FW: Port Disable

"Alistair Francis" <ali-QGBN+/qDeXgGFrCMPLEOK/d9D2ou9A/[email protected]> Thu, 14 Oct 2004 13:11:19 +0200
Newsgroups gmane.comp.security.firewalls.smoothwall.general
Message-ID <[email protected]>
Please ignore the colon (:) between --dport and xxx. Oops!

Rgds,

Ali

-----Original Message-----
From: Alistair Francis [mailto:ali-QGBN+/qDeXgGFrCMPLEOK/d9D2ou9A/[email protected]]
Sent: 14 October 2004 13:08
To: SMOOTHWALL
Cc: Varady Zoltan
Subject: RE: [gpl] Port Disable


I'm guessing it would be something like this?

/sbin/iptables -A FORWARD -p TCP -i $GREEN_DEV -s 0/0 --dport:xxx -j DROP

Where xxx is the port number that the virus is using.

Can anyone confirm if I'm right, if so, I just learned something! ;)

Rgds,

Alistair Francis
Systems Administrator
Comm Express Services SA (PTY) LTD
TEL:    +27 (0)11 475-5567
FAX:   +27 (0)11 475-6238
CELL: +27 (0)82 608-0181

The information contained in this electronic mail message is confidential to
the Matragon group of companies and may enjoy legal privilege. The contents
are intended solely for the addressee and access thereto by anyone else is
unauthorised. Should you not be the intended recipient, kindly delete the
message and inform us. Any disclosure, copying or distribution is prohibited
and may be unlawful. Please also note that any action taken, or omitted to
be taken in reliance on the information contained herein is done at your own
risk.



-----Original Message-----
From: [email protected]
[mailto:[email protected]]On Behalf Of Varady Zoltan
Sent: 14 October 2004 12:42
To: [email protected]
Subject: Re: [gpl] Port Disable


Thanks for Your help. It is a realy good site.

I read these lines there but... how can I do that how all of the computer in
the network can't use the xxx port.
Can I insert 192.168.0.0 or somthing like this to blokk all of the network's
Pc.

"To block specific traffic from a PC on your green network (ie, web traffic
on port 80), use
# block all outgoing web traffic from this PC
/sbin/iptables -A FORWARD -p TCP -i $GREEN_DEV -s 192.168.0.3 --dport 80 -j
DROP"

OFF We have a Rbot-Fam Virus (bling.exe) and we cant kill him because he
always come back somehow. We put the MS patches to our computers and we
removed the virus from the infected computers in safe mode but when you
restart the PC it is again in the system32. So I think he downloads himself
from the others infected computers. It wont solve the problem but it is good
to know how can I disable a port on SW to defend our network. /OFF



----- Original Message -----
From: "Samuel Gordon-Stewart" <smoothwallsamuel-/[email protected]>
To: "Varady Zoltan" <[email protected]>; <[email protected]>
Sent: Thursday, October 14, 2004 11:42 AM
Subject: Re: [gpl] Port Disable


> --- Varady Zoltan <[email protected]> wrote:
> > Can I disable some port in the SW against the
> > viruses ?
> All incoming ports are blocked, however outgoing ports
> can be blocked, see
> http://martybugs.net/smoothwall/iptables.cgi for
> details.
>
> samuel
>
> =====
> I must be really old in dog years!
> Listen to my lovely music www.thefunkyasylum.com/notnice.mp3
> Protect your network www.smoothwall.org
>
>
>
> _______________________________
> Do you Yahoo!?
> Declare Yourself - Register online to vote today!
> http://vote.yahoo.com
_______________________________________________
gpl mailing list
[email protected]
http://lists.smoothwall.org/mailman/listinfo/gpl

SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall
_______________________________________________
gpl mailing list
[email protected]
http://lists.smoothwall.org/mailman/listinfo/gpl

SmoothWall Stash - Buy Our Stuff! http://cafepress.com/smoothwall