Re: crack my machine

From: Ben Measures (saint_abroadremove_at_removehotmail.com)
Date: 01/22/04


Date: Thu, 22 Jan 2004 04:52:20 +0000

charly wrote:
> Greetings,
>
> I run my linux box at home which is behind a modem-Router
>
> every request on port 21,22 are routed to my box.
> I installed (ok with a lot of help from you people :) ) an iptables
> script as a firewall.
>
> When I ping my ip, I, in fact ping the router, don't I ?

Yes, the router responds to the ping. Doesn't matter if you're in your
network or on the internet. Ignore NeoSadist.

> So the machine behind the router can not be accessed from outside
> excepted for the ports which are routed ?

Yes and no. If all is well, the machine inside can only be accessed by
computers it first makes a connection with, or by external computers
through the forwarded ports. However, if the outside controls your
router, then the machine is open to all attacks on all ports. So make
sure your machine is secure anyways.

Short lesson: Don't count the village walls to keep marauders out - lock
your house door.

> If I do a port-scan of the ip, I scan the router and not the machine
> as well....

Yes, all except for the forwarded ports.

> So my question is :
>
> If my machine, were to be hacked it could only be through the 21,22 ports ?
Or through the firewall/router and then through any port on your machine.

> Networks security is more like to a hobby to me and I'll get no training
> in this field of computer sciences so I welcome any links regarding this.
>
> I am trying to collect links on the subject to read on my spare time so
> Google is my friend but you're knowledge is valuable as well. I am
> reading netfilter.org and then will write this group's archive but if
> you have some good links ....
>
> many thx for your attention.

http://www.gentoo.org/doc/en/gentoo-security.xml
This was written with Gentoo Linux in mind but virtually all of it is
applicable to any Linux installation. Its a good place to start.

-- 
Ben M.
----------------
What are Software Patents for?
To protect the small enterprise from bigger companies.
What do Software Patents do?
In its current form, they protect only companies with
big legal departments as they:
a.) Patent everything no matter how general
b.) Sue everybody. Even if the patent can be argued
	invalid, small companies can ill-afford	the
	typical $500k cost of a law-suit (not to mention
	years of harassment).
Don't let them take away your right to program
whatever you like. Make a stand on Software Patents
before its too late.
Read about the ongoing battle at http://swpat.ffii.org/
----------------


Relevant Pages

  • Re: Linux executable picks up FreeBSD library over linux one and breaks
    ... But if it is in a subdirectory where no FreeBSD lib resides, it is ok (the linux browser sets LD_LIBRARY_PATH in the start script to the right path). ... Have a look how the native browser works, the private libs are not in ldconfig either and the browser start script sets the library path for the browser binary. ... don't care for ports to do at all. ... install libs or hide the libs in special dirs), ...
    (freebsd-hackers)
  • Re: crack my machine
    ... >]computers it first makes a connection with, ... >]router, then the machine is open to all attacks on all ports. ... What are Software Patents for? ...
    (comp.os.linux.security)
  • Re: which linux? (not flame bait, thank you)
    ... > Portupgrade really helps with maintaining ports. ... I would like to have a little exposure to linux ... > keep my server and desktop running with the same versions, ... 'full' RH or SuSE install, but slightly behind the times, as is Debian, ...
    (freebsd-questions)
  • Re: Linux executable picks up FreeBSD library over linux one and breaks
    ... But if it is in a subdirectory where no FreeBSD lib resides, it is ok (the linux browser sets LD_LIBRARY_PATH in the start script to the right path). ... Have a look how the native browser works, the private libs are not in ldconfig either and the browser start script sets the library path for the browser binary. ... don't care for ports to do at all. ...
    (freebsd-hackers)
  • Re: many packages not available
    ... "install" a port because the port at install stage pulls another ... And ports that do not build on *your* machine for whatever reason, ... for example in Gentoo Linux, I miss some much more basic features like ... USB WLAN on Linux, that hurts. ...
    (comp.unix.bsd.freebsd.misc)

Quantcast