Re: how to interpret this iptables log. My computer compromised?

From: Pete Houston (ph1_at_zapthisbit.openstrike.co.uk)
Date: 08/05/03

  • Next message: Ronny Roethof: "blocking non peering"
    Date: Tue, 05 Aug 2003 09:33:12 GMT
    
    

    In article <csWUa.299$Cx4.109497@news20.bellglobal.com>, H. S. wrote:
    > Jeremia d. wrote:
    > In the last hour or so, I was experimenting with some iptables scripts
    > and in the process I stopped iptables a few times (3 or 4) for a few
    > seconds, only long enough to let the next script run. Then I saved those
    > new rules with '/sbin/iptables -save'.
    >
    > Is this dangerous? Leaving my computer open only for a few seconds (3~10
    > sec)?

    In a word, yes. Of course, the longer you are "open" the more dangerous
    it is, but there is no need to be "open" at all. Simply take the
    relevant interface down, and make all your iptables mods while it is
    off-line. Only when you are sure that you are secure again, bring the
    interface back up. Hopefully you will see in your boot sequence that the
    iptables rules are processed before the interfaces are brought up, and
    this is the reason for that.

    Pete

    -- 
    Openstrike - improving business through open source
    http://www.openstrike.co.uk/
    

  • Next message: Ronny Roethof: "blocking non peering"

    Relevant Pages

    • Fwd: iptables related query
      ... iptables scripts from scratch :-) ... Subject: iptables related query ... amounts of traffic that won't pose any problem. ... more complicated ruleset will be needed. ...
      (Debian-User)
    • Re: How secure is secure?
      ... > Am I secure from hackers or should I still be worried about beefing up ... > security with added rules using iptables? ... look at Arno's IPTABLES scripts at www.freshmeat.net if you want a ...
      (comp.os.linux.security)
    • Re: help with iptables
      ... :away from this and start learning what iptables is all about and how to ... and everyone goes on about iptables scripts ... the 'iptables' command to install the rules one at a time. ... While the format of lines in that file closely resembles ...
      (comp.os.linux.networking)
    • Re: Ipchains
      ... > For RH9 you should really use iptables, ... > connection tracking firewall which gives much greater flexibility. ... > plenty of sample iptables scripts available online. ...
      (comp.os.linux)
    • Re: passive ftp problem
      ... echo " External Interface: $EXTIF" ... # If your Linux distribution came with a copy of iptables, ... Outgoing traffic from various internfaces. ...
      (comp.os.linux.security)

  • Quantcast