Prisizaidziau su Firewall

G
  • 10 Grd '07

Sweiki,
Instaliavau firefall neatsimenu kokia , intikas veikia puikiai ,bet kaip istryniau ja , tai su ja intikas pradingo ka daryti? kaip pakeisti nustatymus i pradinius?
Aciu

R
  • 10 Grd '07

per ka jungiesi i interneta?
parodyk
sudo iptables -L
ifconfig -a
route -n

G
  • 10 Grd '07

sudo iptables -L

hain INPUT (policy DROP)
target prot opt source destination
ACCEPT 0 -- anywhere anywhere
ACCEPT 0 -- 192.168.1.4 192.168.1.255
logaborted tcp -- anywhere anywhere state RELATED,ESTABLISHED tcp flags:RST/RST
ACCEPT 0 -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT icmp -- anywhere anywhere icmp destination-unreachable
ACCEPT icmp -- anywhere anywhere icmp time-exceeded
ACCEPT icmp -- anywhere anywhere icmp parameter-problem
nicfilt 0 -- anywhere anywhere
srcfilt 0 -- anywhere anywhere

Chain FORWARD (policy DROP)
target prot opt source destination
ACCEPT 0 -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT icmp -- anywhere anywhere icmp destination-unreachable
ACCEPT icmp -- anywhere anywhere icmp time-exceeded
ACCEPT icmp -- anywhere anywhere icmp parameter-problem
srcfilt 0 -- anywhere anywhere

Chain OUTPUT (policy DROP)
target prot opt source destination
ACCEPT 0 -- anywhere anywhere
ACCEPT 0 -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT icmp -- anywhere anywhere icmp destination-unreachable
ACCEPT icmp -- anywhere anywhere icmp time-exceeded
ACCEPT icmp -- anywhere anywhere icmp parameter-problem
s1 0 -- anywhere anywhere

Chain f0to1 (3 references)
target prot opt source destination
logdrop 0 -- anywhere anywhere

Chain f1to0 (1 references)
target prot opt source destination
logdrop 0 -- anywhere anywhere

Chain logaborted (1 references)
target prot opt source destination
logaborted2 0 -- anywhere anywhere limit: avg 1/sec burst 10
LOG 0 -- anywhere anywhere limit: avg 2/min burst 1 LOG level warning prefix `LIMITED '

Chain logaborted2 (1 references)
target prot opt source destination
LOG 0 -- anywhere anywhere LOG level warning tcp-sequence tcp-options ip-options prefix `ABORTED '
ACCEPT 0 -- anywhere anywhere state RELATED,ESTABLISHED

Chain logdrop (4 references)
target prot opt source destination
logdrop2 0 -- anywhere anywhere limit: avg 1/sec burst 10
LOG 0 -- anywhere anywhere limit: avg 2/min burst 1 LOG level warning prefix `LIMITED '
DROP 0 -- anywhere anywhere

Chain logdrop2 (1 references)
target prot opt source destination
LOG 0 -- anywhere anywhere LOG level warning tcp-sequence tcp-options ip-options prefix `DROPPED '
DROP 0 -- anywhere anywhere

Chain logreject (0 references)
target prot opt source destination
logreject2 0 -- anywhere anywhere limit: avg 1/sec burst 10
LOG 0 -- anywhere anywhere limit: avg 2/min burst 1 LOG level warning prefix `LIMITED '
REJECT tcp -- anywhere anywhere reject-with tcp-reset
REJECT udp -- anywhere anywhere reject-with icmp-port-unreachable
DROP 0 -- anywhere anywhere

Chain logreject2 (1 references)
target prot opt source destination
LOG 0 -- anywhere anywhere LOG level warning tcp-sequence tcp-options ip-options prefix `REJECTED '
REJECT tcp -- anywhere anywhere reject-with tcp-reset
REJECT udp -- anywhere anywhere reject-with icmp-port-unreachable
DROP 0 -- anywhere anywhere

Chain nicfilt (1 references)
target prot opt source destination
RETURN 0 -- anywhere anywhere
RETURN 0 -- anywhere anywhere
RETURN 0 -- anywhere anywhere
logdrop 0 -- anywhere anywhere

Chain s0 (1 references)
target prot opt source destination
f0to1 0 -- anywhere 192.168.1.4
f0to1 0 -- anywhere 192.168.1.255
f0to1 0 -- anywhere localhost
logdrop 0 -- anywhere anywhere

Chain s1 (1 references)
target prot opt source destination
f1to0 0 -- anywhere anywhere

Chain srcfilt (2 references)
target prot opt source destination
s0 0 -- anywhere anywhere

ifconfig -a
eth0 Link encap:Ethernet HWaddr 00:1A:4D:7B:14:1C
inet addr:192.168.1.4 Bcast:192.168.1.255 Mask:255.255.255.0
inet6 addr: fe80::21a:4dff:fe7b:141c/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:5 errors:0 dropped:0 overruns:0 frame:0
TX packets:8 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:3380 (3.3 KB) TX bytes:870 (870.0 b)
Interrupt:21 Base address:0xc000

lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)

route -n
Kernel IP routeing table
Destination Gateway Genmask Flags Metric Ref Use Iface
192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0
169.254.0.0 0.0.0.0 255.255.0.0 U 1000 0 0 eth0
0.0.0.0 192.168.1.1 0.0.0.0 UG 100 0 0 eth0

R
  • 10 Grd '07

kas bus jei:
sudo iptables -F
sudo iptables -P INPUT ACCEPT
sudo iptables -P OUTPUT ACCEPT
sudo iptables -P FORWARD ACCEPT

G
  • 10 Grd '07

Aciu rdx padejo ir as vel su savo megstamiausia os

R
  • 19 Sau '08

turiu klausima..
issijungia pati savaime firestarter programa..
nesuprantu kodel!
kad paleisti ja ivedu passworda ir tada ji isijungia... o pati kadanori ima ir issijungia! Nezinau ka daryt..kita firewall ieskot, ar ka opcijose pakeist? ieskojau neradau nieko itartino..
o sulaiko tai daugybe visokiu siuksliu

V
  • 19 Sau '08

paleisk ja ish terminalo - ir kai ishsijungs viska kas bus ishvesta i ta terminala - papostink chia

R
  • 20 Sau '08

nemoku as tokiu dalyku kaip paleisti ja is terminalo...tai ir paleist ja reikia..ir po to terminalo langa niekada neuzdaryt? tai ten nezinau..tiek to...jei labai daznai issijungines tai bandysiu...kolkas tai buvo issijungus tik 5kart aplamai..

R
  • 20 Sau '08

kaip per ta terminala paleisti firestarter?
isjungti terminalo po to jau nebebus galima?
ar tai saugu palikti ta terminalo langa ijungta?

A
  • 20 Sau '08

sudo firestarter

R
  • 29 Sau '08

glibc detected firestarter: munmap_chunk(): invalid pointer: 0x084507f0 *
======= Backtrace: =========
/lib/tls/i686/cmov/libc.so.6(cfree+0x1bb)[0xb722892b]
/usr/lib/libglib-2.0.so.0(g_free+0x31)[0xb7353961]
/usr/lib/libglib-2.0.so.0(g_hash_table_replace+0xb9)[0xb733fcd9]
firestarter[0x8061a37]
/usr/lib/libglib-2.0.so.0[0xb734c8d6]
/usr/lib/libglib-2.0.so.0(g_main_context_dispatch+0x17c)[0xb734c11c]
/usr/lib/libglib-2.0.so.0[0xb734f55f]
/usr/lib/libglib-2.0.so.0(g_main_loop_run+0x1a9)[0xb734f909]
/usr/lib/libgtk-x11-2.0.so.0(gtk_main+0xb4)[0xb7a2f9e4]
firestarter[0x804fff5]
/lib/tls/i686/cmov/libc.so.6(__libc_start_main+0xe0)[0xb71d1050]
firestarter[0x804f1e1]
======= Memory map: ========
08048000-080b7000 r-xp 00000000 08:01 4965780 /usr/sbin/firestarter
080b7000-080b9000 rw-p 0006e000 08:01 4965780 /usr/sbin/firestarter
080b9000-084cc000 rw-p 080b9000 00:00 0 [heap]
b592d000-b5937000 r-xp 00000000 08:01 8355907 /lib/libgcc_s.so.1
b5937000-b5938000 rw-p 0000a000 08:01 8355907 /lib/libgcc_s.so.1
b5948000-b59a8000 rw-s 00000000 00:09 46366746 /SYSV00000000 (deleted)
b59a8000-b5a2c000 r--p 00000000 08:01 5197008 /usr/share/fonts/truetype/ttf-dejavu/DejaVuSans-Bold.ttf
b5a2c000-b5a2d000 ---p b5a2c000 00:00 0
b5a2d000-b622d000 rw-p b5a2d000 00:00 0
b622d000-b6234000 r-xp 00000000 08:01 4966167 /usr/lib/libfam.so.0.0.0
b6234000-b6235000 rw-p 00006000 08:01 4966167 /usr/lib/libfam.so.0.0.0
b6235000-b623b000 r-xp 00000000 08:01 8355866 /lib/libacl.so.1.1.0
b623b000-b623c000 rw-p 00005000 08:01 8355866 /lib/libacl.so.1.1.0
b623c000-b623f000 r-xp 00000000 08:01 8355872 /lib/libattr.so.1.1.0
b623f000-b6240000 rw-p 00002000 08:01 8355872 /lib/libattr.so.1.1.0
b6250000-b625c000 r-xp 00000000 08:01 5029916 /usr/lib/gnome-vfs-2.0/modules/libfile.so
b625c000-b625d000 rw-p 0000b000 08:01 5029916 /usr/lib/gnome-vfs-2.0/modules/libfile.so
b625d000-b625f000 r-xp 00000000 08:01 5096764 /usr/lib/pango/1.6.0/modules/pango-basic-fc.so
b625f000-b6260000 rw-p 00001000 08:01 5096764 /usr/lib/pango/1.6.0/modules/pango-basic-fc.so
b6260000-b62eb000 r--p 00000000 08:01 5197009 /usr/share/fonts/truetype/ttf-dejavu/DejaVuSans.ttf
b62eb000-b62f1000 r--s 00000000 08:01 1196117 /var/cache/fontconfig/945677eb7aeaf62f1d50efc3fb3ec7d8-x86.cache-2
b62f1000-b62f4000 r--s 00000000 08:01 1198650 /var/cache/fontconfig/e383d7ea5fbe662a33d9b44caf393297-x86.cache-2
b62f4000-b62f8000 r--s 00000000 08:01 1198649 /var/cache/fontconfig/921a30a17f0be15c70ac14043cb7a739-x86.cache-2
b62f8000-b62f9000 r--s 00000000 08:01 1198648 /var/cache/fontconfig/c69f04ab05004e31a6d5e715764f16d8-x86.cache-2
b62f9000-b62fa000 r--s 00000000 08:01 1198647 /var/cache/fontconfig/4c73fe0c47614734b17d736dbde7580a-x86.cache-2
b62fa000-b62fd000 r--s 00000000 08:01 1198646 /var/cache/fontconfig/a755afe4a08bf5b97852ceb7400b47bc-x86.cache-2
b62fd000-b62fe000 r--s 00000000 08:01 1198645 /var/cache/fontconfig/75a2cd575a62c63e802c11411fb87c37-x86.cache-2
b62fe000-b6304000 r--s 00000000 08:01 1199403 /var/cache/fontconfig/6d41288fd70b0be22e8c3a91e032eec0-x86.cache-2
b6304000-b6306000 r--s 00000000 08:01 1198643 /var/cache/fontconfig/de156ccd2eddbdc19d37a45b8b2aac9c-x86.cache-2
b6306000-b630e000 r--s 00000000 08:01 1198642 /var/cache/fontconfig/e3de0de479f42330eadf588a55fb5bf4-x86.cache-2
b630e000-b6314000 r--s 00000000 08:01 1198641 /var/cache/fontconfig/0f34bcd4b6ee430af32735b75db7f02b-x86.cache-2
b6314000-b6315000 r--s 00000000 08:01 1198640 /var/cache/fontconfig/4794a0821666d79190d59a36cb4f44b5-x86.cache-2
b6315000-b6317000 r--s 00000000 08:01 1198639 /var/cache/fontconfig/de9486f0b47a4d768a594cb4198cb1c6-x86.cache-2
b6317000-b631d000 r--s 00000000 08:01 1198638 /var/cache/fontconfig/d52a8644073d54c13679302ca1180695-x86.cache-2
b631d000-b6321000 r--s 00000000 08:01 1196102 /var/cache/fontconfig/089dead882dea3570ffc31a9898cfb69-x86.cache-2
b6321000-b6323000 r--s 00000000 08:01 1198162 /var/cache/fontconfig/e13b20fdb08344e0e664864cc2ede53d-x86.cache-2
b6323000-b6324Aborted (core dumped)