LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-26-2004, 10:51 AM   #1
tigerflag
Member
 
Registered: Aug 2002
Location: Phoenix, AZ
Distribution: PCLinuxOS 2012.08
Posts: 430

Rep: Reputation: 30
Guarddog leaves Cups port 631 open, how do I close it?


I installed Mepis Linux on a friend's computer the other day. It's Debian-based. It came with Guarddog which I configured. She's on a stand-alone computer using a cable broadband connection. No servers, she just needs a connection to the internet for surfing, receiving mail and minor downloading. She's using Cups for her local parallel port printer.

I blocked the IPP protocol in Guarddog but it still leaves the IPP port 631 open, according to the GRC ShieldsUP scan. She doesn't need remote Cups access. I don't want to disable Cups because she needs it to print. What can we do?

This is her first experience with Linux. She lives in a different city and anything you suggest, I'm going to have to talk her through it over the phone, so I hope the solution is simple. I feel really bad leaving her computer vulnerable like this. She asked me for Linux and I just didn't have much time to tweak it after installing.

Thanks!
Siri Amrit
 
Old 08-28-2004, 05:59 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Configure cupsd to run on localhost (grep Listen cupsd.conf). If paranoid (and why not?) additionally configure Iptables to only accept traffic for the IPP port from localhost. I don't know if Cups is compatible with libwrap, if it is, then you could additionally configure /etc/hosts.allow (you *did* "echo ALL: ALL > /etc/hosts.deny" anyway, right?).
 
Old 08-28-2004, 09:34 AM   #3
tigerflag
Member
 
Registered: Aug 2002
Location: Phoenix, AZ
Distribution: PCLinuxOS 2012.08
Posts: 430

Original Poster
Rep: Reputation: 30
Thanks, unSpawn. Get ready to flame me.

>Configure cupsd to run on localhost (grep Listen cupsd.conf)

What will that command show or do? I tried the command here and don't have that file on my system. She's in New Mexico and has no experience with Linux, commandline or Vi. I'm in Arizona using Slackware, not Debian-based Mepis. I have to walk her through things over the phone and that's hard if I can't see what she sees. Is there a way she could open and edit the Cups file using Kwrite? Perhaps she could send me the file and I could see how to change it to make it run on localhost? I don't even know where the Cups file would be...

I can't configure her IPtables, and doubt if she can, either. I wouldn't know how even if I was there.

>you *did* "echo ALL: ALL > /etc/hosts.deny" anyway, right?

No, I didn't. I don't even know what that means or does. Can you please elucidate?

Thanks!
Siri Amrit
 
Old 08-28-2004, 05:49 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Getting the file from her would be good, unless some userfriendly tool (re)configured it for her. Wanna get prepared: D/L Debian's Cups package, unpack and peruse the contents. Conf should live around /etc/cups/ or so, the line by default being commented out, reads something like "# Listen 631". Make it read "Listen 127.0.0.1:631", send file, make her restart Cups.

Same drill for the firewall I guess, but let's do one thing at a time.
 
Old 08-29-2004, 12:28 PM   #5
tigerflag
Member
 
Registered: Aug 2002
Location: Phoenix, AZ
Distribution: PCLinuxOS 2012.08
Posts: 430

Original Poster
Rep: Reputation: 30
Thank you!

Siri Amrit
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
CUPS http://localhost:631/ LUB997 Linux - Software 1 09-26-2005 07:52 PM
nmap reports port 21 (ftp) open - how to close it? shazam75 Linux - Security 3 09-23-2005 07:13 PM
Can I just leave port 80 open, close everthing else? Andknig Linux - Security 1 05-05-2005 03:59 PM
does CUPS need internet and open TCP port? servnov Linux - Newbie 1 11-14-2004 11:45 AM
open and close network port abd_bela Linux - Security 5 08-19-2004 03:40 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:39 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration