Page 2 of 2 FirstFirst 12
Results 11 to 12 of 12

Thread: Knoppix & Security : Ongoing Issue

  1. #11
    Senior Member registered user
    Join Date
    Nov 2002
    Location
    USA, IL
    Posts
    1,041
    --With a sufficient number of users, you will eventually run out of available seperate partitions, even with Extended/Logical in effect. Somewhere around 16, 20 or mebbe 24 I think. (Altho I've never had to have that many myself. I think the most I've gone up to is around 12 or 13, and that's on an 80-gig HD.) However, you might get around this limitation with multiple HD's and multiple "home-only" server boxes with NFS.

    --Putting /home itself on a separate partition is a good idea though, as it can last through various flavors of Linux as well as being a bit more secure.

    --Which flavor do you run on your Linux router? Have you used LRP*, and do you recommend it?

    --The part that I'm most interested in, having never done a software router myself (tried the Linksys hardware DSL sharing solution, but since it only uses class C (192.168...) it didn't work with my Class A setup {10.0...}) is the actual rules that people use in RL. Rickenbacherus, if you or anyone else could post an example of what specific rules you use and why, it would be a great help to me.

    ( * LRP:
    http://freshmeat.net/projects/linuxr.../?topic_id=864,
    http://www.linuxrouter.org/ )

    Quote Originally Posted by rickenbacherus
    Your concerns John Doe are why I choose to run a Linux router....(snip)

    If you want real security build your own router. Boot the OS from a removable disc, either a floppy or cdrom. If your router OS is installed on a hard drive then it can be written to- period.

    (snip)
    Build a router, make it small, make it cool looking- install Linux to your network machines, put each users /home directory on a seperate partition, don't get lazy with permissions and you will likely never reinstall an OS again.

    Well ok that's not entirely true. You see...............Linux in and of itself is highy addictive and you will soon find yourself saying "so many distro's so little time".

  2. #12
    Senior Member registered user
    Join Date
    Mar 2003
    Location
    colorado springs, colorado
    Posts
    1,933
    Quote Originally Posted by Dave_Bechtel
    --With a sufficient number of users, you will eventually run out of available seperate partitions, even with Extended/Logical in effect. Somewhere around 16, 20 or mebbe 24 I think. (Altho I've never had to have that many myself. I think the most I've gone up to is around 12 or 13, and that's on an 80-gig HD.) However, you might get around this limitation with multiple HD's and multiple "home-only" server boxes with NFS.
    True....I have never had that many either but certainly it would be possible to run out.

    Here is _Shields Up which just scans some commmon ports- note the hilarious dialouge about windows network machines....
    ----------------------------------------------------------------------------------------------------------

    Shields UP! is checking YOUR computer's Internet
    connection security . . . currently located at IP:

    xx.xx.xx.xx

    Please Stand By. . .

    Attempting connection to your computer. . .
    Shields UP! is now attempting to contact the Hidden Internet Server within your PC. It is likely that no one has told you that your own personal computer may now be functioning as an Internet Server with neither your knowledge nor your permission. And that it may be serving up all or many of your personal files for reading, writing, modification and even deletion by anyone, anywhere, on the Internet!


    Preliminary Internet connection refused!
    This is extremely favorable for your system's overall Windows File and Printer Sharing security. Most Windows systems, with the Network Neighborhood installed, hold the NetBIOS port 139 wide open to solicit connections from all passing traffic. Either this system has closed this usually-open port, or some equipment or software such as a "firewall" is preventing external connection and has firmly closed the dangerous port 139 to all passersby. (Congratulations!)


    Unable to connect with NetBIOS to your computer.
    All attempts to get any information from your computer have FAILED. (This is very uncommon for a Windows networking-based PC.) Relative to vulnerabilities from Windows networking, this computer appears to be VERY SECURE since it is NOT exposing ANY of its internal NetBIOS networking protocol over the Internet.
    ----------------------------------------------------------------------------------------------------------

    Now- just for the fun of it let's add these rules to the ipchains:

    /sbin/ipmasqadm autofw -A -r tcp 1 65535 -h 192.168.0.99
    /sbin/ipmasqadm autofw -A -r udp 1 65535 -h 192.168.0.99
    These rules will stealth all ports by forwarding them to a non-existant machine on my network.

    Ok let's do the port scan at shieldsup again:
    ---------------------------------------------------------------------------------------------------------
    Your Internet port 139 does not appear to exist!
    One or more ports on this system are operating in FULL STEALTH MODE! Standard Internet behavior requires port connection attempts to be answered with a success or refusal response. Therefore, only an attempt to connect to a nonexistent computer results in no response of either kind. But YOUR computer has DELIBERATELY CHOSEN NOT TO RESPOND (that's very cool!) which represents advanced computer and port stealthing capabilities. A machine configured in this fashion is well hardened to Internet NetBIOS attack and intrusion.

    Unable to connect with NetBIOS to your computer.
    All attempts to get any information from your computer have FAILED. (This is very uncommon for a Windows networking-based PC.) Relative to vulnerabilities from Windows networking, this computer appears to be VERY SECURE since it is NOT exposing ANY of its internal NetBIOS networking protocol over the Internet.
    ----------------------------------------------------------------------------------------------------------

    Here's Sygate's results:

    FTP DATA

    20

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    FTP

    21

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    SSH

    22

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    TELNET

    23

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    SMTP

    25

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    DNS

    53

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    DCC

    59

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    FINGER

    79

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    WEB

    80

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    POP3

    110

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    IDENT

    113

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    NetBIOS

    139

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    HTTPS

    443

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    Server Message Block

    445

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    SOCKS PROXY

    1080

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    WEB PROXY

    8080

    BLOCKED

    This port has not responded to any of our probes. It appears to be completely stealthed.

    SOURCE PORT

    61897

    BLOCKED

    This is the port you are using to communicate to our Web Server. A firewall that uses Stateful Packet Inspection will show a 'BLOCKED' result for this port.



    I think that this should quash any doubts about how secure a Linux router can be. I'd love to see some dlink and netgear results.

    I use Coyote Linux which borrows heavily from LRP. In fact some of the LRP add-on packages have been converted for use in Coyote. I can access my router via web browser, make backup copies of my router floppy, ssh, restart firewall rules with a simple command of firewall-r and a host of other features.
    Of course I'll need to unstealth a port for ssh to work again.

Page 2 of 2 FirstFirst 12

Similar Threads

  1. Security ISSUE for netowrk ???
    By prelude in forum Networking
    Replies: 7
    Last Post: 09-15-2004, 04:17 AM
  2. knoppix security
    By lordb in forum Hdd Install / Debian / Apt
    Replies: 1
    Last Post: 05-02-2004, 06:43 AM
  3. SECURITY ISSUE
    By alxdotnet in forum Hdd Install / Debian / Apt
    Replies: 0
    Last Post: 02-12-2004, 05:57 PM
  4. Knoppix Security
    By Bd84 in forum General Support
    Replies: 12
    Last Post: 05-27-2003, 04:16 PM
  5. Knoppix and security
    By WT in forum General Support
    Replies: 1
    Last Post: 12-31-2002, 09:21 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


GIGABYTE A520M DS3H AC AMD AM4 Motherboard mATX picture

GIGABYTE A520M DS3H AC AMD AM4 Motherboard mATX

$59.99



Intel H310 LGA1151 8-9th Gen DDR4 M.2 NVMe mATX Motherboard IO Shield Battery picture

Intel H310 LGA1151 8-9th Gen DDR4 M.2 NVMe mATX Motherboard IO Shield Battery

$54.99



⁠Intel H81 Motherboard M.2 NVMe LGA 1150 mATX w/ IO Shield (Random Slot Color)⁠ picture

⁠Intel H81 Motherboard M.2 NVMe LGA 1150 mATX w/ IO Shield (Random Slot Color)⁠

$29.90



ASUS B85M-G / B85M-G PLUS LGA1150 DDR3 Micro ATX Motherboard HDMI Support 4thCPU picture

ASUS B85M-G / B85M-G PLUS LGA1150 DDR3 Micro ATX Motherboard HDMI Support 4thCPU

$45.00



GIGABYTE B365 HD3 LGA1151 Intel 9th Gen motherboard picture

GIGABYTE B365 HD3 LGA1151 Intel 9th Gen motherboard

$59.99



ASUS PRIME B360M-C MicroATX Intel LGA1151 DDR4 HDMI VGA USB RJ-45 Audio picture

ASUS PRIME B360M-C MicroATX Intel LGA1151 DDR4 HDMI VGA USB RJ-45 Audio

$34.99



ASRock B550M PRO4 AM4 AMD B550 SATA 6Gb/s Micro ATX AMD Motherboard picture

ASRock B550M PRO4 AM4 AMD B550 SATA 6Gb/s Micro ATX AMD Motherboard

$76.49



ASUS PRIME Z370-A II LGA 1151 Intel Z370 DDR4 DIMM USB3.1 DVI  ATX RGB picture

ASUS PRIME Z370-A II LGA 1151 Intel Z370 DDR4 DIMM USB3.1 DVI ATX RGB

$69.99



B85M-G Motherboard Intel Core i7-4770 CPU LGA1150 mATX 4 DIMM IO Shield picture

B85M-G Motherboard Intel Core i7-4770 CPU LGA1150 mATX 4 DIMM IO Shield

$75.96



ASRock Z370 Pro4 LGA 1151 Z370 HDMI USB 3.1 2 Ultra M.2 DDR4 ATX Motherboard picture

ASRock Z370 Pro4 LGA 1151 Z370 HDMI USB 3.1 2 Ultra M.2 DDR4 ATX Motherboard

$75.00