Re: Am I missing something about portsentry?

From: R. DuFresne (dufresne_at_sysinfo.com)
Date: 05/22/03

  • Next message: n0brain: "RE: Cain a& Abel Question"
    Date: Thu, 22 May 2003 14:00:11 -0400 (EDT)
    To: "Vlad G." <recompiler@hacksrus.com>
    
    

    It should not take a kill and restart or even a kill -HUP of portsentry,
    but, removing from the portsentry.blocked.X files and then deleting the
    route should reopen access for the target/source in question. Depending
    upon the OS, the dead route points the offender to 127.0.0.1, so:

    route -delete target-ip 127.0.0.1 should remove that also.

    Thanks,

    Ron DuFresne

    On Thu, 22 May 2003, Vlad G. wrote:

    > In the process of pentesting a machine on local network I got locked out of
    > it due to port sentry. I kept spoofing MAC addreses, and finally got in
    > with an SMTP exploit.
    >
    > Some of the admin stuff has to be done only from a specific MAC address,
    > but its now locked out. I went to portsentry.history and removed the IP
    > address, and removed it from portsentry.blocked.udp, portsentry.blocked and
    > portsentry.blocked.tcp . I even added it to portsentry.ignore. The IP
    > address that was black listed still not able to connect, I get connection
    > to host lost error. I'm sure it's because portsentry.conf file has
    > KILL_ROUTE="/sbin/route add -host $TARGET$ reject".
    >
    > I tried deleting the route, but nothing seems to be working. Any
    > suggestions?
    >
    > thanks
    >

    -- 
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
            admin & senior security consultant:  sysinfo.com
                            http://sysinfo.com
    "Cutting the space budget really restores my faith in humanity.  It
    eliminates dreams, goals, and ideals and lets us get straight to the
    business of hate, debauchery, and self-annihilation."
                    -- Johnny Hart
    testing, only testing, and damn good at it too!
    ---------------------------------------------------------------------------
    *** Wireless LAN Policies for Security & Management - NEW White Paper ***
    Just like wired networks, wireless LANs require network security policies 
    that are enforced to protect WLANs from known vulnerabilities and threats. 
    Learn to design, implement and enforce WLAN security policies to lockdown enterprise WLANs.
    To get your FREE white paper visit us at:    
    http://www.securityfocus.com/AirDefense-pen-test
    ----------------------------------------------------------------------------
    

  • Next message: n0brain: "RE: Cain a& Abel Question"

    Relevant Pages

    • Re: Downloader.Trojan
      ... a little unsure as to how to go about doing what you suggest. ... > control lists and just ... > Restart, then kill it. ... After following this route, ...
      (microsoft.public.security.virus)
    • Re: As not to offend anyone
      ... Would you throw a major temper tantrum, riot, kill hundreds of people, or ... perhaps go the other route and pray they see the light? ...
      (misc.news.internet.discuss)
    • Zaragoza to the coast
      ... I'll be driving from Zaragoza toward Salou/Port Aventura with a couple ... of days to kill - wondering what there is en route that I shouldn't ... Towns, cathedrals, vineyards, just general scenery, whatever. ...
      (rec.travel.europe)
    • Re: National Postal Workers Food Drive -- May 13th
      ... Especially in my neighborhood ... where they walk the route, they would kill themselves collecting food, ...
      (rec.food.cooking)
    • RE: [fw-wiz] Interlopers on the WLAN
      ... the weak default setus that might be infringing security of various gov ... > these WLANs are operated by non-technical consumers who, in my view, ... Spammers might well take this route, and might already have taken this ... shadowed by the free wireless routes available for access. ...
      (Firewall-Wizards)