Re: IPChains leak for UDP!?

From: Alexander List (alexlist@sbox.tu-graz.ac.at)
Date: 10/31/01


Date: Wed, 31 Oct 2001 20:01:09 +0100 (CET)
From: Alexander List <alexlist@sbox.tu-graz.ac.at>
To: "Sanjeev B.S." <sanjeev@mbu.iisc.ernet.in>
Subject: Re: IPChains leak for UDP!?
Message-ID: <Pine.LNX.4.33.0110311957120.7620-100000@linux.babenberg.vc-graz.ac.at>

On Wed, 31 Oct 2001, Sanjeev B.S. wrote:

> But occasionally I would get some portsentry warnings, telling some port
> is getting probed. (I think all UDP only, I am not sure. Ports are
> usually 137, 138, 80, etc.)

I run iplogger and observe similar behaviour. But I think those tools are
running in promiscuous mode, so they will probably log everything kinda
"natively", analyzing packets themselves, and the packets don't have to
traverse the kernel's IP stack (and/or ipchains) to get logged. I have -l
switches on my ipchains deny rules so I see everything logged that I
actually don't want to see on my system ;-)

If I'm talking complete nonsense, someone please correct me ;-)

Alex

-- 
People often think of research as a form of development -- that it's
about doing exactly what you planned, doing it on time, and doing it
with resources that you said you'd use.  But if you're going to do
that, you have to know what you are doing, and if you know what you
are doing, it isn't really research."
             --Dave Liddle, The New Yorker, Feb. 23/Mar.2, 1998, p84



Relevant Pages

  • Re: iptables firewall script for linux
    ... "ipchains: Incompatible with this kernel". ... port is shown as LISTENING. ... What's wrong with reading the HOWTOs? ... included for their basic firewall concepts. ...
    (comp.security.firewalls)
  • Re: Ipchains and smtp rule
    ... Subject: Ipchains and smtp rule ... If the client's IDENT port is silently ... the whole mess was due to a missing switch on the dmz. ... With C++ it's harder, but if you succed, you'll shoot off the whole leg. ...
    (Focus-Linux)
  • Re: [ISA 2004] transparenter Proxy
    ... Das Filtern auf TCP Flags war bei IPCHAINS ... deshalb freu ich mich auf den ISA ... > die Sache indem du ein Portscanner verwendest und deinen absender Port auf ... Ich habe einen Portscanner auf das ...
    (microsoft.public.de.german.isaserver)
  • Re: Coyote IP Chains?
    ... > Using Sygate's online scanner it seems that Coyote Linux allows external ... > Sygate still is indicating the port is open which leads me to believe I ... Try this ruleset instead (my ipchains syntax might be a little off ... familiarize yourself with nmap; ...
    (comp.os.linux.security)
  • IPChains leak for UDP!?
    ... Subject: IPChains leak for UDP!? ... But occasionally I would get some portsentry warnings, ... Q2) I tried blocking UDP ports 137-139 specifically right in the begging, ...
    (Focus-Linux)