Re: XP box inside the firewall

2003-07-30 Thread Kristof Goossens
On Wed, Jul 30, 2003 at 02:01:06PM +0200, Kjetil Kjernsmo wrote: > Hi all! [snip] > The question is really if I could do something in the firewall that > would help isolate the XP box somewhat. Closing outgoing ports (input > ports are all closed), drop certain types of packages, or something

Re: XP box inside the firewall

2003-07-30 Thread Kristof Goossens
On Wed, Jul 30, 2003 at 02:01:06PM +0200, Kjetil Kjernsmo wrote: > Hi all! [snip] > The question is really if I could do something in the firewall that > would help isolate the XP box somewhat. Closing outgoing ports (input > ports are all closed), drop certain types of packages, or something

Re: iptables rule to drop from sources that are -nat postrouting from the outside to inside

2003-05-31 Thread Kristof Goossens
On Fri, May 30, 2003 at 09:20:19AM +0200, Filippi Marco wrote: [snip] > > > how can they be dropped? > > > > not sure, but I think that it'll work when you specify the outside > > interface... For example: if you want to drop the http requests from > > w.x.y.z then your rule should look like: > >

Re: iptables rule to drop from sources that are -nat postrouting from the outside to inside

2003-05-31 Thread Kristof Goossens
On Fri, May 30, 2003 at 09:20:19AM +0200, Filippi Marco wrote: [snip] > > > how can they be dropped? > > > > not sure, but I think that it'll work when you specify the outside > > interface... For example: if you want to drop the http requests from > > w.x.y.z then your rule should look like: > >

Re: iptables rule to drop from sources that are -nat postrouting from the outside to inside

2003-05-30 Thread Kristof Goossens
On Thu, May 29, 2003 at 11:19:24PM -0500, Hanasaki JiJi wrote: > I have a nat postrouting rule that passes traffice from the outside > world to an internal host to handle port 80 (webserver) > > there are also rules to drop certain source addresses yet these > addresses are still coming through

Re: iptables rule to drop from sources that are -nat postrouting from the outside to inside

2003-05-30 Thread Kristof Goossens
On Thu, May 29, 2003 at 11:19:24PM -0500, Hanasaki JiJi wrote: > I have a nat postrouting rule that passes traffice from the outside > world to an internal host to handle port 80 (webserver) > > there are also rules to drop certain source addresses yet these > addresses are still coming through

Re: Should I use Snort/PortSentry?

2003-05-23 Thread Kristof Goossens
On Thu, May 22, 2003 at 08:46:47PM -0400, Rob French wrote: [snip] > So, are any network/port-related tools useful? In my personal opinion it is ALWAYS usefull to know what is going on on your system. No mather how little ports are open... You said it was for your laptop, and thats why you sho

PHP & imap-ssl support

2003-05-21 Thread Kristof Goossens
Hello all, I want to use debian packages for imap-ssl support in php4. regular imap works fine after installing the php4-imap package; however the imap-ssl does not work. In the output of phpinfo() I can see that my php4 (debian stable package) was configured with the option --with-imap, but not -

Re: Snort signature download script

2003-04-27 Thread Kristof Goossens
On Sat, Apr 26, 2003 at 12:52:58PM +0200, Konstantin Filtschew wrote: > hi, > > there is a signature download script posted on > http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=173254 > > from http://www.xssass.be > > I tried it, but he tells me, that the md5 checksum is wrong > > you can down

Re: Snort signature download script

2003-04-26 Thread Kristof Goossens
On Sat, Apr 26, 2003 at 12:52:58PM +0200, Konstantin Filtschew wrote: > hi, > > there is a signature download script posted on > http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=173254 > > from http://www.xssass.be > > I tried it, but he tells me, that the md5 checksum is wrong Ah... :( There w

Re: text mode virtual terminal auto lock

2003-03-13 Thread Kristof Goossens
On Thu, Mar 13, 2003 at 06:48:58AM +, Aurelio Turco wrote: > I have looked around for a screen lock > for the text mode virtual terminal > that activates automatically after > a certain amount of idle time > but could not find even one. > > Does anyone know of any? vlock does the locking part

Re: text mode virtual terminal auto lock

2003-03-12 Thread Kristof Goossens
On Thu, Mar 13, 2003 at 06:48:58AM +, Aurelio Turco wrote: > I have looked around for a screen lock > for the text mode virtual terminal > that activates automatically after > a certain amount of idle time > but could not find even one. > > Does anyone know of any? vlock does the locking part

securing pop3

2003-02-08 Thread Kristof Goossens
Hello all, I need to make a pop3 account on my server. I intend to work with ipop3d to provide secure pop3 service. Now I want to provide this service for only few people, and I don't want them to have an account on the system. Well, they can have a pop3 account, but no other access whatsoever...

securing pop3

2003-02-08 Thread Kristof Goossens
Hello all, I need to make a pop3 account on my server. I intend to work with ipop3d to provide secure pop3 service. Now I want to provide this service for only few people, and I don't want them to have an account on the system. Well, they can have a pop3 account, but no other access whatsoever...

Re: cluster on firewall?

2003-02-06 Thread Kristof Goossens
On Thu, Feb 06, 2003 at 03:09:34AM +0200, Haim Ashkenazi wrote: > Hi > > I have setup a firewall with 4 legs as follows: > * One leg goes to the router (cisco). > * Second leg goes to a switch connected to the internal network > (10.20...). > * The third and fourt

Re: cluster on firewall?

2003-02-06 Thread Kristof Goossens
On Thu, Feb 06, 2003 at 03:09:34AM +0200, Haim Ashkenazi wrote: > Hi > > I have setup a firewall with 4 legs as follows: > * One leg goes to the router (cisco). > * Second leg goes to a switch connected to the internal network > (10.20...). > * The third and fourt

Re: question about SSH / IPTABLES

2003-01-23 Thread Kristof Goossens
On Thu, Jan 23, 2003 at 12:24:49PM +0100, Iñaki Martínez wrote: > Hi!!! > > I have a server in internet and i want several clients to access to it via > SSH but i DON'T want they to be able to use SSH from that server. > > So i client can access the server via SSH, but s/he CAN NOT ssh to other

Re: question about SSH / IPTABLES

2003-01-23 Thread Kristof Goossens
On Thu, Jan 23, 2003 at 12:24:49PM +0100, Iñaki Martínez wrote: > Hi!!! > > I have a server in internet and i want several clients to access to it via > SSH but i DON'T want they to be able to use SSH from that server. > > So i client can access the server via SSH, but s/he CAN NOT ssh to other

Re: Updating Snort Signatures In Stable ?

2002-12-06 Thread Kristof Goossens
if nessicery... I find this script very usefull and use it in combination with cron... Anyhow: this is the script located @ www.xssass.be... Kind regards, Kristof Goossens -- Digital fingerprint: F56F F987 0E0C AFF8 0B6D 7CA1 F152 E07D 72AF 337B pgpFWz2uly8PL.pgp Description: PGP signature

Re: Updating Snort Signatures In Stable ?

2002-12-06 Thread Kristof Goossens
if nessicery... I find this script very usefull and use it in combination with cron... Anyhow: this is the script located @ www.xssass.be... Kind regards, Kristof Goossens -- Digital fingerprint: F56F F987 0E0C AFF8 0B6D 7CA1 F152 E07D 72AF 337B msg08045/pgp0.pgp Description: PGP signature

Snort alert log

2002-11-14 Thread Kristof Goossens
010 Win: 0x0 TcpLen: 0 I don't know what this means however... Specially the ports seam strange to me. Any help would be appreciated! Thanks in advance, Kristof Goossens -- Digital fingerprint: F56F F987 0E0C AFF8 0B6D 7CA1 F152 E07D 72AF 337B pgprwbRh5dhNR.pgp Description: PGP signature

Snort alert log

2002-11-13 Thread Kristof Goossens
010 Win: 0x0 TcpLen: 0 I don't know what this means however... Specially the ports seam strange to me. Any help would be appreciated! Thanks in advance, Kristof Goossens -- Digital fingerprint: F56F F987 0E0C AFF8 0B6D 7CA1 F152 E07D 72AF 337B msg07728/pgp0.pgp Description: PGP signature

Re: port 6051: hacked?

2002-09-06 Thread Kristof Goossens
On Fri, Sep 06, 2002 at 12:16:39PM +0200, Ramin Motakef wrote: > Hi all, > Todays nmap run shows me: > > Interesting ports on (xx): > (The 59984 ports scanned but not shown below are in state: closed) > Port State Service > 21/tcp openftp > 22/tcp