LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   Sheilds up shows opened ports with Firestarter? (https://www.linuxquestions.org/questions/linux-security-4/sheilds-up-shows-opened-ports-with-firestarter-489220/)

badmofo666 10-03-2006 10:46 PM

Sheilds up shows opened ports with Firestarter?
 
I just made my old computer into a Router/Firewall using Firestarter. I checked the firewall with the Shields Up website and it showed just a few "stealthed" ports, about 3 opened ports, and all the rest showed "closed." It said that all the ports should be "stealthed."

The opened ports really worried me. It showed OpenSSH(which I use locally), DNS(not sure if I need), and some unknown port in the 800's as opened. The only ports I have open in firestarter are port forwarded to my other pc, and that's just azureus, limewire, and a game(these were the only stealthed ports). I also set firestarter to always accept connection from my local IP.

I thought firestarter is supposed to block all inbound connections unless they're specifically allowed?

After this, I did set it to block all ICMP services and ran sheilds up again, and this time it showed everything as "stealthed." I don't know if this will cause any problems or not though? Is my system now firewalled or not?

////// 10-04-2006 02:38 AM

I wouldn't trust grc so much, there is lots of better scans around.

Nessus scan:
http://www.it-sec.de/vulchke.htm

Different pings and Dos packets.
http://www.pcflank.com/scanner1s.htm

Normal tcp - udp scan.
http://scan.sygate.com/

Test with these if you have any open ports.

badmofo666 10-05-2006 07:24 AM

Those all said I passed too. But...

I don't see how just filtering ICMP would close my open ports?

Or were these ports really open?

addux 01-01-2007 10:37 PM

**I'm a neWb plz bear with me**

This isn't directly related to the thread and related problem but includes issues with Firestarter, open ports, security, and ultimately Azureus.

I use Firestarter despite the understanding that Ubuntu (my current *nix), by default, closes all incoming ports. I have opened port 6881 for Azureus although Firestarter 'warns' it is open to anyone. At night I leave my torrents on the net to be seeded and on numerous occasions I wake up to see that various high numbered, random ports are open as an active connection ("unkown" apps/service), including various connections, as expected, on port 6881. Finally, they, according to Firestarter, stay active after Azureus is terminated. Is this a serious problem? Any ideas as to why the ports stay open? Related at all to exploits or bugs in Azureus?

chort 01-02-2007 01:53 AM

Quote:

Originally Posted by badmofo666
Those all said I passed too. But...

I don't see how just filtering ICMP would close my open ports?

Or were these ports really open?

Because it blocked the out-bound "ICMP port unreachable" errors. It's not any more secure, it just made the scanner happy.

You should check your firewall configuration to see what it's set to block and allow. If SSH is really opened from the Internet, that might not be what you wanted.


All times are GMT -5. The time now is 07:10 AM.