Go Back   openSUSE Forums > Archives > SLS Archives > ARCHIVES - SuSE Linux > ARCHIVES - Network & Security > ARCHIVES - Security
Forums FAQ Members List Search Today's Posts Mark Forums Read


ARCHIVES - Security Want to know if you should really apply the latest kernel patch? Want to know how to configure your firewall? Discuss any Security related topics in here!

 
Page 1 of 3 1 23
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 22-Feb-2008, 10:17
andrew sorensen
Guest
 
Posts: n/a
Default

How can i list iptabled users? i tried iptables -L and i dont see any ip set to reject... and i have a feeling i forgot to unrject a certian ip, thanks.
  #2 (permalink)  
Old 22-Feb-2008, 10:20
FeatherMonkey
Guest
 
Posts: n/a
Default

Suse is rarely managed directly via iptables but SuSEfirewall config.

How can i list iptabled users <= not even sure what this means
  #3 (permalink)  
Old 22-Feb-2008, 11:06
andrew sorensen
Guest
 
Posts: n/a
Default

Quote:
Suse is rarely managed directly via iptables but SuSEfirewall config.

How can i list iptabled users <= not even sure what this means
[/b]
users = ip adresses.
iptables -I INPUT -s 25.55.55.55 -j DROP
i used that i think some time ago (ip was not that however)
  #4 (permalink)  
Old 22-Feb-2008, 11:11
FeatherMonkey
Guest
 
Posts: n/a
Default

it won't stay then. You have to use the proper way adding them like that they're persistent till next reboot.
  #5 (permalink)  
Old 22-Feb-2008, 11:59
andrew sorensen
Guest
 
Posts: n/a
Default

Quote:
it won't stay then. You have to use the proper way adding them like that they're persistent till next reboot.
[/b]
what is the "proper way"?
  #6 (permalink)  
Old 22-Feb-2008, 12:03
FeatherMonkey
Guest
 
Posts: n/a
Default

Mmm using Susefirewall
  #7 (permalink)  
Old 22-Feb-2008, 12:08
andrew sorensen
Guest
 
Posts: n/a
Default

Quote:
Mmm using Susefirewall
[/b]
I dont see any option in yast firewall.
  #8 (permalink)  
Old 22-Feb-2008, 12:11
FeatherMonkey
Guest
 
Posts: n/a
Default

Well if not there get your hands dirty and look in the config. You may need the custom bit specifically.

But blocking IP's seems pointless unless you're 100% sure its not a dynamic address.
  #9 (permalink)  
Old 22-Feb-2008, 12:13
andrew sorensen
Guest
 
Posts: n/a
Default

Quote:
Well if not there get your hands dirty and look in the config. You may need the custom bit specifically.

But blocking IP's seems pointless unless you're 100% sure its not a dynamic address.
[/b]
k, maybe i will take a look at the fail2ban script or sometime to learn howto do it. Some were abusing a game server, and it does not have any way to ban... so i need to be able to block them for a certian time, until they get point.
  #10 (permalink)  
Old 22-Feb-2008, 12:21
FeatherMonkey
Guest
 
Posts: n/a
Default

Hope there's an rpm because I thought that was tied into iptables proper and ssh.

If you go to tips and tricks I did a very crude one using time to enable only so many ssh attempts for so many mins. But I did struggle, but I suspect with it you could work out what you need to do.

I'm not sure what you mean unless you mean they are ssh abusing, how are you going to know good from bad.
 
Page 1 of 3 1 23

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




 

Search Engine Friendly URLs by vBSEO 3.3.0 RC2