LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-13-2010, 09:05 AM   #1
taylorkh
Senior Member
 
Registered: Jul 2006
Location: North Carolina
Distribution: CentOS 6, CentOS 7 (with Mate), Ubuntu 16.04 Mate
Posts: 2,127

Rep: Reputation: 174Reputation: 174
Question How to block my computer from connecting TO a specific IP address?


I was taking a peek at the active connections shown by the Firestarter GUI and noticed the following (the source is my computer):

Source Destination Port Service Program
192.168.0.112 66.235.133.42 80 HTTP

I closed all Internet related apps and the connection persisted. After a reboot it did not reconnect (yet).

The IP address appears to belong to esomniture.com - some sort of web analytics company.

So my question is... How do I prevent my computer from connecting to these rascals. I have found a lot of documentation regarding stopping inbound connections to services on my computer but not the other way. I have various filtering addons installed in Firefox however, this connection seems to be at a lower level as no program is specified as being responsible for the connection.

TIA,

Ken
 
Old 02-13-2010, 09:32 AM   #2
r3sistance
Senior Member
 
Registered: Mar 2004
Location: UK
Distribution: CentOS 6/7
Posts: 1,375

Rep: Reputation: 217Reputation: 217Reputation: 217
Hi,

iptables -i output -d 66.235.133.42 -j DROP

should force anything going from your machine to that ip to just be dropped for the session. It might require sudo and run by /sbin/iptables rather then iptables.

This of course assumes you are running iptables, this is only a temp fix, but let's see if it works first.
 
Old 02-13-2010, 10:09 AM   #3
taylorkh
Senior Member
 
Registered: Jul 2006
Location: North Carolina
Distribution: CentOS 6, CentOS 7 (with Mate), Ubuntu 16.04 Mate
Posts: 2,127

Original Poster
Rep: Reputation: 174Reputation: 174
Thanks r3sistance,

I will try that if/when the connection reappears. Otherwise I will have no idea if it works as desired.

Yes, I am running iptables - Firestarter is a GUI front end for it as I understand.

Further searching tells me that the offending web site uses tracking cookies. I clear all cookies when I close Firefox so I generally do not worry about them very much. I have explicitly added esomniture.com to Add Block Plus so I may never see it again.

However, I have your command example in my bag of tricks should some other rascal connection appear.

Regards,

Ken
 
Old 02-13-2010, 10:36 AM   #4
r3sistance
Senior Member
 
Registered: Mar 2004
Location: UK
Distribution: CentOS 6/7
Posts: 1,375

Rep: Reputation: 217Reputation: 217Reputation: 217
please note that the command I supplied is for the destination IP, if you want to block traffic coming from an ip you'd use -s instead of -d as -s states source IP.
 
Old 02-15-2010, 04:29 PM   #5
taylorkh
Senior Member
 
Registered: Jul 2006
Location: North Carolina
Distribution: CentOS 6, CentOS 7 (with Mate), Ubuntu 16.04 Mate
Posts: 2,127

Original Poster
Rep: Reputation: 174Reputation: 174
Hi r3sistance,

I found another connection I did not like and tried your command. I received the following
Quote:
sudo /sbin/iptables -i output -d xx.xxx.xxx.xx -j DROP
iptables v1.4.4: no command specified
I tried both with and w/o sudo and with and w/o sbin. What am I missing?

TIA

Ken
 
Old 02-15-2010, 04:45 PM   #6
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984Reputation: 1984
the case is wrong, use "iptables -I OUTPUT -d xx.xxx.xxx.xx -j DROP" instead.
 
Old 02-15-2010, 05:55 PM   #7
taylorkh
Senior Member
 
Registered: Jul 2006
Location: North Carolina
Distribution: CentOS 6, CentOS 7 (with Mate), Ubuntu 16.04 Mate
Posts: 2,127

Original Poster
Rep: Reputation: 174Reputation: 174
Thanks acid_kewpie,

In the interim I have tracked down my latest strange connection. It seems to that VMWare player and workstation phone home to be able to download updates and other necessary files on an as needed basis. Why the programs need to maintain a continuous HTTPS connection - who knows. I found the preference settings to turn off the phone home. I will keep the correct syntax in my bag of tricks and try it in the future.

Ken
 
Old 02-16-2010, 05:45 AM   #8
r3sistance
Senior Member
 
Registered: Mar 2004
Location: UK
Distribution: CentOS 6/7
Posts: 1,375

Rep: Reputation: 217Reputation: 217Reputation: 217
Hi Ken,

Sorry about the case mistake there, it's useful to know iptables when it comes to being secure. VMWare does like to keep up to date and has caused other issues in the past but it's still a sweet piece of software relatively speaking, personally tho, license prices do put me off.

r3sistance.
 
Old 02-16-2010, 07:55 AM   #9
taylorkh
Senior Member
 
Registered: Jul 2006
Location: North Carolina
Distribution: CentOS 6, CentOS 7 (with Mate), Ubuntu 16.04 Mate
Posts: 2,127

Original Poster
Rep: Reputation: 174Reputation: 174
Thanks r3sistance,

From what little I have looked into Iptables - it is hardly user friendly. I am running Firestarter in anal retentive mode where it stops everything unless I allow the connection. I have enabled HTTP, HTTPS, ssh, smb and a couple of others such as ftp to my ISP's speed test site. When I see a connection which I do not expect, such as the one from VMWare, I get a little perturbed and investigate.

As to VMWare... I purchased a license for Workstation on sale a couple of years back on Cyber Monday. I though I needed it to create virtual machines although I knew I could run them in the free Player. Turns out that Player can create new machines so I have the extra capabilities of Workstation although I do not really take advantage of them.

I have run Linux for many years - at least a Samba server for file and printer sharing - but until recently not as my primary OS. Now that I have a more capable machine (Dell XPS 8000 with an i7-860 processor and 8 GB of RAM) I am running Ubuntu 9.10 64 bit with an XP Pro VM for those few things I cannot yet run in Linux (such as some Flash enabled web sites).

Enough computer stuff for the moment. I have to do some TIG welding on a brake servo I am repairing for my 1980 MGB and I have to fabricate new wings for the wife's whirly gig goose. The recent winds have broken off two of them.

Regards,

Ken
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Blocking dhcpd address lease for specific MAC address kulman Linux - Server 8 03-30-2013 01:51 PM
[SOLVED] Sendmail: block specific sender to specific recipient - How? thekillerbean Linux - Server 6 07-13-2010 04:13 AM
How to block specific Websites? alfredh SUSE / openSUSE 3 06-24-2006 05:17 AM
How to block specific IPs? cranium2004 Linux - Networking 3 04-01-2005 09:02 AM
block specific ip addresses paperdiesel Linux - Security 3 07-21-2004 11:47 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:14 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration