Snort alert log

2002-11-13 Thread Kristof Goossens
: 0x0 TcpLen: 0 I don't know what this means however... Specially the ports seam strange to me. Any help would be appreciated! Thanks in advance, Kristof Goossens -- Digital fingerprint: F56F F987 0E0C AFF8 0B6D 7CA1 F152 E07D 72AF 337B msg07728/pgp0.pgp Description: PGP signature

Re: Updating Snort Signatures In Stable ?

2002-12-06 Thread Kristof Goossens
and use it in combination with cron... Anyhow: this is the script located @ www.xssass.be... Kind regards, Kristof Goossens -- Digital fingerprint: F56F F987 0E0C AFF8 0B6D 7CA1 F152 E07D 72AF 337B msg08045/pgp0.pgp Description: PGP signature

securing pop3

2003-02-08 Thread Kristof Goossens
Hello all, I need to make a pop3 account on my server. I intend to work with ipop3d to provide secure pop3 service. Now I want to provide this service for only few people, and I don't want them to have an account on the system. Well, they can have a pop3 account, but no other access whatsoever...

Re: iptables rule to drop from sources that are -nat postrouting from the outside to inside

2003-05-30 Thread Kristof Goossens
On Thu, May 29, 2003 at 11:19:24PM -0500, Hanasaki JiJi wrote: I have a nat postrouting rule that passes traffice from the outside world to an internal host to handle port 80 (webserver) there are also rules to drop certain source addresses yet these addresses are still coming through

Re: iptables rule to drop from sources that are -nat postrouting from the outside to inside

2003-05-31 Thread Kristof Goossens
On Fri, May 30, 2003 at 09:20:19AM +0200, Filippi Marco wrote: [snip] how can they be dropped? not sure, but I think that it'll work when you specify the outside interface... For example: if you want to drop the http requests from w.x.y.z then your rule should look like: iptables

Re: XP box inside the firewall

2003-07-30 Thread Kristof Goossens
On Wed, Jul 30, 2003 at 02:01:06PM +0200, Kjetil Kjernsmo wrote: Hi all! [snip] The question is really if I could do something in the firewall that would help isolate the XP box somewhat. Closing outgoing ports (input ports are all closed), drop certain types of packages, or something

Re: port 6051: hacked?

2002-09-06 Thread Kristof Goossens
On Fri, Sep 06, 2002 at 12:16:39PM +0200, Ramin Motakef wrote: Hi all, Todays nmap run shows me: Interesting ports on (xx): (The 59984 ports scanned but not shown below are in state: closed) Port State Service 21/tcp openftp 22/tcp

Snort alert log

2002-11-14 Thread Kristof Goossens
: 0x0 TcpLen: 0 I don't know what this means however... Specially the ports seam strange to me. Any help would be appreciated! Thanks in advance, Kristof Goossens -- Digital fingerprint: F56F F987 0E0C AFF8 0B6D 7CA1 F152 E07D 72AF 337B pgprwbRh5dhNR.pgp Description: PGP signature

Re: question about SSH / IPTABLES

2003-01-23 Thread Kristof Goossens
On Thu, Jan 23, 2003 at 12:24:49PM +0100, Iñaki Martínez wrote: Hi!!! I have a server in internet and i want several clients to access to it via SSH but i DON'T want they to be able to use SSH from that server. So i client can access the server via SSH, but s/he CAN NOT ssh to other

Re: cluster on firewall?

2003-02-06 Thread Kristof Goossens
On Thu, Feb 06, 2003 at 03:09:34AM +0200, Haim Ashkenazi wrote: Hi I have setup a firewall with 4 legs as follows: * One leg goes to the router (cisco). * Second leg goes to a switch connected to the internal network (10.20...). * The third and fourth legs

securing pop3

2003-02-08 Thread Kristof Goossens
Hello all, I need to make a pop3 account on my server. I intend to work with ipop3d to provide secure pop3 service. Now I want to provide this service for only few people, and I don't want them to have an account on the system. Well, they can have a pop3 account, but no other access whatsoever...

Re: text mode virtual terminal auto lock

2003-03-13 Thread Kristof Goossens
On Thu, Mar 13, 2003 at 06:48:58AM +, Aurelio Turco wrote: I have looked around for a screen lock for the text mode virtual terminal that activates automatically after a certain amount of idle time but could not find even one. Does anyone know of any? vlock does the locking part. You

Re: Snort signature download script

2003-04-26 Thread Kristof Goossens
On Sat, Apr 26, 2003 at 12:52:58PM +0200, Konstantin Filtschew wrote: hi, there is a signature download script posted on http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=173254 from http://www.xssass.be I tried it, but he tells me, that the md5 checksum is wrong Ah... :( There was a

Re: Snort signature download script

2003-04-27 Thread Kristof Goossens
On Sat, Apr 26, 2003 at 12:52:58PM +0200, Konstantin Filtschew wrote: hi, there is a signature download script posted on http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=173254 from http://www.xssass.be I tried it, but he tells me, that the md5 checksum is wrong you can download the

PHP imap-ssl support

2003-05-21 Thread Kristof Goossens
Hello all, I want to use debian packages for imap-ssl support in php4. regular imap works fine after installing the php4-imap package; however the imap-ssl does not work. In the output of phpinfo() I can see that my php4 (debian stable package) was configured with the option --with-imap, but not

Re: Should I use Snort/PortSentry?

2003-05-23 Thread Kristof Goossens
On Thu, May 22, 2003 at 08:46:47PM -0400, Rob French wrote: [snip] So, are any network/port-related tools useful? In my personal opinion it is ALWAYS usefull to know what is going on on your system. No mather how little ports are open... You said it was for your laptop, and thats why you

Re: iptables rule to drop from sources that are -nat postrouting from the outside to inside

2003-05-30 Thread Kristof Goossens
On Thu, May 29, 2003 at 11:19:24PM -0500, Hanasaki JiJi wrote: I have a nat postrouting rule that passes traffice from the outside world to an internal host to handle port 80 (webserver) there are also rules to drop certain source addresses yet these addresses are still coming through

Re: iptables rule to drop from sources that are -nat postrouting from the outside to inside

2003-05-31 Thread Kristof Goossens
On Fri, May 30, 2003 at 09:20:19AM +0200, Filippi Marco wrote: [snip] how can they be dropped? not sure, but I think that it'll work when you specify the outside interface... For example: if you want to drop the http requests from w.x.y.z then your rule should look like: iptables

Re: XP box inside the firewall

2003-07-30 Thread Kristof Goossens
On Wed, Jul 30, 2003 at 02:01:06PM +0200, Kjetil Kjernsmo wrote: Hi all! [snip] The question is really if I could do something in the firewall that would help isolate the XP box somewhat. Closing outgoing ports (input ports are all closed), drop certain types of packages, or something