Re: Port 113 security

From: Nick Mashchenko (mnv@gu.kiev.ua)
Date: 03/06/03

  • Next message: Glynn Clements: "Re: Port 113 security"
    Date: Fri, 7 Mar 2003 00:01:50 +0200
    From: Nick Mashchenko <mnv@gu.kiev.ua>
    To: Chris Santerre <csanterre@MerchantsOverseas.com>
    
    

    Hello Chris,

    Thursday, March 6, 2003, 5:07:06 PM, you wrote:

    CS> Currently I block port 113 (ident) on the firewall. I block everything and
    CS> pick and choose what to let in. Never got around to letting this in :)
    CS> Anyway, I have about 6-7 in.identd processes running all the time from
    CS> failed ident attempts. Nothing big really. System is working great. Logs get
    CS> filled a little much with DENY messages.

    CS> So does evryone generally let these thru? Any exploits? is there a way to
    CS> get rid of those in.identd processes if I leave it blocked?

    Chris, this is OK. A lot of programs are trying to send a request to
    an identd. They want to know, who are you. I don't remember which
    programs exactly are doing this, but I definitely know about this :-).
    So, do not be trouble! :-). You can also tune up your firewall to push
    it REJECT such a request instead of DENY. 70% if you'll REJECT, the
    correspondent's identd will not try again to send the same request
    again and again to your box :-).

    --
    Best regards,
      Nick Mashchenko
      UOL VoIP engineer
    

  • Next message: Glynn Clements: "Re: Port 113 security"

    Relevant Pages

    • Re: identd server
      ... >> Ident daemon does not provide any usefull/reliable info to requester, ... If the computer the request ... I don't know if any such firewall ...
      (comp.os.linux.security)
    • Re: some thoughts on the Slammer fiasco
      ... it can break SQL server. ... the port its better to do it at the router level so the firewall can do the ... > WTF are you running a software firewall on an SQL box for. ... > firewall of your choice) block port X. ...
      (microsoft.public.sqlserver.security)
    • Re: Blocking Port scans
      ... >Firewall Assessment for a CISCO PIX firewall. ... >I think it should be easy to block FIN, NULL and XMAS ... than wondering how to block port scans. ...
      (Pen-Test)
    • Re: 3-5 sec wait time on SMTP relaying
      ... I dont think the JavaMail API supports ident, ... do ident through a firewall - thats where the timeout kicks in - and in ... my case we are going through the firewall. ... secs - its a heavily used smtp server. ...
      (comp.mail.sendmail)
    • Re: N00b Question
      ... > would have to block port 80, used for all web viewing, which isn't ... >> I am very new to the firewall and network security world. ...
      (Security-Basics)