Re: Port 113 security

From: Brian Hatch (focus-linux@ifokr.org)
Date: 03/06/03

  • Next message: Peter H. Lemieux: "Re: Port 113 security"
    Date: Thu, 6 Mar 2003 14:56:48 -0800
    From: Brian Hatch <focus-linux@ifokr.org>
    To: Chris Santerre <csanterre@MerchantsOverseas.com>
    
    
    

    > Currently I block port 113 (ident) on the firewall. I block everything and
    > pick and choose what to let in. Never got around to letting this in :)
    > Anyway, I have about 6-7 in.identd processes running all the time from
    > failed ident attempts. Nothing big really. System is working great. Logs get
    > filled a little much with DENY messages.

    If you don't want to allow others to contact your IDENT port,
    then kill any in.identd processes (they're not needed) and
    block the inbound accesses with REJECT instead of DENY/DROP.

    If a remote server does an IDENT check (say a remote Sendmail
    server) then you want it to get a 'connection failed' notice
    right away, otherwise it will wait until the timeout occurs,
    and this ties down their system and slows down your ability to
    get the mail out the door.

    > So does evryone generally let these thru? Any exploits? is there a way to
    > get rid of those in.identd processes if I leave it blocked?

    Any way to get rid of them? Sure - kill them and turn them off in
    your /etc/rcX.d directories. (chkconfig on Red Hat, etc.)
    Or just kill them and uninstall identd entirely.

    --
    Brian Hatch                  There you have the
       Systems and                source of your
       Security Engineer          popularity
    http://www.ifokr.org/bri/      -- your absense.
    Every message PGP signed
    
    



  • Next message: Peter H. Lemieux: "Re: Port 113 security"

    Relevant Pages

    • Re: Is the game lost....?
      ... > ....or is there any way of getting rid of the M3 scourge or are we stuck ... > with them...shurley if the majority don't want want them we could do ... decreed that every citizen was to kill ten flies each day. ... Kill them off. ...
      (uk.radio.amateur)
    • Re: process cant be killed
      ... > and not even after a kill -9, is there any other method to get rid of it ... system call your process is hanging in to return and thus the SIGKILL to ... accessing files over an NFS mount when the NFS mount suddenly disappears ...
      (comp.unix.aix)
    • Re: OT The ATC
      ... just get rid of them. ... Don't you like the idea that we can kill a few million ethnics at the ...
      (uk.rec.motorcycles)
    • Re: regedit.exe starts and vanishes immediately
      ... > I want to get rid of the widows protected files checking evry time windows ... Safe Mode, in safe mode, open Task Manager, kill as many processes as ... you can, then kill explorer - this will kill your desktop, then do a CAD ...
      (microsoft.public.win2000.general)
    • Re: Trouble unmounting USB devices
      ... gamin to get rid gam_server issue. ... you may search for the pid and kill it: ... > Kevin Kempter wrote: ...
      (Fedora)

  • Quantcast