LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-07-2006, 09:08 AM   #1
delta_9
Member
 
Registered: Feb 2006
Location: Athens
Distribution: opensuse 11/kubuntu 8.04
Posts: 99

Rep: Reputation: 15
How does firewall protect me


Ok, i have suse 10,with built in firewall.I installed amule.Before opening tcp,UDP ports in firewall amule could work,but not very well.I could download,upload anything,in a low speed though.So my questions is how does it protect me ,since programmes(or an intruder) have acces to network(or my system) even if this acces is poor?
 
Old 03-07-2006, 09:34 AM   #2
J_K9
Member
 
Registered: Nov 2004
Distribution: Slackware 11, Ubuntu 6.06 LTS
Posts: 700

Rep: Reputation: 30
It is probably slower because the firewall is filtering the packets as they pass, and (I'm not too familiar with amule) the filtering process could be slowing it down.

I'm guessing that the only thing someone else on amule could do is view the files you have downloaded and are allowing for upload, correct? They do not have access to all your other files. Then, unless there is a bug in amule, you should be safe. Your firewall is filtering the ports used by amule (or so it seems from the information you've given), so any odd activity *should* be spotted by the firewall.

How does the firewall protect you? Simple. It is filtering all the other ports other than the amule ones to protect you. Sure, an attacker might go for your amule port which may be slightly vulnerable - but unless you were running an unpatched version of amule with known vulnerabilities then they would have quite a lot of trouble getting in. You mention you are in a network - does your router have an inbuilt SPI firewall?

My guess is that you are more secure than you think - but I've never used amule in my life, so I can't help you there.

Cheers,

-jk
 
Old 03-10-2006, 08:53 AM   #3
delta_9
Member
 
Registered: Feb 2006
Location: Athens
Distribution: opensuse 11/kubuntu 8.04
Posts: 99

Original Poster
Rep: Reputation: 15
My questions was not for amule only.I just gave it as an exmple,to ask if a firewall protects me even if programmes(any programmes),which are not "allowed to reach network" can reach network but poorly
 
Old 03-10-2006, 10:35 AM   #4
jomen
Senior Member
 
Registered: May 2004
Location: Leipzig/Germany
Distribution: Arch
Posts: 1,687

Rep: Reputation: 55
If you block or drop certain types of packages - or you take them, then log them, then drop them...these packages will not go through - anything else will. There is no in between - like you suggested that they will still go through, but poorly.
Eighter yes or no.
 
Old 03-10-2006, 01:13 PM   #5
geeman2.0
Member
 
Registered: Feb 2005
Location: Ontario, Canada
Distribution: Gentoo, Slackware
Posts: 345

Rep: Reputation: 30
A properly configured firewall will guarantee that packets can only get through to certain ports. If your amule packets are still getting through then they must be using some other ports that are being left open.
 
Old 03-11-2006, 12:06 AM   #6
BDHamp
Member
 
Registered: Mar 2005
Distribution: Ubuntu 9.10, Mint 8, Slackware 12
Posts: 105

Rep: Reputation: 16
Just a clarification here ...

Based on what was said, I believe delta_9 was simply offering an example of opening ports and asking, then, if the firewall is still any protection once those ports are open. The reason for this example, I suspect, is that the eDonkey network, which aMule uses, requires you to open two specific ports so that you can receive a HighID on the network, which, without going into all the details, generally lets you transmit and receive faster. It will work without these ports open, but you get a LowID on the network and have to go through the server rather than direct connections, which slows things down.
 
Old 03-11-2006, 07:40 AM   #7
jonaskoelker
Senior Member
 
Registered: Jul 2004
Location: Denmark
Distribution: Ubuntu, Debian
Posts: 1,524

Rep: Reputation: 47
I'm no eDonkey network expert, but here's my best guess:

The firewall only filters incoming connections. That is, no one can connect to you, but you can connect to anyone (OP: think of it as having an unlisted phone number if it helps).

If a lot of people also filter incoming connections, that means there's a lot of people you can't connect to; if there's fewer people you can connect to, that means there are fewer hosts to send you the data you need, thus you get a lower bitrate.

So, it does not conflict with the empirical evidence. Why do I think this is likely? Because it makes sense--on most desktop machines, you don't offer services to the world (that is, you're always a client, never a server), so there's usually no need to have anyone connect to you.

Peer-to-peer really shows that this assumption is wrong--you want to have people connecting to you; however, the adaption is slow.

hth --Jonas
 
Old 03-11-2006, 07:59 AM   #8
KimVette
Senior Member
 
Registered: Dec 2004
Location: Lee, NH
Distribution: OpenSUSE, CentOS, RHEL
Posts: 1,794

Rep: Reputation: 46
http://www.google.com/search?q=how+f...en-US:official

First hit is a HowStuffWorks article which is very good for novices.
 
Old 03-11-2006, 09:56 AM   #9
delta_9
Member
 
Registered: Feb 2006
Location: Athens
Distribution: opensuse 11/kubuntu 8.04
Posts: 99

Original Poster
Rep: Reputation: 15
What i wanted to ask is exactly what BDHamp described.This is what is all about:Even if ports are closed amule(or nicotine, or bittorrent or a trojan, or a worm) can have acces to network
 
Old 03-11-2006, 10:39 AM   #10
Crito
Senior Member
 
Registered: Nov 2003
Location: Knoxville, TN
Distribution: Kubuntu 9.04
Posts: 1,168

Rep: Reputation: 53
You need to read up on difference between stateful and stateless firewalls. http://en.wikipedia.org/wiki/Stateful_firewall
http://en.wikipedia.org/wiki/Stateless_firewall

Also note that if using a firewall integrated with a home router, you're likely also using PAT which requires the opening and closing of high port numbers all the time to function. But you didn't ask about that so...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How Do You Protect Yourself? nuka_t Linux - Security 5 08-18-2004 11:35 PM
What does the GPL protect? Thaidog General 4 06-28-2004 02:51 AM
How to protect my SQUID? yuzuohong Linux - Networking 1 05-30-2003 07:32 AM
samba and firewall auto protect saavik Linux - Security 1 04-19-2002 11:20 AM
samba and firewall auto protect saavik Linux - Networking 0 02-14-2002 12:11 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration