[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] weird /local/local/portsentry ipchains happening



Andy Brown wrote:

Okay, firstly, yep sort out why /usr/local/local existed, sounds like a mv done wrongly somewhere along the lines, and yes run chkrootkits' and have a look at who's been logged in from where and why. Usual stuff.

Onto ipchains, yes portsentry uses ipchains (if it can, portsentry can drop routes in other ways, but ipchains is the best to do this) so you do have it up and running on the raq.
Do an:
# ipchains -L
and it will list all the rules and settings currently stored.
If you're just running portsentry, chances are there will be few lines, and all under the chain input

To unblock somebody, find the rule you want to delete and type:
# ipchains -D input 1

Note : ipchains works from number 0 upwards, so the top rule is 0, next 1, etc.. Also be worth checking in /etc/hosts.deny as it also writes a line in there to stop the ip using tcpwrapped programs too.



Thanks Andy! A great little quick tutorial on ipchains that will help me a lot. I'll spend some time rooting around to see if I can find anything. I did recently update bind on two raq4s and on one got a "/ almost full at 95%" type message so moved /usr/local to /home/local on one machine, but didn't on this one. So it is possible I did some kind of brain spasm on it.

--
Jim Dory, Engineering
City of Nome
PO Box 281
102 Division St.
Nome, AK 99762
907.443.6604