Re: iptables anti-nimda anyone?

From: Bjørn Ruberg (bjorn@linpro.no)
Date: 09/21/01


To: Konrad Michels <konrad@overnetdata.com>
Subject: Re: iptables anti-nimda anyone?
From: bjorn@linpro.no (Bjørn Ruberg)
Date: 21 Sep 2001 08:45:59 +0200
Message-ID: <uizadzpyrbs.fsf@false.linpro.no>

Konrad Michels <konrad@overnetdata.com> writes:

> Hi everyone
> I don't suppose one of our iptables gurus out there has an iptables rule
> to filter out this damn nimda thing? I'm really annoyed about it
> filling up my apache logz and would love to drop the packets 'ere they
> get to the apache server . . .

You may be able to deny it with the string matching patch from the patch-o-matic
section in iptables 1.2.3:

 string.patch
 The string patch:
    Author: Emmanuel Roger <winfield@freegates.be>
    Status: Working
    
    This patch adds CONFIG_IP_NF_MATCH_STRING which allows you to
    match a string in a whole packet.
    
    THIS PATCH REQUIRES AT LEAST KERNEL 2.4.9 !!!

Be aware that the patch-o-matic is not always considered to be stable and bug-free.

Read the iptables INSTALL file for information on how to apply the patches.

Oh, and the string match? I guess "c+dir" will take care of most of it. Read the
security focus analysis available at
<URL:http://aris.securityfocus.com/alerts/nimda/010919-Analysis-Nimda.pdf>

Hope this helps,
Bjørn

-- 
Bjørn Ruberg, Linpro AS
bjorn@linpro.no

The more you scream, the less you hear. (Fish)



Relevant Pages

  • Re: IPTABLES STRING PATCH LIMITATION
    ... I really think you need to have a rethink about your use of IPTables. ... STRING can put a lot of load on a computer as every single ... You can also tweak the web server to look at the url's before they are ...
    (comp.os.linux.networking)
  • iptables anti-nimda/my project...
    ... Subject: iptables anti-nimda/my project... ... > You may be able to deny it with the string matching patch from the patch-o-matic ... add it to the exploit file, kill -1 the redirector, and you're ... NT server is virtually "patched" until the admin can get to it. ...
    (Focus-Linux)
  • Re: iptables anti-nimda anyone?
    ... Subject: iptables anti-nimda anyone? ... I can see where having this string filter could be handy. ... extensions you want to generate kernel patches for. ... The string patch: ...
    (Focus-Linux)
  • Scripting fun...
    ... people who know what they're doing to laugh at. ... and every IP trying to retrieve a file of that name (or string) I ... Yahoo web crawlers. ... not already in the iptables to the iptables drop list. ...
    (Ubuntu)
  • Sparc64 U60: no iptables
    ... >> It is related to the iptables subsystem. ... >> How can I get the copy of the trace without handwriting? ... I found the culprit for my oops. ... The culprit patch substitute the NR_CPUS by the num_possible_cpusmacro. ...
    (Linux-Kernel)