From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: open ports 25/tcp and 110/tcp
Date: Wed, 3 Dec 2003 23:01:11 +0000 [thread overview]
Message-ID: <200312032301.11900.Antony@Soft-Solutions.co.uk> (raw)
In-Reply-To: <002101c3b9ef$53e5d780$0201a8c0@OurPC>
On Wednesday 03 December 2003 10:46 pm, David F. Strauch wrote:
> Hello All,
>
> I've been working with giptables firewall and have run into a big issue.
> Although my script seems to be correct namp is finding ports 25/tcp and
> 110/tcp open. To start troubleshooting this problem I've commented
> everything out and stripped down the ruleset to just the default DROP
> policy. Yet nmap -sT -F -P0 -0 xx.xx.xx.xx still returns 25/tcp and
> 110/tcp as open!
>
> Now I'm starting to think that iptables is broken. I've built iptables with
> grsecurity-1.9.12 and iptables1.2.8 with a plain vanilla kernel 2.4.22 Is
> anyone aware of any issues?
Where are you testing from?
Is there any chance (particularly with port 25) that the requests are being
redirected to some other server, and this is what is being reported as open?
Try doing "telnet xx.xx.xx.xx 25" and see what login banner you get for the
SMTP service - does this correspond to the machine you're testing, or any
other machine you know about?
Try the same thing on port 110 and see if that login banner reveals a clue
either.
Antony.
--
The idea that Bill Gates appeared like a knight in shining armour to lead all
customers out of a mire of technological chaos neatly ignores the fact that
it was he who, by peddling second-rate technology, led them into it in the
first place.
- Douglas Adams in The Guardian, 25th August 1995
Please reply to the list;
please don't CC me.
next prev parent reply other threads:[~2003-12-03 23:01 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-12-03 22:46 open ports 25/tcp and 110/tcp David F. Strauch
2003-12-03 23:01 ` Antony Stone [this message]
2003-12-03 23:15 ` David F. Strauch
2003-12-03 23:23 ` Antony Stone
2003-12-03 23:34 ` David F. Strauch
[not found] ` <002201c3b9f5$c7ee11a0$0201a8c0@OurPC>
2003-12-03 23:39 ` Antony Stone
2003-12-03 23:58 ` David F. Strauch
2003-12-04 0:08 ` Antony Stone
2003-12-04 0:14 ` Michael Gale
2003-12-04 0:28 ` Jeffrey Laramie
2003-12-04 0:37 ` Michael Gale
2003-12-04 1:14 ` Jeffrey Laramie
2003-12-04 0:39 ` Antony Stone
2003-12-04 1:27 ` Jeffrey Laramie
2003-12-04 3:46 ` David F. Strauch
2003-12-04 0:11 ` Jeffrey Laramie
2003-12-03 23:08 ` Rob Sterenborg
2003-12-03 23:17 ` Antony Stone
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200312032301.11900.Antony@Soft-Solutions.co.uk \
--to=antony@soft-solutions.co.uk \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox