/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ Hey Everyone, Lots of changes and some SERIOUS security issues covered. 399 users on the Updates list and counting!!! Ok, first, here are the changes posted to my site from the main page's "Top 10" since the last update sent out on 2/21/00: -- 03/19/00 Updated TrinityOS and the TrinityOS archive 03/18/00 Updated TrinityOS and the TrinityOS archive 03/18/00 Updated the Internet retailers URL on the CD-R page 02/21/00 Updated TrinityOS, including new firewall rulesets, archive, etc Updated the IP Masq HOWTO to v1.82 01/24/00 Updated TrinityOS, posted a 01/03/00 TrinityOS port to .doc and .pdf, and updated function.s 01/17/00 Updated TrinityOS and the TrinityOS-security archive as well Updated the CD Writer page to add clarifications of CD writer formats and issues with different colored blank CD media. 01/02/00 Updated TrinityOS and the archive as well 01/02/00 Added PS, PDF, and a TGZ archive of the IP-Masq HOWTO v1.80 Here are all the changes to TrinityOS... -- I 3/27/00 Updated the IPCHAINS firewall to v3.55 *Sent Update* Deleted the text from the IPCHAINS firewall ruleset and the DHCPcd section: -- #****************************************** # ABSOLUTELY CRITICAL: If you run the # /etc/dhcpcd/dhcpcd-ethX.exe file (needed # for DHCP'ed DSL and cablemodem users), # you CANNOT also enable the # /etc/rc.d/init.d/firewall script below. #****************************************** -- The reason for this is that the firewall script file WON'T be executed if the old IP address for the machine was the same after reboot. So, you need to have: Redhat: the /etc/rc.d/init.d/firewall script activated Slackware: have the /etc/rc.d/rc.local script load the /etc/rc.d/rc.firewall ruleset. Please NOTE: ------------ I think there still might be some issues with this setup. The problem stems around the fact that the rc.firewall might get loaded from both dhcpcd's /etc/dhcpcd/dhcpcd-ethX.exe AND /etc/rc.d/init.d/firewall. I'm still looking into this and if you have any comments on this, I'd love to hear from you. [Section 10 and 35] *C* There are -6- new security vunerabilities for Linux that depends on the distro you are running. Check out this section ASAP!! [Section 60] G Updated the TrinityOS archive script to reflect the DHCPcd issues. ------------------ N 3/25/00 Updated the SSH Url [Section 3] N Fixed a typo where I was calling the "Dial-In Server HOWTO" the "Dial-UP" server HOWTO. [Section 5] G Updated the IPCHAINS firewall to 3.54 - Added filters for the new "Shaft" DDos tools [Section 10] ------------------ I 03/20/00 Found a typo in the /usr/lib/sendmail-cf/cf/trinityos.mc file. Changed "confSTMP" to "confSMTP". Thanks to [EMAIL PROTECTED] for this one. [Section 25] ------------------ *C* 03/19/00 I -thought- I solved all the DHCPcd issues but it sounds like DHCP users cannot run both the /etc/rc.d/init.d/firewall and the /etc/dhcpcd/dhcpcd-eth0.exe file. This yeilds BAD results. I have added comments to make DHCP users aware of this in both the IPCHAINS firewall and the DHCP sections. [Section 10, 35] I have changed the enabling the /etc/rc.d/init.d/firewall script from AutoFix to Userfix in the TrinityOS archive script. ------------------ I 03/18/00 Added a top section to clarify why TrinityOS is both Trademarked and Copyrighted: -- Sorry for all the legal stuff... Yet I've already had one company try to have the name TrinityOS taken from me and one HOWTO author has already ripped off MUCH of TrinityOS's content though it was re-written to avoid and direct copyright issue. I'm just covering my butt here from the many lowlifes in the world. -- [Intro] N Updated the URL for Diald Thanks to [EMAIL PROTECTED] for this one. [Section 5] N Tripwire has gone OpenSource for Linux! Woohoo! They have also released a version that runs on Glibc. I've updated the Tripwire section with all the new URLs. Thanks to [EMAIL PROTECTED] for this one. [Section 5] N Added a few URLs for PPPoE [Section 5] N Added a few URLs for PPTP and Encrypted PPTP VPNs [Section 5] G Added a URL to Robert Gram's FAQ on how to understand what Firewall logs mean. [Section 5] N Added a URL for Linux Real Time Messangers (ICQ, AIM, etc) [Section 5] N Deleted the reference to /etc/localhosts. This is OLD stuff. Thanks to [EMAIL PROTECTED] for this one. [Section 7] G Fixed the permission setting locations of klogd and syslogd. Thanks to [EMAIL PROTECTED] for this one. [Section 8] G Updated the IPCHAINS rc.firewall ruleset to v3.52 # v3.52 - 03/18/00 # - Finally found a 100% solution for # DHCPcd users out there that get DHCP'ed # IP addresses on their external INTERFACE. # Changes in the firewall ruleset is only # the DELETION of comments in the top # section to then refer users to the DHCPcd # section in TrinityOS for full details # (as it should be to minimize confusion). # # The syntax "dhcpcd -D -H $EXTINT # etc/rc.d/rc.firewall" was WRONG. # # - Moved the PORTFW variabled to be below # the SECUREHOST section for clarity. # # - Added some comments for PORTFW users # on how to allow portfw access to explict # hosts and/or networks. # # - Added two more PORFWIP variabless to # the IPCHAINS ruleset # # - Moved the PORFW section from the INPUT # section to the FORWARDing section for # better clarity # # - Added a section in the general INPUT # section for Squid w/ JunkBuster. # # - Expanded on the DoubleClick filtering # example with network numbers from # [EMAIL PROTECTED] # # Thanks to [EMAIL PROTECTED] for helping # troubleshoot this for me. # [Section 10] # G Deleted an extra "#" from the /etc/rc.d/init.d/firewall script that kept it running with Linuxconf. Thanks to [EMAIL PROTECTED] for catching this one. [Section 10] G Updated the IPFWADM rc.firewall ruleset to v2.97 # v2.97 - Deleted the DHCPcd commands as # the syntax was old an misleading. # Update to IPCHAINS for a far # superior firewall ruleset. [Section 10] G Added a recommendation for users to check out Robert Gram's Firewall hit FAQ to understand what their firewall logs really mean. [Section 10] I Finally found the proper solution to get users that use DHCPcd on their external interfaces to re-run the rc.firewall ruleset upon a lease renew. [Section 35] I Updates to the TrinityOS archives: - Fixed the permission setting locations of klogd and syslogd Thankd to [EMAIL PROTECTED] for catching this. - Fixed an error in the TrinityOS archive where chkconfig was enabling "network" instead of "firewall" in the various /etc/rc.d/rc.Xd dirs. Thanks to [EMAIL PROTECTED] for catching this one. - Updated the firewall to v3.52 ----------------- N 03/13/00 Added the URL for the DHCPcd homepage [Section 5] ----------------- N 03/05/00 [EMAIL PROTECTED] informed me that the Trinity site, the first nuclear test site, wasn't in Nevada but White Planes, New Mexico. Thanks James! N Updated the rc.firewall ruleset to v3.51 - Removed a duplicate input filter for spoofed packets, etc. Interestingly enough, trinityos.wri didn't have the duped line. Thanks to [EMAIL PROTECTED] for the sharp eye. [Section 10] N Updated the TrinityOS archive ------------------ N 02/29/00 Updated the proceedures for installing Sendmail manually. Before I did: cp /usr/src/archive/sendmail/sendmail-x.x.x/ /usr/lib/sendmail-cf now it is: mkdir /usr/lib/sendmail-cf tar cpf - /usr/src/archive/sendmail/sendmail-x.x.x/* | (cd /usr/lib/sendmail-cf; tar xvpf -) This fixes an issue where the /usr/lib/sendmail-cf dir isn't already present or when its on the same file system. Thanks to [EMAIL PROTECTED] for bringing this to my attention. [Section 25] ------------------ N 02/26/99 Updated the IPCHAINS rc.firewall to v3.50 - Fixed a minor error in the commented Diald line were the $INTLAN variable needed to have the extra "/24" deleted. Thanks to [EMAIL PROTECTED] for reporting this. [Section 10] G Fixed a missing "fi" statement in the TrinityOS-security.sh script that would kill it after the PPP section. ------------------ .----------------------------------------------------------------------------. | David A. Ranch - Linux/Networking/PC hardware [EMAIL PROTECTED] | !---- ----! `----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----' _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
