Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Networking & Security
  • Search

howto scan for security holes / test my firewall

Having problems getting connected to the internet or running a server? Wondering about securing your box? Ask here.
Post Reply
Advanced search
12 posts • Page 1 of 1
Author
Message
Qubax
Guru
Guru
User avatar
Posts: 451
Joined: Fri Jul 19, 2002 9:41 pm
Location: Tirol, Austria

howto scan for security holes / test my firewall

  • Quote

Post by Qubax » Tue Sep 10, 2002 4:49 pm

i got my fwbuilder emerged and running, compiled my script.
fwbuilder was not hard, so i want to know how good the script for th e firewall is

does somebody know a light program that tells my where a still have a security hole (don't want nessus - seems to be quit a big download and i just want to test my firewall)

thx
Top
delta407
Bodhisattva
Bodhisattva
User avatar
Posts: 2876
Joined: Tue Apr 23, 2002 12:16 am
Location: Chicago, IL
Contact:
Contact delta407
Website

Re: howto scan for security holes / test my firewall

  • Quote

Post by delta407 » Tue Sep 10, 2002 5:32 pm

Qubax wrote: does somebody know a light program that tells my where a still have a security hole (don't want nessus - seems to be quit a big download and i just want to test my firewall)
You generally want to rest your firewall from outside your firewall -- I would suggest nmap. Tell it to do agressive scans, fingerprinting, etc. and see what you can see. Fix any problems that arise. Lather, rinse, repeat.

Alternatively, you could post your IP address to the forum and we can test it for you. ;)
I don't believe in witty sigs.
Top
Qubax
Guru
Guru
User avatar
Posts: 451
Joined: Fri Jul 19, 2002 9:41 pm
Location: Tirol, Austria

  • Quote

Post by Qubax » Tue Sep 10, 2002 10:33 pm

yes i want to test my firewall from outside

i looked around and found scan.sygate.com that scans nearly all thinks i know
can somebody just try out one the scans and tell me if they tell the truth

i made all scans, it seems that if forgotten to block UDP (what ever that is, but as linuxer i'll find out about it) - have a look at fwbuilder

fwbuilder seems to be good - easy to use and seems to secure
Top
Chickpea
l33t
l33t
Posts: 846
Joined: Mon Jun 03, 2002 3:09 am
Location: Vancouver WA

  • Quote

Post by Chickpea » Tue Sep 10, 2002 11:43 pm

scan.sygate.com is the site I almost alway recommend. I have used this to test my system on several occasions and it seems okay. I generally run the test with and without the firewall running to compare results. I also use another site -https://grc.com/x/ne.dll?bh0bkyd2

Good luck.

C
Top
splooge
l33t
l33t
Posts: 636
Joined: Fri Aug 30, 2002 5:45 pm

  • Quote

Post by splooge » Wed Sep 11, 2002 12:49 am

scan.sygate.com doesn't work for me, page won't even load. I don't think it likes my tight firewall settings.

The other site can't find anything even responding on my system.

What's really scary is when i had apache up for a few days messing around with it, I checked out my web logs and there was at least 100 entries of the Nimda or Code Red virus scanning my web server (../../cmd.exe). It's simply amazing how many windows users don't know they're infected to heck and back.
Top
Xor
Tux's lil' helper
Tux's lil' helper
User avatar
Posts: 144
Joined: Sun Jul 07, 2002 11:05 am

  • Quote

Post by Xor » Wed Sep 11, 2002 1:12 pm

my 2c: take a notebook with nessus to one of your frinds and let it run... next try nmap with it's variuos options (Protocol Scan, OS Finderprint, Stealth Scan, Fin Scan etc)... oh... and one peace of advice, don't come up with the idea to disable all of icmp (filter it, but don't disable it...)

you may also want to try the linux-kernel patches included in gentoo (don't know if gentoo-kernel has but gentoo-crypto-kernel has) like OpenWall and GRSecurity - really nifty features... but if you're used to use a mouse don't touch it :twisted:

cheers
xor
Top
Qubax
Guru
Guru
User avatar
Posts: 451
Joined: Fri Jul 19, 2002 9:41 pm
Location: Tirol, Austria

  • Quote

Post by Qubax » Wed Sep 11, 2002 4:52 pm

has somebody an idea of how to block with fwbuilder? my fw should block everything that is incoming and let everything through that wants out, but it seems not to do this,cause scan.sygate.com tells me that udp is not blocked (ok, its closed, but i want it blocked)

kann somebody give my a hint of how to do that with fwbuilder

grc.com/x/ne.dll?bh0bkyd2 tells me that fw is working fine (could not detect me or any port), so with how much can i be confident?
Top
Qubax
Guru
Guru
User avatar
Posts: 451
Joined: Fri Jul 19, 2002 9:41 pm
Location: Tirol, Austria

  • Quote

Post by Qubax » Wed Sep 11, 2002 6:08 pm

a more detailed question
shouldn't

Code: Select all

iptables -N RULE_2
iptables -A INPUT -j RULE_2 
iptables -A RULE_2 -j LOG  --log-level info --log-prefix "RULE 2 -- REJECT "
iptables -A RULE_2 -j REJECT  --reject-with icmp-host-prohibited 
lock up everything from outside, cause this is the part of the script fwbuilder gives me, to reject everything

i also have

Code: Select all

iptables -N RULE_1
iptables -A INPUT -p udp -m multiport --destination-port 138,137,139,69 -j RULE_1 
iptables -A RULE_1 -j LOG  --log-level info --log-prefix "RULE 1 -- REJECT "
iptables -A RULE_1 -j REJECT  --reject-with icmp-host-prohibited 
to reject to ports for netbios-dgm/ns/ssn but it seems not to work (sygate says so)

is there something i have to compile into iptables?
Top
Craigo
Apprentice
Apprentice
User avatar
Posts: 249
Joined: Fri Aug 09, 2002 4:00 pm
Location: /dev/life

  • Quote

Post by Craigo » Wed Sep 11, 2002 7:04 pm

Check out this site below:

http://iptables-tutorial.haringstad.com/

I had my own firewall in ipchains and that guide + other help from peeps online really sorted out the switch to iptables. Take a look today!

-/Craigo/-
Top
davoid
n00b
n00b
User avatar
Posts: 26
Joined: Sat Jun 29, 2002 11:54 pm
Location: Montreal, Canada
Contact:
Contact davoid
Website

  • Quote

Post by davoid » Thu Sep 12, 2002 1:18 am

you might want to get ahold of netcat (nc) it's a great tool, IMHO
At first they laugh at you, then they ignore you then they fight you and then you win. --Gandhi
Top
splooge
l33t
l33t
Posts: 636
Joined: Fri Aug 30, 2002 5:45 pm

  • Quote

Post by splooge » Thu Sep 12, 2002 5:51 am

I use the iptables firewall script from here:

http://projectfiles.com/firewall/

Under the 'advanced' configuration section, set 'RFC_1122_COMPLIANT' to NO, this will disable everything incoming including icmp.

I also use the traffic shaper from here:

http://lartc.org/wondershaper/
Top
Qubax
Guru
Guru
User avatar
Posts: 451
Joined: Fri Jul 19, 2002 9:41 pm
Location: Tirol, Austria

  • Quote

Post by Qubax » Thu Sep 12, 2002 12:43 pm

http://projectfiles.com/firewall/ works great
easy to config +
all scans i found were completly blocked

thx to splooge

but now a newbie question: how kann i make it start while booting? just make a link to default runlevel? or doing something with rc-update?
Top
Post Reply

12 posts • Page 1 of 1

Return to “Networking & Security”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Authors
Gentoo is a trademark of the Gentoo Foundation, Inc. and of Förderverein Gentoo e.V.
The contents of this document, unless otherwise expressly stated, are licensed under the CC-BY-SA-4.0 license.
The Gentoo Name and Logo Usage Guidelines apply.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy