Re: ipf stopped working on 5.3

From: Arne (arne_woerner_at_yahoo.com)
Date: 10/25/05

  • Next message: Fernando Gleiser: "Re: ipf stopped working on 5.3"
    Date: Tue, 25 Oct 2005 13:27:34 -0700 (PDT)
    To: John Fitzgerald <jjfitzgerald@gmail.com>, freebsd-security@FreeBSD.org
    
    

    I think you should try to implement a pf-based and/or a ipfw-based
    firewall (both works quite well for me) immediately, so that your
    system is not so much endangered... This is just a workaround...

    -Arne

    --- John Fitzgerald <jjfitzgerald@gmail.com> wrote:

    > I've had ipf working on a few 5.3 servers for quite awhile. Not
    > too long ago
    > some developers had to do some coding work and were coming from
    > dynamic
    > IP's. I (reluctantly) opened up SSH to the world. Immediately I
    > started
    > seeing the attacks where bots of some sort would try to break in
    > with a
    > variety of different users.
    >
    > So, I (thought) I closed it up again and told the developers to
    > use a
    > dedicated proxy. They did, but I realized that I hadn't actually
    > closed
    > things off. I was still getting attacked. I had tried, but ipf
    > suddenly
    > wasn't working. Whenever I would change the firewall rules and
    > ipf -D and
    > the ipf -E -f /etc/my.rules it would simply return:
    >
    > 1:ioctl(add/insert rule): No such process
    >
    > I didn't have the time to look into it at the time, but am now
    > trying to
    > figure it out. Ipf is obviously not working and I don't know
    > why. I have
    > tried recompiling the kernel a myriad of different ways.
    > With/without ipfw,
    > with/without ipsec, etc. All to no avail. Is this a bug, did I
    > get hacked?
    >
    > I have googled this quite a bit and the only thing that I found
    > was possibly
    > a buildworld scenario where something got updated and it doesn't
    > work now. I
    > didn't install src so I'm a bit out of luck on that one.
    >
    > FreeBSD 5.3-RELEASE
    > OpenSSH_3.8.1p1 FreeBSD-20040419, OpenSSL 0.9.7d 17 Mar 2004
    >
    > Cheers,
    > JJ
    > _______________________________________________
    > freebsd-security@freebsd.org mailing list
    > http://lists.freebsd.org/mailman/listinfo/freebsd-security
    > To unsubscribe, send any mail to
    > "freebsd-security-unsubscribe@freebsd.org"
    >

            
                    
    __________________________________
    Yahoo! Mail - PC Magazine Editors' Choice 2005
    http://mail.yahoo.com
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Fernando Gleiser: "Re: ipf stopped working on 5.3"

    Relevant Pages

    • Re: Bridging Firewalls
      ... What attacks are possible on ... the firewall itself beeing compromised. ... One possible scenario could perhaps be if the filtering software can be ... ipf or even ipfw to crash in some ...
      (comp.security.firewalls)
    • Re: Bridging Firewalls
      ... What attacks are possible on ... the firewall itself beeing compromised. ... One possible scenario could perhaps be if the filtering software can be ... ipf or even ipfw to crash in some ...
      (comp.security.firewalls)
    • Re: Bridging Firewalls
      ... What attacks are possible on ... the firewall itself beeing compromised. ... One possible scenario could perhaps be if the filtering software can be ... ipf or even ipfw to crash in some ...
      (comp.security.unix)
    • Re: Bridging Firewalls
      ... What attacks are possible on ... the firewall itself beeing compromised. ... One possible scenario could perhaps be if the filtering software can be ... ipf or even ipfw to crash in some ...
      (comp.security.unix)
    • Re: Hacking to Xp box
      ... I think there was a misunderstanding in the firewall point: ... you need to find some vulnerability that could be exploited to run ... > restricts most of the attacks that use anonymous connections. ... > Audit your website security with Acunetix Web Vulnerability Scanner: ...
      (Pen-Test)