View previous topic :: View next topic |
Author |
Message |
IntergalacticWalrus Guru


Joined: 07 Jan 2003 Posts: 513 Location: Montreal QC (Canada)
|
Posted: Thu Jun 02, 2005 5:12 am Post subject: Home router guide and security (or lack thereof??) |
|
|
Hey, yesterday I've set up a home router with Gentoo, with the help of the helpful guide, and today I've noticed thanks to nmap (ran on a machine out of my local network) that all of the services on my router are open to the Internet !!!!! WTF?? I know next to nothing as to how to set up iptables, but I trusted those instructions in the guide, thinking they were safe since the author probably knew what he was doing, but it turned out it doesn't seem to lock up any ports! Have I missed something? It pretty freaked me out to notice that, according to nmap, my nfs port was open. Does it mean someone could mount my nfs exports from the 'net?
Last edited by IntergalacticWalrus on Thu Jun 02, 2005 5:18 am; edited 1 time in total |
|
Back to top |
|
 |
pjp Administrator


Joined: 16 Apr 2002 Posts: 20589
|
Posted: Thu Jun 02, 2005 5:18 am Post subject: |
|
|
I haven't used the guide, but none of the "section headings" had the word security in it, so I don't see a reason to expect much security from it. Check out the Gentoo Security Handbook. _________________ Quis separabit? Quo animo? |
|
Back to top |
|
 |
IntergalacticWalrus Guru


Joined: 07 Jan 2003 Posts: 513 Location: Montreal QC (Canada)
|
Posted: Thu Jun 02, 2005 5:21 am Post subject: |
|
|
One thing I don't understand in particular is that the guide has a line to open up ssh (iptables -A INPUT -p TCP --dport ssh -i eth1 -j ACCEPT), but from my nmap scan this seemed futile since everything else appeared open. |
|
Back to top |
|
 |
pjp Administrator


Joined: 16 Apr 2002 Posts: 20589
|
Posted: Thu Jun 02, 2005 5:27 am Post subject: |
|
|
Maybe its a bug in the guide, or a typo/misconfig on your part. Have you searched bugzilla to see if anything has been reported? If you don't find anything, double check your config against the doc, and file a bug report. _________________ Quis separabit? Quo animo? |
|
Back to top |
|
 |
|