All of lore.kernel.org
 help / color / mirror / Atom feed
From: jwlargent <jwlargent@vlsmaps.com>
To: Elvir Kuric <omasnjak@gmail.com>
Cc: Marc Haber <mh+netfilter@zugschlus.de>, netfilter@lists.netfilter.org
Subject: Re: Restricting applications/protocols to use specific ports using iptables, is this possible
Date: Tue, 05 Jun 2007 11:00:30 -0500	[thread overview]
Message-ID: <4665889E.2030201@vlsmaps.com> (raw)
In-Reply-To: <1814bfe70706040539x61ca3113rb8679da3cc29b304@mail.gmail.com>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Elvir Kuric wrote:
> On 6/4/07, Marc Haber <mh+netfilter@zugschlus.de> wrote:
>> On Mon, Jun 04, 2007 at 01:37:07PM +0200, Elvir Kuric wrote:
>> > I am interested in one thing, is possible using iptables software
>> > limit particular application/protocol to use/bind to particular
>> ports.
>>
>> Why do you want to do that?
>
> :) I want to control which ports are open in output chain. Testing,
> exploring.
>
> I know it is not important which ports are open in output chain,
> usually putting output policy to accept.

It is important to know what ports are open in the output chain.  This
is exactly the attitude
that helps the spread of Trojans and Viruses.
You should only open ports you need, for example a user brings in
a Trojan that tries to infect other systems and connects back to a monitor
somewhere to let it know about the host it just took over.  If you are
blocking the ports it
uses to infect other systems you limit the damage it does.  Now there
is nothing that keeps it
from using a port you have open, say port 80 http., but at least you
have tried to limit your exposure.

>
>>
>> > For example I want to send all reqestes from my machine using
>> ports I
>> > specify, not random ones,
>>
>> Why?
>>
>> >  or accept ping echo-replay on specific ports.
>>
>> Pleas get your facts straight. ICMP does not have ports.
>
> ICMP was just example, first on my mind in that moment :)
>
> Regards
>
> Elvir Kuric
>>
>> Greetings
>> Marc
>>
>> --
>>
-----------------------------------------------------------------------------
>>
>> Marc Haber         | "I don't trust Computers. They | Mailadresse
>> im Header
>> Mannheim, Germany  |  lose things."    Winona Ryder | Fon: *49 621
>> 72739834
>> Nordisch by Nature |  How to make an American Quilt | Fax: *49 3221
>> 2323190
>>
>>


- --
Jeff Largent
System Administrator
Visual Lease Services Inc.
http://www.vlsmaps.com
(405) 379-5280
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGZYidd02kARNrtZkRAnIpAJ9DaulTYHRPSX4SWrwhH6n00LcxUQCg4qug
41YEjFzdoMVSJaBKJyfg15Q=
=dTnF
-----END PGP SIGNATURE-----



  parent reply	other threads:[~2007-06-05 16:00 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-06-04 11:37 Restricting applications/protocols to use specific ports using iptables, is this possible Elvir Kuric
2007-06-04 12:06 ` Marc Haber
2007-06-04 12:39   ` Elvir Kuric
2007-06-04 14:18     ` Gáspár Lajos
2007-06-05 16:00     ` jwlargent [this message]
2007-06-05 17:00       ` Elvir Kuric
2007-06-05 17:42         ` Marc Haber

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4665889E.2030201@vlsmaps.com \
    --to=jwlargent@vlsmaps.com \
    --cc=mh+netfilter@zugschlus.de \
    --cc=netfilter@lists.netfilter.org \
    --cc=omasnjak@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.