LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-19-2001, 11:07 PM   #1
LanceS
LQ Newbie
 
Registered: Oct 2001
Posts: 1

Rep: Reputation: 0
Has anyone configured PortSentry


I host a few sites for friends and family.

My WebHost has sent a notice that we should expect attacks from you know who.

They have made available PortSentry from Psionic.

My concern at this point is how to configure which IP's to allow.

They have it so that PortSentry runs from a telnet "menu". I took a quick look and enabled it at which point it said something about making sure I allowed my ISP's ip. I thinks thats what it said 'cause I disabled it and started a search on the Net for info on configuring it, That's how I found this Forum.

Well I went back in and the original menu no longer dispalys the "welcome" page and just allows options to restart add and block IP's etc.

So, I hoping by now you get my drift and can offer some help in my determining what IP's need to be enabled. I'm guessing that after I check whose been scanning my server, I should block those addresses.

But who, should I allow. Do I need to explicitly allow all ISP's that my clients dial in from? That doesn't sound right.

TIA - Lance
 
Old 10-22-2001, 02:46 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Its called *Port*sentry for a reason :-]
With Portsentry you can either (un)block ports, or (un)block ranges; you should add all DNSes, connecting mailservers etc to the ignore file anyway, and make sure which mode Portsentry runs to determine if you should add publicly accessable ports to the ignore section of the config or chalk up the ranges. Portsentry seems to accept netmasks, so IIRC, you could get away with specifying like 192.180.0.0/255.255.0.0 type ranges.

*IMO Portsentry should be replaced with Snort.
Snort isnt the same in that it doesnt have blocking capabilities, but is more advanced because it *scans* incoming packets (on all ports) for malicious contents. By comparing it with "signatures" it is able to detect abuse of services by exploits/dos/trojan/whatever else. It also comes with complementary apps that can do the blocking.

Also I would like to make a note on Single Points Of Failure. Any of these apps, including the firewall can be considered that way, because they don't check theirselves for having running state or validity of rules they put out, only if their own config is right at startup. In case of (inadverted|malicious) breakage this would leave the services on your box unprotected and open for public (mis)usage. Run services on separate boxen (eggs in one basket), don't run services(+versions) with known vulnerabilities, make sure your webapps are well-coded and maintained, chroot/jail if necessary.

HTH somehow
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
portsentry skoot Linux - Security 18 11-21-2005 06:29 AM
how to change notification email for portsentry and how to test portsentry roorings Linux - Security 1 11-04-2003 10:36 AM
PortSentry mikesvx1 Linux - Security 5 12-20-2001 01:52 AM
portsentry Jase Linux - Security 1 07-24-2001 07:49 AM
portsentry Dallam Linux - Security 5 07-12-2001 05:42 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:53 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration