LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-06-2004, 04:39 PM   #1
phatbastard
Member
 
Registered: Mar 2004
Location: Houston, Texas
Distribution: Kubuntu, zenwalk
Posts: 117

Rep: Reputation: 15
Secure this!!!


Ping Reply: RECEIVED (FAILED) — Your system REPLIED to our Ping (ICMP Echo) requests, making it visible on the Internet. Most personal firewalls can be configured to block, drop, and ignore such ping requests in order to better hide systems from hackers. This is highly recommended since "Ping" is among the oldest and most common methods used to locate systems prior to further exploitation.


I got that from shields up on grc.com. How do i configure slackware 10 to drop ping (ICMP Echo) requests. Im running firestarter and there is no way to configure that i think. Must be something command line somehwhere?
 
Old 11-06-2004, 04:50 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
this is a simialr thread http://www.linuxquestions.org/questi...threadid=22708

although i am pretty sure that firestart will happily let you block pings itself, if you go through the wizardy UI
 
Old 11-06-2004, 05:04 PM   #3
phatbastard
Member
 
Registered: Mar 2004
Location: Houston, Texas
Distribution: Kubuntu, zenwalk
Posts: 117

Original Poster
Rep: Reputation: 15
worked....thanks
 
Old 11-06-2004, 05:26 PM   #4
SciYro
Senior Member
 
Registered: Oct 2003
Location: hopefully not here
Distribution: Gentoo
Posts: 2,038

Rep: Reputation: 51
careful how you set it up, pings are necessary for a lot of things with the Internet ... so don't block em all

also that site just trys to scare people ... pings are not a vulnerability, if your scared someone might get into your computer, then go thru and secure it the right way before trying to obscure everything
 
Old 11-08-2004, 04:01 PM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Someone care to expand on the different types of ICMP message, how some of them have sysctl options to turn off and how some of them are not a problem?
 
Old 11-08-2004, 05:09 PM   #6
SciYro
Senior Member
 
Registered: Oct 2003
Location: hopefully not here
Distribution: Gentoo
Posts: 2,038

Rep: Reputation: 51
http://www.faqs.org/docs/iptables/icmptypes.html

is that work? .... for more info look at the wiki, theres a link to the RFC with specific info on what it is ... you can configure iptables to drop or reject or whatever certain icmp types, i myself block types 13-18 because i don't think anyone should need to ask me them

http://wiki.linuxquestions.org/wiki/ICMP

Last edited by SciYro; 11-08-2004 at 05:12 PM.
 
Old 11-08-2004, 06:00 PM   #7
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Some OSs uses ICMP ECHO REQUEST and ICMP ECHO REPLY for PathMTU Discovery (PMTU-D). Disabling "PING" can result in other hosts using the smallest allowable packet to communicate with you and thus significantly lower your performance while communicating to those sites.
 
Old 11-08-2004, 06:23 PM   #8
jev-bird
Member
 
Registered: Jul 2004
Location: USofA
Distribution: Whatever runs accordingly.
Posts: 200

Rep: Reputation: 30
if you want to play nice then don't disable icmp echo request, etc. But it's your choice and I never ever had any problems blocking pings.

If your isp's network is prone to bots and automated tools sweeping a netblock looking for certain ports on various machines then obviously your machine will not be a target if you block such request. You should be more concerned about blocking SYN FYN and other types of packets with thoose flags set.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
VSFTPD with secure & non-secure logins Ricci Graham Linux - Software 6 02-24-2020 11:49 PM
Secure email (SSL vs. secure authentication) jrdioko Linux - Newbie 2 11-28-2004 01:39 PM
Is it secure? hsegtreas Linux - Security 8 05-23-2004 09:17 PM
vsftpd very very secure, so secure i can't use it... baronsam Linux - Networking 4 10-06-2003 06:12 PM
Is this secure enough? ed_tang Linux - Networking 2 07-27-2003 09:26 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration