Results 1 to 7 of 7

Thread: Knoppix 3.9 Kernel 2.6.11 iptables string-match

Hybrid View

  1. #1
    Junior Member registered user
    Join Date
    Sep 2005
    Posts
    10

    Knoppix 3.9 Kernel 2.6.11 iptables string-match

    I need some help, perhaps directly by klaus.
    I just started working with iptables and wondering, that by default iptables "only" scans the packet-headers.
    Well in my case it makes for sence, scanning the packet-contents. This is why i tried compiling the string-match out of patch-o-matic-ng.
    I installed the newest iptables and got the latest version of patch-o-matic including string-match. The latest patch-o-matic does not include string match anymore. (Anyone knowing why?).
    Compiling failed and i added some lines in code, but didn't help.
    So I had a look at my old knoppix 3.9 with kernel 2.6.11 installed. (On my PC i have knoppix 4.0 installed). And surprisingly i found a compiled kernel-module for the string-match!
    But that doesn't help a lot when there are no sources.
    Does anyone have a "good" source of ipt_string, which works with 2.6.12 kernel? (iptables 1.3.3)

    PLEASE Help.

    @Klaus: Perhaps you have the sources of the string match in knoppix 3.9? I cannot find them

  2. #2
    Junior Member registered user
    Join Date
    Sep 2005
    Posts
    10
    No idea?
    Please have a look at it and try to help ...

  3. #3
    Senior Member registered user
    Join Date
    Nov 2002
    Location
    Long Island, NY USA
    Posts
    1,510
    Klaus Knopper is usually too busy to check these forums. So can contact him & other Knoppix developers at their mailing list http://lists.debian.org/debian-knoppix/

  4. #4
    Junior Member registered user
    Join Date
    Sep 2005
    Posts
    10

    Re: Knoppix 3.9 Kernel 2.6.11 iptables string-match

    Quote Originally Posted by floschi
    perhaps directly by klaus.
    This should not mean, that he's the only guy, who could solve it. Anyone else could also have a solution.

  5. #5
    Junior Member registered user
    Join Date
    Sep 2005
    Posts
    10
    The last left error occuring in compilation is:
    176: error: Initialisierungs-Element ist zur Lade-Zeit nicht berechenbar
    (near initialization for 'string_match.revision')
    If i should translate the first quoted line it means:
    "Initialization-element can't be calculated within loading-time"

    The Code leading to this:

    Code:
    static struct ipt_match string_match
    = { { NULL, NULL }, "string", &match, &checkentry, NULL, THIS_MODULE };
    It is in most cases near line 176.

    Does anyone know what's going on here?

  6. #6
    Junior Member registered user
    Join Date
    Sep 2005
    Posts
    10
    And the solution I found yesterday is:

    replace the above quoted Code with the following:

    Code:
    static struct ipt_match string_match = {
       .name       = "string",
       .checkentry   = checkentry,
       .me       = THIS_MODULE
    };
    And then have fun!
    My Problem: After compiling the kernel nothing worked any more But that's another story ...

  7. #7
    Junior Member registered user
    Join Date
    Sep 2005
    Posts
    10
    I experienced another problem after compiling the ipt_string.c
    Now i get a Kernel PANIC!
    I set up a rule for dropping all icmp requests coming from a speacial host with hex-string-matching
    "7f656c66". Now when I am sending this hex-string via "ping" from the host, my Firewall get's a Kernel PANIC.
    The PANIC accures when ipt_do_table is in stack. So does anyone know this error? I have no idea how to deal with it. The module is properly loaded.
    Perhaps there is another module missing?

    The rule:
    iptalbes -I INPUT -m string --hex-string 7f656c66 -p icmp -s vvv.xx.y.zz -j DROP


    .. you could call it a "Ping of death" - but I don't like that. Kernel: 2.6.12.2; iptables: 1.3.3


    Unable to handle kernel NULL pointer

    Oops: 0000 [#1]
    EIP: 0060
    EFLAGS: 00010206
    EIP is at rest_init 0x3feffd6c/ox28
    Process swapper (pid:0
    Call Trace:

    ipt_do_table
    ip_local_deliver_finish
    ipt_hook
    nf_iterate
    ip_local_deliver_finish
    ip_local_deliver
    ip_local_deliver_finish
    ip_rcv
    netif_recieve_skb
    process_backlog
    net_rx_action
    _do_softirq
    irq_exit
    do_IRQ
    common_interrupt
    default_idle
    default_idle
    cpu_idle
    start_kernel
    Code: Bad EIP value
    Kernel PANIC - not syncing: Fatal exception in interrupt

Similar Threads

  1. iptables configuration
    By DieselDriver in forum Networking
    Replies: 3
    Last Post: 03-03-2005, 02:44 PM
  2. Setting up iptables on Knoppix HD install
    By Neo-Rio in forum General Support
    Replies: 2
    Last Post: 04-08-2004, 08:05 AM
  3. basic firewall rules for iptables
    By zebul666 in forum Ideas
    Replies: 4
    Last Post: 04-07-2004, 07:00 AM
  4. Need help with iptables
    By Markus in forum Networking
    Replies: 6
    Last Post: 01-24-2004, 07:27 PM
  5. IPtables script, submitted for consideration
    By Dave_Bechtel in forum Hdd Install / Debian / Apt
    Replies: 1
    Last Post: 10-11-2003, 05:27 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


OPNsense pfSense 8-Core Atom C3758 2.2GHz 8GB DDR4 64GB SSD 8x NIC QAT AES VPN picture

OPNsense pfSense 8-Core Atom C3758 2.2GHz 8GB DDR4 64GB SSD 8x NIC QAT AES VPN

$145.00



pfSense Firewall 16-Core Atom C3958 8GB DDR4 RAM 64GB SSD 8x 1Gbe QAT AES-NI VPN picture

pfSense Firewall 16-Core Atom C3958 8GB DDR4 RAM 64GB SSD 8x 1Gbe QAT AES-NI VPN

$184.99



NETGEAR ProSafe 8-Port Gigabit VPN Firewall FVS318G NEW IN BOX picture

NETGEAR ProSafe 8-Port Gigabit VPN Firewall FVS318G NEW IN BOX

$69.99



SonicWall TZ280 Firewall 03-SSC-6933 Advanced Edition 3YR NEW SEALED picture

SonicWall TZ280 Firewall 03-SSC-6933 Advanced Edition 3YR NEW SEALED

$999.99



Firewalla Gold Pro - 10 Gbps Cyber Security Firewall picture

Firewalla Gold Pro - 10 Gbps Cyber Security Firewall

$610.00



Fortinet FortiGate 60F FG-60F P24286-03-13 Network Firewall Security Appliance picture

Fortinet FortiGate 60F FG-60F P24286-03-13 Network Firewall Security Appliance

$155.75



OPNsense pfSense 16-Core Atom C3958 16GB ECC RAM 512GB SSD 8-Port QAT AES-NI VPN picture

OPNsense pfSense 16-Core Atom C3958 16GB ECC RAM 512GB SSD 8-Port QAT AES-NI VPN

$248.00



TWO (2) Firewalla Gold Pro Devices - 10 Gbps Cyber Security Firewall picture

TWO (2) Firewalla Gold Pro Devices - 10 Gbps Cyber Security Firewall

$1111.00



Protectli Vault FW4C-0-8-120 - 4 port, Quad Core, 8GB RAM, 128GB picture

Protectli Vault FW4C-0-8-120 - 4 port, Quad Core, 8GB RAM, 128GB

$180.00



Zero Trace Pen: All-in-one Tor Network Anonymous Drive + Cryptocurrency Wallet picture

Zero Trace Pen: All-in-one Tor Network Anonymous Drive + Cryptocurrency Wallet

$147.00