Re: iptables anti-nimda anyone?

From: Rob 'Feztaa' Park (fezziker@home.com)
Date: 09/24/01


Date: Sun, 23 Sep 2001 21:46:44 -0600 (MDT)
From: Rob 'Feztaa' Park <fezziker@home.com>
To: <teo@gecadsoftware.com>
Subject: Re: iptables anti-nimda anyone?
Message-ID: <Pine.LNX.4.33L2.0109232145270.20377-100000@feztron.ath.cx>

On Fri, 21 Sep 2001, teo@gecadsoftware.com (dis)graced my inbox with this:

> until the storm gets low I have this:
>
> $IPTABLES -I INPUT -p tcp --dport 80 -m string --string .ida -m state --state ESTABLISHED \
> -j REJECT --reject-with tcp-reset
> $IPTABLES -I INPUT -p tcp --dport 80 -m string --string cmd.exe -m state --state ESTABLISHED \
> -j REJECT --reject-with tcp-reset
> $IPTABLES -I INPUT -p tcp --dport 80 -m string --string root.exe -m state --state ESTABLISHED \
> -j REJECT --reject-with tcp-reset

Unless you actually have exe files that you wish to share with people, I'd
recommend that you just block exe's altogether (like you've done with
ida's).

-- 
Rob 'Feztaa' Park
fezziker@home.com
--
Whom computers would destroy, they must first drive mad.



Relevant Pages

  • Re: FTP File Transfer.
    ... Can anyone recommend good host sites (I am looking at ... > Another problems is the amount of spam/virus filters now being put in place ... Our tranfers will xontain some .exe files and that causes ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Hard SF recommendations?
    ... Altogether, I think I got maybe a dozen titles recommended... ... Author of: iPod & iTunes Garage ...
    (rec.arts.sf.written)
  • Re: Hard SF recommendations?
    ... kirk@xxxxxxxxxxxxx (Kirk McElhearn) wrote: ... Altogether, I think I got maybe a dozen titles recommended... ... > descriptions of books on Amazon, I don't see much that stands out.) ...
    (rec.arts.sf.written)
  • Kodak v550
    ... Are they very tough and ... recommend them? ... stay away from them altogether? ... Prev by Date: ...
    (rec.photo.digital)