Re: nmap 113/auth on shorewall



On 17.06.2006, dshesnicky@xxxxxxxxx <dshesnicky@xxxxxxxxx> wrote:

I didn't ask if you use any service from firewall. I asked if you use
IRC or FTP _anywhere_.

Someone could be using either from inside the company
through the firewall - why? I understand why your asking

No, you don't. FTP and IRC (often) use ident protocol to determine the
username on remote machine of connecting user (that is, on user's
machine). Try guess how long would be delay if you DROP packets and if
you REJECT them.
Every "how to build my first firewall" document teaches that.

but if it needs to be on I should see it in my configs. What
bothers me is that it shouldn't even be there, it makes me
wonder about shorewall to some extent.

I think what I will do is put a specific DROP rule on it to
if it changes anything.


--
Feel free to correct my English
Stanislaw Klekot
.



Relevant Pages

  • Re: cannot connect..
    ... yes, I can ping from the remote machine, IP is correct ... they are on the same lan and there is a firewall on the ftp server ... I just tried turning off the firewall and it connected! ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: nmap 113/auth on shorewall
    ... IRC or FTP _anywhere_. ... username on remote machine of connecting user (that is, ... Every "how to build my first firewall" document teaches that. ...
    (comp.os.linux.security)
  • Re: nmap 113/auth on shorewall
    ... IRC or FTP _anywhere_. ... through the firewall - why? ... wonder about shorewall to some extent. ...
    (comp.os.linux.security)
  • Re: nmap 113/auth on shorewall
    ... Do you use IRC or FTP? ... I didn't ask if you use any service from firewall. ... Feel free to correct my English ...
    (comp.os.linux.security)
  • Re: cannot connect..
    ... Information About the IIS File Transmission Protocol (FTP) Service ... How can I find a way for ppl outside the> lan to reach it? ... >> a) yes, I can ping from the remote machine, IP is correct ... >> c) they are on the same lan and there is a firewall on the ftp server ...
    (microsoft.public.inetserver.iis.ftp)