, as set by gShield, do iptables -L. -mk
 
Old 07-16-2002, 11:18 PM   #4
bluehz
LQ Newbie
 
Registered: Jul 2002
Posts: 12

Original Poster
Rep: Reputation: 0
I just wanted to know whether people are getting in or not,

I am a bit worried (aka paranoid) as I compiled and ran the Saint intrusion detection system and it indicated - specifically the "Evidence of penetration:

* Fresh install of Slackware 8.1
* gShield firewall - basically default setting
* qmail mail server
* cable connection behind Linksys router

Evidence of Penetration

* linux.macvoodoo.lan: Possible Trinity portshell detected
* linux.macvoodoo.lan: Possible mstream handler detected
* linux.macvoodoo.lan: Possible shaft handler detected
* linux.macvoodoo.lan: Possible stacheldraht handler detected

BROWNPossible Vulnerabilities

* linux.macvoodoo.lan: Is your Kerberos secure? (CVE 2000-0389 2000-0390 2000-0391)
* linux.macvoodoo.lan: possible vulnerability in Linux lpd

BROWNLimit Internet Access ?

* linux.macvoodoo.lan: rlogin is enabled
* linux.macvoodoo.lan: pop receives password in clear
* linux.macvoodoo.lan: rexec is enabled and could help attacker

Should I be worried are these erroneous readings?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Drop connections to port 80 at firewall machine also drop at protected network? Niceman2005 Linux - Security 2 10-27-2005 08:21 AM
iptables - drop all -> allow needed OR allow all -> drop specific lucastic Linux - Security 5 12-21-2004 02:07 AM
how to drop all packets to one host with the default rule of accept dan5009 Linux - Security 1 08-20-2003 05:55 PM
gShield and VPN kleanthis Linux - Security 2 05-17-2002 07:10 PM
gShield question natto34 Linux - Newbie 1 04-07-2002 01:06 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:26 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration