/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


A few questions first:

1) How are you connected to the Inet?  PPP?  DSL?  Static or dynamic IP
address?

2) How are you loading the rc.firewall script?


Anyway, since it sounds like your firewall isn't running upon boot,
you should be concerned why you have ports 1080, 12345, and 111
open.  This is BAD.

Next, filtering in-bound pings is silly though its simple.
You need to filter ICMP-ECHO destined to your external interface.

Lastly, blocking OS detection is almost impossible.  OS fingerprinting
is done by the way a given OS responds to various IP flags, etc.
You could alter this by editing the Linux TCP/IP source code but no
by doing something in a firewall ruleset.

--David


>My firewall script (from the TrinityOS (tm) site) leaves ports 22 (ssh),
>53 (domain), 80 (http), 111 (sunrpc) open, and "filtered" ports open on
>1080 (socks), 12345 and 12346 (NetBus). (I have tested this from a
>couple of security sites, such as secure-me.net). The firewall is
>started on bootup, and it seems to be working: rc.firewall is called by
>the /etc/init.d/network script in Debian (and it is executable).
>
>The _second_ time I run the script from the command line, and then run
>these security tools, the only ports left open are 53 (domain) and the
>filtered ones. Why is this? Is the way I configured my firewall to be
>engaged, incorrect? By running the firewall a second time, I have
>noticed that the scans I have experienced from script kiddies has gone
>way, way down, so I would like to make sure that the firewall is
>properly engaged the first time.
>
>Some other questions to enhance security:
>1. Should I be concerned about the ports that are visible? -
>2. Should I be concerned because my system responds to pings? Would
>someone give me an ipmasq script that would limit responding to pings to
>the @Home network (I lose my ip address if my box doesn't respond).
>3. How do I fake out the OS of my system? I don't want people to be able
>to "see" this.
>
>I have tried to close these "holes" without success, by adding lines to
>the firewall script, but only made the holes worse, and quickly reverted
>to my working firewall. Help is greatly appreciated.
>
>_______________________________________________
>Masq maillist  -  [EMAIL PROTECTED]
>Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS
INCLUDES UNSUBSCRIBING!
>or email to [EMAIL PROTECTED]
>
>PLEASE read the HOWTO and search the archives before posting.
>You can start your search at http://www.indyramp.com/masq/
>Please keep general linux/unix/pc/internet questions off the list.
>
.----------------------------------------------------------------------------.
|  David A. Ranch - Linux/Networking/PC hardware         [EMAIL PROTECTED]  |
!----                                                                    ----!
`----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----'

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to