RE: Port Disable
"Alistair Francis" <ali-QGBN+/qDeXgGFrCMPLEOK/d9D2ou9A/[email protected]> Thu, 14 Oct 2004 13:07:48 +0200
| Newsgroups | gmane.comp.security.firewalls.smoothwall.general |
|---|---|
| Message-ID | <[email protected]> |
I'm guessing it would be something like this? /sbin/iptables -A FORWARD -p TCP -i $GREEN_DEV -s 0/0 --dport:xxx -j DROP Where xxx is the port number that the virus is using. Can anyone confirm if I'm right, if so, I just learned something! ;) Rgds, Alistair Francis Systems Administrator Comm Express Services SA (PTY) LTD TEL: +27 (0)11 475-5567 FAX: +27 (0)11 475-6238 CELL: +27 (0)82 608-0181 The information contained in this electronic mail message is confidential to the Matragon group of companies and may enjoy legal privilege. The contents are intended solely for the addressee and access thereto by anyone else is unauthorised. Should you not be the intended recipient, kindly delete the message and inform us. Any disclosure, copying or distribution is prohibited and may be unlawful. Please also note that any action taken, or omitted to be taken in reliance on the information contained herein is done at your own risk. -----Original Message----- From: [email protected] [mailto:[email protected]]On Behalf Of Varady Zoltan Sent: 14 October 2004 12:42 To: [email protected] Subject: Re: [gpl] Port Disable Thanks for Your help. It is a realy good site. I read these lines there but... how can I do that how all of the computer in the network can't use the xxx port. Can I insert 192.168.0.0 or somthing like this to blokk all of the network's Pc. "To block specific traffic from a PC on your green network (ie, web traffic on port 80), use # block all outgoing web traffic from this PC /sbin/iptables -A FORWARD -p TCP -i $GREEN_DEV -s 192.168.0.3 --dport 80 -j DROP" OFF We have a Rbot-Fam Virus (bling.exe) and we cant kill him because he always come back somehow. We put the MS patches to our computers and we removed the virus from the infected computers in safe mode but when you restart the PC it is again in the system32. So I think he downloads himself from the others infected computers. It wont solve the problem but it is good to know how can I disable a port on SW to defend our network. /OFF ----- Original Message ----- From: "Samuel Gordon-Stewart" <smoothwallsamuel-/[email protected]> To: "Varady Zoltan" <[email protected]>; <[email protected]> Sent: Thursday, October 14, 2004 11:42 AM Subject: Re: [gpl] Port Disable > --- Varady Zoltan <[email protected]> wrote: > > Can I disable some port in the SW against the > > viruses ? > All incoming ports are blocked, however outgoing ports > can be blocked, see > http://martybugs.net/smoothwall/iptables.cgi for > details. > > samuel > > ===== > I must be really old in dog years! > Listen to my lovely music www.thefunkyasylum.com/notnice.mp3 > Protect your network www.smoothwall.org > > > > _______________________________ > Do you Yahoo!? > Declare Yourself - Register online to vote today! > http://vote.yahoo.com _______________________________________________ gpl mailing list [email protected] http://lists.smoothwall.org/mailman/listinfo/gpl SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall _______________________________________________ gpl mailing list [email protected] http://lists.smoothwall.org/mailman/listinfo/gpl SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall