Re: Newbie: Help with home machine surveillance

From: Alan W. Frame (alan.frame@acm.org)
Date: 01/01/02


From: alan.frame@acm.org (Alan W. Frame)
Date: Tue, 1 Jan 2002 14:05:55 +0000

Tim Haynes <usenet@stirfried.vegetable.org.uk> wrote:

> Dave K. <david345@toast.com> writes:
>
> > I used some website (don't have
> > the name offhand) to check that all my ports were secure.
>
> `netstat -plant | grep LIST' is a bit quicker, although the external
> correlation is reasonable; you have to design your rule-set such that you
> don't just match the ports they scan you for, but in such a way that *if*
> the ports they scan all come back filtered, you know everything else is too.

Indeed.

Out of instinct I netstat -plant'd recently on a random[0] box in a DMZ
and found that a rather old lpr was running - OK, the ipchains on the
box was nailed down, and the packet-filtering on the routers was nailed
down, but if they had failed....

rgds, Alan
[0] I'm in the process of building a replacement - with *only* the
binaries I want on it - and LIDS controlling what binaries can bind to
what ports.

-- 
99 Ducati 748BP, 95 Ducati 600SS, 81 Guzzi Monza, 74 MV Agusta 350
"Ride to Work, Work to Ride" SI# 7.067 DoD#1930 PGP Key 0xBDED56C5



Relevant Pages

  • Re: Fast releases demand binary updates.. (Was: Release schedule for 2006 )
    ... > binaries, including X11, KDE, printing, Mozilla, etc worked just fine. ... > Upgrading the ports from there was somewhat annoying, ... libs/apps from pkg_add which are trying to link to libraries installed via ... grab binaries and install them... ...
    (freebsd-current)
  • Re: Is FreeBSD 5.2.1 on Opteron a 64 bits OS?
    ... downloading an ISO of CURRENT for amd64, but couldn't get it to burn ... I was referring to the ports collection. ... in the kernel itself) and any other ports that require Linux emulation. ... support for running binaries compiled for the 32-bit i386 platform. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: LaTeX oder teTeX
    ... What you do need to do after building the binaries is add ... TeXlive system cohabit with ports that wants teTeX. ... TeX system, no matter which one it is''? ...
    (freebsd-questions)
  • Re: kde applications crash (Was: no permissions to libc.so.x libpthread.so.x and other files)
    ... Recompile all your ports. ... binaries linked to libc.so.5, you need to recompile all your ports. ... you may delete all unreferenced libraries (according ...
    (freebsd-current)
  • Re: AMD64 Stability with 6.1+?
    ... with AMD64 systems using FreeBSD (the 64-bit binaries)? ... majority of PORTS in the tree? ...
    (freebsd-questions)

Loading