LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-03-2001, 08:48 PM   #1
Kid_Gloves
LQ Newbie
 
Registered: May 2001
Posts: 2

Rep: Reputation: 0
Talking


Hiyas folks,

i just installed redhat 7.2 and was wondering with that install(I did a workstation class install) is there any servers that were installed on my system that would leave me vuneralble to security threats?Also theres a nuke for IRC that allows someone to send an unprotocol error packet to the victim with the IRC server as the apperant sender that would reset the victims connection to that server, My question is would linux be exploitable this way?
 
Old 05-04-2001, 04:41 AM   #2
raz
Member
 
Registered: Apr 2001
Location: London
Posts: 408

Rep: Reputation: 31
Answer to that question is yes.
type netstat -l and see all the ports listening for connections.

Anyone of these ports could have a security issue just waiting to happen.

What you need to do is decided which ones you don't use and remove them, then decide if the ones you do use can be used from one fixed IP address or does the whole world need to see it like IRC.

This is where you put up a firewall or use simple tcp wrappers in hosts.allow and hosts.deny.

Answering your question on that kiddy nuke thing.
It's not going to work if you set your firewall not to respond to ICMP type 3 errors, the only problem with this is if your network connection goes down external connection won't know about it and keep retrying your IP address.

Also due to this nuke using ICMP messages as its DOS attack, it's still part of TCP so they have to guess the sequencer number of the IRC client connected to the socket.

On NT 4.0 easy on Linux just about imposable.
The Linux stack is using random positive increments, not time dependent sequenced numbers.

Best advice is put up a firewall.
/Raz
 
Old 05-04-2001, 08:38 AM   #3
woodchuck
LQ Newbie
 
Registered: Apr 2001
Posts: 9

Rep: Reputation: 0
I've always found -p useful on netstat. If you run it as root, it can help you identify exactly which daemon to turn off.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Two servers! jay3d Linux - Networking 1 08-19-2005 07:15 AM
Servers Casper12 Linux - Newbie 2 08-07-2005 04:37 PM
servers upload-3 Linux - Networking 1 12-15-2004 02:44 AM
one or two servers jeffpoulsen Linux - Networking 2 06-22-2004 07:43 AM
servers... kr00sh1n80r Linux - Networking 2 04-04-2002 08:04 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:25 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration