Search This Blog

Tuesday, September 04, 2007

from Miss Victoria. i need youe help

From Miss Victoria Adja,
 
Dear,
How are you Doing,my name is Miss Victoria Adja, please i want to you Recover some money my father left in bank here, please is very important you get back to me to give you the details.
we shall talk on pacentage.
Sincerely yours,
Miss Victoria Adja.
Please contact me through this email:  victoadja@yahoo.fr


Stockage illimité de vos mails avec Yahoo! Mail. Changez aujourd'hui de mail !

Monday, September 03, 2007

Nice_Offers

 
Nice offers for everyone!
 


Luggage? GPS? Comic books?
Check out fitting gifts for grads at Yahoo! Search.

WindowSecurity.com - Monthly Article Update

WindowSecurity.com - Monthly Article Update

Hi Security World,

New articles added to WindowSecurity.com last month:

Title: GFI LANguard N.S.S.- Voted WindowSecurity.com Readers' Choice Award Winner - Patch Management Category
Author: Admin
Link: http://www.WindowSecurity.com/news/WindowSecurity-Readers-Choice-Award-Patch-Management-Category-GFI-LANguard-NSS-Jul07.html
Summary: GFI LANguard N.S.S was selected the winner in the Patch Management category of the WindowSecurity.com Readers' Choice Awards. WinINSTALL and PatchLink Update were first runner-up and second runner-up.

Title: Unique Group Policy Security Settings
Author: Derek Melber
Link: http://www.WindowSecurity.com/articles/Unique-Group-Policy-Security-Settings.html
Summary: Enforcing Group Policy Security Settings (including some in-depth Registry "hacks"), and some of the most common scenarios where security settings do not behave as they appear.

Title: Encryption Key Management
Author: Ricky M. Magalhaes
Link: http://www.WindowSecurity.com/articles/Encryption-Key-Management.html
Summary: What needs to be done to effectively store the keys to your encrypted data.

Title: A Microsoft PKI Quick Guide – Part 3: Installation
Author: Martin Kiaer
Link: http://www.WindowSecurity.com/articles/Microsoft-PKI-Quick-Guide-Part3.html
Summary: How to install a PKI based on Microsoft Certificate Services in Windows Server 2003.

Title: Reducing the Attack Surface of the Administrator Account
Author: Derek Melber
Link: http://www.WindowSecurity.com/articles/Reducing-Attack-Surface-Administrator-Account.html
Summary: Limiting what the 'administrator' accounts can do in networks.

Title: Configuring Granular Password Settings in Windows Server 2008, Part 2
Author: Jakob H. Heidelberg
Link: http://www.WindowSecurity.com/articles/Configuring-Granular-Password-Settings-Windows-Server-2008-Part2.html
Summary: How to configure Granular Password Settings for individual users or groups in a Windows Server 2008 Active Directory environment.

Title: Microsoft UK Events Website Hacked
Author: Jonathan Spiteri
Link: http://www.WindowSecurity.com/articles/Microsoft-UK-Events-Website-Hacked.html
Summary: A detailed analysis how the website was hacked and how it could have been avoided.

Visit the Subscription Management (http://newsletter.isoftmarketing.com/) section to unsubscribe.
WindowSecurity.com is in no way affiliated with Microsoft Corp.
For sponsorship information, contact us at advertising@windowsecurity.com

Copyright © WindowSecurity.com 2007. All rights reserved.

ISAserver.org - Monthly Article Update

ISAserver.org - Monthly Article Update

Hi Security World,

New articles added to ISAserver.org last month:

Title: bt-LogAnalyzer Voted ISAserver.org Readers' Choice Award Winner - Reporting
Author: Site Admin
Link: http://www.ISAserver.org/news/ISAserver-Readers-Choice-Award-Reporting-bt-LogAnalyzer-Jun07.html
Summary: bt-LogAnalyzer was selected the winner in the Reporting category of the ISAserver.org Readers' Choice awards. WebSpy ISA Server Suite and ISALyzer were runner-up and second runner-up respectively.

Title: Publishing Exchange 2007 OWA, Exchange ActiveSync and RPC/HTTP using the 2006 ISA Firewall (Part 7)
Author: Thomas Shinder
Link: http://www.ISAserver.org/tutorials/Publishing-Exchange-2007-OWA-Exchange-ActiveSync-RPCHTTP-2006-ISA-Firewall-Part7.html
Summary: How to configure the clients.

Title: Publishing Exchange 2007 OWA, Exchange ActiveSync and RPC/HTTP using the 2006 ISA Firewall (Part 6)
Author: Thomas Shinder
Link: http://www.ISAserver.org/tutorials/Publishing-Exchange-2007-OWA-Exchange-ActiveSync-RPCHTTP-2006-ISA-Firewall-Part6.html
Summary: Creating OWA, RPC/HTTP and Exchange ActiveSync Web Publishing Rules.

Title: Generating SSL Certificates for Exchange 2007 and ISA Server 2006
Author: Steven Hope
Link: http://www.ISAserver.org/tutorials/Generating-SSL-Certificates-Exchange-2007-ISA-Server-2006.html
Summary: Using ISA Server to front a single Exchange 2007 server in a split DNS configuration.

Title: Publishing Exchange 2007 OWA, Exchange ActiveSync and RPC/HTTP using the 2006 ISA Firewall (Part 5)
Author: Thomas Shinder
Link: http://www.ISAserver.org/tutorials/Publishing-Exchange-2007-OWA-Exchange-ActiveSync-RPCHTTP-2006-ISA-Firewall-Part5.html
Summary: Requesting a Web site certificate to bind to the Web listener and creating the Web listener.

Title: Publishing Exchange 2007 OWA, Exchange ActiveSync and RPC/HTTP using the 2006 ISA Firewall (Part 4)
Author: Thomas Shinder
Link: http://www.ISAserver.org/tutorials/Publishing-Exchange-2007-OWA-Exchange-ActiveSync-RPCHTTP-using-2006-ISA-Firewall-Part4.html
Summary: Installing and configuring the Client Access Server.

Visit the Subscription Management (http://newsletter.isoftmarketing.com/) section to unsubscribe.
ISAserver.org is in no way affiliated with Microsoft Corp.
For sponsorship information, contact us at advertising@isaserver.org

Copyright © ISAserver.org 2007. All rights reserved.

[NEWS] IBM DB2 sysproc.auth_list_groups_for_authid Buffer Overflow

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html


- - - - - - - - -

IBM DB2 sysproc.auth_list_groups_for_authid Buffer Overflow
------------------------------------------------------------------------


SUMMARY

Buffer overflow on sysproc.auth_list_groups_for_authid function. By
passing an overly long value of more then 40-bytes to the
auth_list_groups_for_authid function, a stack-based buffer can be
overflowed.

DETAILS

Vulnerable Systems:
* DB2 version 9.1 Fixpack 2 Enterprise server edition

Immune Systems:
* DB2 version 9.1 Fixpack 3 Enterprise server edition

Impact:
An attacker can use this to cause a denial of service or take complete
control of an affected system.

Vendor Status:
Vendor was contacted and a patch was
<http://www-1.ibm.com/support/docview.wss?uid=swg1IZ01828> released.

Fix:
To fix the problem apply the fixpak 3 for DB2 version 9.1
<http://www-306.ibm.com/software/data/db2/support/db2_9/>

http://www-306.ibm.com/software/data/db2/support/db2_9/


ADDITIONAL INFORMATION

The information has been provided by <mailto:shatter@appsecinc.com> Team
SHATTER.
The original article can be found at:
<http://www.appsecinc.com/resources/alerts/db2/2007-01.shtml>

http://www.appsecinc.com/resources/alerts/db2/2007-01.shtml

========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

WindowsNetworking.com - Monthly Article Update

WindowsNetworking.com - Monthly Article Update

Hi Security World,

New articles and tutorials added to WindowsNetworking.com last month:

Title: How to configure the new Windows Server 2008 advanced firewall MMC snap-in
Author: David Davis
Link: http://www.WindowsNetworking.com/articles_tutorials/configure-Windows-Server-2008-advanced-firewall-MMC-snap-in.html
Summary: The new features of the Windows Server 2008 Advanced Firewall and how to configure this powerful host-based firewall using the new MMC snap-in.

Title: Cisco PIX - Voted WindowsNetworking.com Readers' Choice Award Winner - Firewalls & VPN hardware
Author: Site Admin
Link: http://www.WindowsNetworking.com/news/WindowsNetworking-Readers-Choice-Award-Firewalls-VPN-Hardware-Cisco-PIX-Jul07.html
Summary: Cisco PIX was selected the winner in the Firewalls & VPN hardware category of the WindowsNetworking.com Readers' Choice awards. Checkpoint VPN-1 UTM and SonicWALL PRO 5060 were runner-up and second runner-up respectively.

Title: Enabling Network Mapping in Windows Vista
Author: Brien M. Posey
Link: http://www.WindowsNetworking.com/articles_tutorials/Enabling-Network-Mapping-Windows-Vista.html
Summary: Enabling Windows Vista's Network Mapping feature on domain networks.

Title: Office Communications Server 2007: Microsoft goes VoIP (Part 2)
Author: Ted Wallingford
Link: http://www.WindowsNetworking.com/articles_tutorials/Office-Communications-Server-2007-Microsoft-VoIP-Part2.html
Summary: Installing, configuring and beginning to use Microsoft Office Communications Server.

Title: Working with Network Monitor (Part 3)
Author: Brien M. Posey
Link: http://www.WindowsNetworking.com/articles_tutorials/Working-With-Network-Monitor-Part3.html
Summary: How to begin isolating the captured data that you are interested in.

Title: Group Policy Extensions in Windows Vista and Windows Server 2008, Part 2
Author: Brien M. Posey
Link: http://www.WindowsNetworking.com/articles_tutorials/Group-Policy-Extensions-Windows-Vista-Windows-Server-2008-Part2.html
Summary: Group policy settings that are unique to Windows Vista and Windows Server 2008.

Title: Networking Basics, Part 11: The Active Directory Users and Computers Console
Author: Brien M. Posey
Link: http://www.WindowsNetworking.com/articles_tutorials/Networking-Basics-Part11.html
Summary: The Active Directory Users and Computers console and how to use this console to manage remote domains.

Title: Memory and Storage - Part 2: New Memory Technologies
Author: Russell Hitchcock
Link: http://www.WindowsNetworking.com/articles_tutorials/Memory-Storage-Part2.html
Summary: Data storage up-and-coming technologies

Visit the Subscription Management (http://newsletter.isoftmarketing.com/) section to unsubscribe.
WindowsNetworking.com is in no way affiliated with Microsoft Corp.
For sponsorship information, contact us at advertising@WindowsNetworking.com

Copyright © WindowsNetworking.com 2007. All rights reserved.

Sunday, September 02, 2007

[SECURITY] [DSA 1288-2] New pptpd packages fix regression

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- --------------------------------------------------------------------------
Debian Security Advisory DSA 1288-2 security@debian.org
http://www.debian.org/security/

Moritz Muehlenhoff
September 2nd, 2007

http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package : pptpd
Vulnerability : programming error
Problem-Type : remote
Debian-specific: no
CVE ID : CVE-2007-0244

A regression in the handling of out-of-order sequence numbers of some
MPPE implementations was fixed. For reference the original advisory
below:

It was discovered that the PoPToP Point to Point Tunneling Server
contains a programming error, which allows the tear-down of a PPTP
connection through a malformed GRE packet, resulting in denial of
service.

The oldstable distribution (sarge) is not affected by this problem.

For the stable distribution (etch) this problem has been fixed in
version 1.3.0-2etch2.

For the unstable distribution (sid) this problem has been fixed in
version 1.3.4-1.

We recommend that you upgrade your pptpd packages.


Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 4.0 alias etch
- -------------------------------

Source archives:

http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch2.dsc

Size/MD5 checksum: 599 9098a1a6ebac37015c1159a2c6a21655

http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch2.diff.gz

Size/MD5 checksum: 11339 495273aeca7469ef97b157af54b8b89e

http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0.orig.tar.gz

Size/MD5 checksum: 204099 75d494e881f7027f4e60b114163f6b67

Alpha architecture:

http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2etch2_alpha.deb

Size/MD5 checksum: 21576 86f8e1420d2b39f23ca52aad8b9462f8

http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch2_alpha.deb

Size/MD5 checksum: 64776 12d4251d52d6aa4faec9d89c3f9a0c54

AMD64 architecture:

http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2etch2_amd64.deb

Size/MD5 checksum: 20446 a6a3007abffaf4393940ac641396e909

http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch2_amd64.deb

Size/MD5 checksum: 59294 db123a85074522fa397403360f3c0afe

ARM architecture:

http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2etch2_arm.deb

Size/MD5 checksum: 20204 c9b704f2fe5f4f70f04ae9a68673f7d2

http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch2_arm.deb

Size/MD5 checksum: 60602 68586cc6440aa2f92eb4930386dc81c4

HP Precision architecture:

http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2etch2_hppa.deb

Size/MD5 checksum: 21030 eecadad57b44403e9ddf91691922744a

http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch2_hppa.deb

Size/MD5 checksum: 59872 ca8b7cefd65e309eb73ded39aa28b83a

Intel IA-32 architecture:

http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2etch2_i386.deb

Size/MD5 checksum: 20182 ddbd3620e2252b06c58850f0c9470f2f

http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch2_i386.deb

Size/MD5 checksum: 57504 4ac1a61fbec2faba596b3ff4b8c7dc85

Intel IA-64 architecture:

http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2etch2_ia64.deb

Size/MD5 checksum: 23678 706574fe45f2dbb66df8433a181ce108

http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch2_ia64.deb

Size/MD5 checksum: 73974 b1fbb3a8d5f21cb4800f39b2fac15e9b

Big endian MIPS architecture:

http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2etch2_mips.deb

Size/MD5 checksum: 20754 fb8a7880d78b0aa9584d81eb8455195f

http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch2_mips.deb

Size/MD5 checksum: 59778 db4a1e66a2af55f1dbd1367661e9b988

Little endian MIPS architecture:

http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2etch2_mipsel.deb

Size/MD5 checksum: 20878 03784167b79d65347c14eb5295bbf364

http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch2_mipsel.deb

Size/MD5 checksum: 60392 43255efe577c7dfad1bde0667040f44f

PowerPC architecture:

http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2etch2_powerpc.deb

Size/MD5 checksum: 20554 a70b545ca9e62f8460da3a2deb308dac

http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch2_powerpc.deb

Size/MD5 checksum: 61330 7bbb717e342da28d24a7c46edf24c7c0

IBM S/390 architecture:

http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2etch2_s390.deb

Size/MD5 checksum: 20496 8eee9314e2285efb7c06b54047a02adf

http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch2_s390.deb

Size/MD5 checksum: 58274 7b7f426cb51fca01579a5480d562ec77

Sun Sparc architecture:

http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2etch2_sparc.deb

Size/MD5 checksum: 20164 5d7de3ee3845dfb7583a8d4df13ea0b7

http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch2_sparc.deb

Size/MD5 checksum: 57050 0cf177e1bc22d8d8c157dcff87b7c86f


These files will probably be moved into the stable distribution on
its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFG2yRjXm3vHE4uyloRAvFLAJ9lYrGnyxhsMXXdCTDlf4OlwVej8ACeNvnj
AOrKpwexK77cI/Bg0mR6r1Q=
=Tcdo
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

Re: Iptables and FTP problem

Mahdi Rahimi a écrit :
> my Rules for passive FTP look like this and works without problem but i
> want to my LAN works in active ftp.
>
> ###control connection
> $IPTABLES -A FORWARD -p tcp -s $LAN --sport 1024:65535 -d $EXT --dport 21
> -m state --state NEW,ESTABLISHED -j ACCEPT
> $IPTABLES -A FORWARD -p tcp -s $EXT --sport 21 -d $LAN --dport 1024:65535
> -m state --state RELATED,ESTABLISHED -j ACCEPT

RELATED is not needed for the control connections.

> ###data connection
> $IPTABLES -A FORWARD -p tcp -s $LAN --sport 1024:65535 -d $EXT --dport
> 1024:65535 -m state --state RELATED,ESTABLISHED -j ACCEPT
> $IPTABLES -A FORWARD -p tcp -s $EXT --sport 1024:65535 -d $LAN --dport
> 1024:65535 -m state --state RELATED,ESTABLISHED -j ACCEPT

This is getting confusing. In your previous messages, $LAN and $EXT were
used in -i and -o options, meaning they contain interface names. Now
they are used in -s and -d options, meaning they contain addresses or
network address prefixes. So what are $LAN and $EXT ?

Assuming that $LAN and $EXT contain network prefixes (respectively
192.168.1.0/26 and 0.0.0.0/0 according to you previous messages), you
need to add the following rules in order to allow transfers in active mode :

$IPTABLES -A FORWARD -p tcp -s $EXT --sport 20 -d $LAN \
--dport 1024:65535 -m state --state RELATED,ESTABLISHED -j ACCEPT
$IPTABLES -A FORWARD -p tcp -s $LAN --sport 1024:65535 -d $EXT \
--dport 20 -m state --state ESTABLISHED -j ACCEPT

However I recommend filtering at least on the input interface and not
only on the source address, because the source address can be forged.


--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

[NT] Yahoo Messenger YVerInfo.dll ActiveX Multiple Remote Buffer Overflow Vulnerabilities

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html


- - - - - - - - -

Yahoo Messenger YVerInfo.dll ActiveX Multiple Remote Buffer Overflow
Vulnerabilities
------------------------------------------------------------------------


SUMMARY

Yahoo! Messenger is a instant messaging application that allows users to
chat online, share files, conduct PC to PC calls and more. Remote
exploitation of multiple buffer overflow vulnerabilities in Yahoo Inc.'s
Yahoo! Messenger 8.1 allows attackers to execute arbitrary code with the
privileges of the currently logged in user.

DETAILS

Vulnerable Systems:
* Yahoo Instant Messenger version 8.1

When Yahoo Messenger 8.1 is installed, the following vulnerable ActiveX
Control is registered on the system.

ProgID: YVerInfo.GetInfo.1
Clsid: D5184A39-CBDF-4A4F-AC1A-7A45A852C883
File: C:\Program Files\Yahoo!\Common\YVerInfo.dll
Version: 2006.8.24.1

Stack based buffer overflows can be triggered through either the fvCom()
or info() methods of this class.

Analysis:
Exploitation allows attackers to execute arbitrary code with the
privileges of the currently logged in user. Users would be required to
have a vulnerable version of the target software installed and be lured to
a malicious site.

It is important to note that functions within this class can only be
called if the control believes it is being run from the yahoo.com
domain. In order for this exploit to be triggered an attacker would either
have to leverage a Cross-Site Scripting vulnerability in the yahoo.com
domain, or be able to control the targeted user's DNS resolution for the
domain.

Workaround:
Setting the kill bit for the vulnerable ActiveX control's CLSID will
prevent these issues from be exploited within Internet Explorer.

Vendor response:
Yahoo Inc. has addressed these vulnerabilities by releasing an updated
version of Yahoo! Messenger. More information is available at the
following URL: <http://messenger.yahoo.com/security_update.php?id=082907>

http://messenger.yahoo.com/security_update.php?id=082907

CVE Information:
<http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4515>
CVE-2007-4515

Disclosure timeline:
08/21/2007 - Initial vendor notification
08/21/2007 - Initial vendor response
08/30/2007 - Coordinated public disclosure


ADDITIONAL INFORMATION

The information has been provided by
<mailto:idlabs-advisories@idefense.com> iDefense Labs Security Advisories.
The original article can be found at:
<http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=591>

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=591

========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

Saturday, September 01, 2007

RE: Iptables and FTP problem

To use active FTP, try setting this option in your ftp client. Most
clients work standard in passive, but there must be an option to
change that.

edit: forgot sending to the list.
On 9/2/07, Mahdi Rahimi <rahimi@eaedu.net> wrote:
>
> my Rules for passive FTP look like this and works without problem but i
> want to my LAN works in active ftp.
>
> ###control connection
> $IPTABLES -A FORWARD -p tcp -s $LAN --sport 1024:65535 -d $EXT --dport 21
> -m state --state NEW,ESTABLISHED -j ACCEPT
> $IPTABLES -A FORWARD -p tcp -s $EXT --sport 21 -d $LAN --dport 1024:65535
> -m state --state RELATED,ESTABLISHED -j ACCEPT
>
> ###data connection
> $IPTABLES -A FORWARD -p tcp -s $LAN --sport 1024:65535 -d $EXT --dport
> 1024:65535
> -m state --state RELATED,ESTABLISHED -j ACCEPT
> $IPTABLES -A FORWARD -p tcp -s $EXT --sport 1024:65535 -d $LAN --dport
> 1024:65535
> -m state --state RELATED,ESTABLISHED -j ACCEPT
>
>
>
>
>
> --
> To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
> with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
>
>


--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

RE: Iptables and FTP problem

hello, dears
I decide to set my firewalls ruls to passive mode that I sent in pervious
post
and my client set your ftp-client to active or work with IE in passwive mode.
Thanx alot for all.

--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

Re: Iptables and FTP problem

my Rules for passive FTP look like this and works without problem but i
want to my LAN works in active ftp.

###control connection
$IPTABLES -A FORWARD -p tcp -s $LAN --sport 1024:65535 -d $EXT --dport 21
-m state --state NEW,ESTABLISHED -j ACCEPT
$IPTABLES -A FORWARD -p tcp -s $EXT --sport 21 -d $LAN --dport 1024:65535
-m state --state RELATED,ESTABLISHED -j ACCEPT

###data connection
$IPTABLES -A FORWARD -p tcp -s $LAN --sport 1024:65535 -d $EXT --dport
1024:65535
-m state --state RELATED,ESTABLISHED -j ACCEPT
$IPTABLES -A FORWARD -p tcp -s $EXT --sport 1024:65535 -d $LAN --dport
1024:65535
-m state --state RELATED,ESTABLISHED -j ACCEPT

--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

Re: Iptables and FTP problem

hello,

##Control connection ( port 21)
-A FORWARD -i $LAN -o $EXT -m state --state NEW,ESTABLISHED,RELATED -p
tcp -m multiport --dports 21 -j ACCEPT
-A FORWARD -i $EXT -o $LAN -m state --state ESTABLISHED,RELATED -p tcp
-m multiport --sports 21 -j ACCEPT

##Data connection
-A FORWARD -i $EXT -o $LAN -p tcp -m state --state RELATED,ESTABLISHED
-j ACCEPT
-A FORWARD -i $LAN -o $EXT -m state --state ESTABLISHED -p tcp -j ACCEPT

FORWARD default policy is DROP
------------------
With this rules i can't start data connection but control connection work in
Active ftp (standard mode)
My server try to work in passive mode because try to connect the ftp
server via port > 1024 such as 5049, .... after control connection for
data transfer

thanx


--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

Re: Iptables and FTP problem

Hello,

Mahdi Rahimi a écrit :
>
> My NAT(PREROUTING) and Filter table default Policy is DROP.

Bad idea. The nat table is not intended for filtering. Just leave the
nat table chains default policies to ACCEPT, and do the filtering in the
filter table chains.

>>>hello I have problem in our clients's outside ftp access via debian.
>>>My LAN users can't start data transfer to outside FTP servers, but they
>>>can establish connection to port 21 on the outside ftp server.
>>>
>>>I want to my LAN users use ftp clinets in ACTIVE mode.
>>>my rules:
>>>
>>>***nat
>>>-A PREROUTING -i $LAN -s 192.168.1.0/26 -p tcp -m multiport --dport 21
>>>-j ACCEPT

As I said above, the nat table is not intended for filtering, and it is
a bad idea to filter in the nat table.

>>>-A POSTROUTING -s 192.168.1.0/26 -d 0/0 -o eth1 -j MASQUERADE
>>>
>>>***filter
>>>-A FORWARD -i $LAN -o $EXT -s 192.168.1.0/26 -p tcp --dport 21 -m state
>>>--state NEW,ESTABLISHED,RELATED -j ACCEPT
>>>-A FORWARD -i $EXT -o $LAN -p tcp --sport 21 -m state --state
>>>ESTABLISHED,RELATED -j ACCEPT
>>>
>>>*************
>>>modprobe ip_conntrack_ftp , ip_conntrack, ip_nat_ftp

In order for active FTP transfers to work, you need to :
- accept the control connection (port 21) NEW and ESTABLISHED packets
from inside to outside ; OK, done in the first rule in FORWARD ;
- accept the control connection ESTABLISHED packets from outside to
inside ; OK, done in the second FORWARD rule ;
- accept the data connection RELATED and ESTABLISHED packets from
outside to inside ; KO, not done in either rule ;
- accept the data connection (port != 21) ESTABLISHED packets from
inside to outside ; KO, not done in either rule.

The rule
-A FORWARD -i $EXT -o $LAN -m state --state ESTABLISHED,RELATED \
-p tcp -j ACCEPT

alone won't solve the problem because it accepts only data connection
packets from outside to inside ; packets from inside to outside are
still dropped. So you also need something like

-A FORWARD -o $EXT -i $LAN -m state --state ESTABLISHED \
-p tcp -j ACCEPT


--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

Re: Iptables and FTP problem

may you must change FORWARD with ACCEPT to allow transfer on that port.
Greets

On 9/1/07, Mahdi Rahimi <rahimi@eaedu.net> wrote:
>
>
> -A FORWARD -i $LAN -o $EXT -m state --state NEW,ESTABLISHED,RELATED -p
> tcp --dport 21 -j ACCEPT
>
> -A FORWARD -i $EXT -o $LAN -m state --state ESTABLISHED,RELATED -p tcp
> --sport 21 -j ACCEPT
>
> I don't have data transfer with this rules!!!
>
> -------------------------
> rahimi{at}eaedu.net
> rahimi_m{at}cse.shirazu.ac.ir
>
>
> --
> To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
> with a subject of "unsubscribe". Trouble? Contact
> listmaster@lists.debian.org
>
>


--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

Re: Iptables and FTP problem

Nope. Your rule says to allow related,established on port 21. It doesn't
apply to port 20. Add a log rule to see what's being dropped.

You can remove the --sport 21 and just allow in ANY established,related
and that should work.

phil

On 9/1/2007 7:36 AM, Mahdi Rahimi wrote:
> thanks phil
> But i think the port 20 is in RELATED state and no connection need to be
> established. module ip_conntrack_ftp must correct this problem.

[snip]

>>> ***filter
>>> -A FORWARD -i $LAN -o $EXT -s 192.168.1.0/26 -p tcp --dport 21 -m state
>>> --state NEW,ESTABLISHED,RELATED -j ACCEPT
>>> -A FORWARD -i $EXT -o $LAN -p tcp --sport 21 -m state --state
>>> ESTABLISHED,RELATED -j ACCEPT
>>>
>


--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

firewall-wizards Digest, Vol 17, Issue 1

Send firewall-wizards mailing list submissions to
firewall-wizards@listserv.icsalabs.com

To subscribe or unsubscribe via the World Wide Web, visit
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
or, via email, send a message with subject or body 'help' to
firewall-wizards-request@listserv.icsalabs.com

You can reach the person managing the list at
firewall-wizards-owner@listserv.icsalabs.com

When replying, please edit your Subject line so it is more specific
than "Re: Contents of firewall-wizards digest..."


Today's Topics:

1. Re: Query: Why bother with an application proxy over stateful
packet filtering? (K K)
2. Stand Alone vs. Domain System (Rafael Palma Teixeira)


----------------------------------------------------------------------

Message: 1
Date: Tue, 28 Aug 2007 15:20:05 -0500
From: "K K" <kkadow@gmail.com>
Subject: Re: [fw-wiz] Query: Why bother with an application proxy over
stateful packet filtering?
To: "Firewall Wizards Security Mailing List"
<firewall-wizards@listserv.icsalabs.com>
Cc: Andy Cunningham <andyc@cunningham.me.uk>
Message-ID:
<dc718edc0708281320w632cc9c6v10c9a0bddd522c6a@mail.gmail.com>
Content-Type: text/plain; charset=ISO-8859-1

On 8/27/07, william fitzgerald <wfitzgerald@tssg.org> wrote:
> Also, are web proxy's used in conjunction with firewalls
> or in place of a firewall.

Depends on the site. There are many "firewalls" which include web
proxy functionality, and many commercial web proxy products market
themselves as being a replacement for a traditional "firewall".

In big business I often see an ingress+egress packet filter (a "filter
router") on the outermost edge, with proxy firewalls just inside the
filter, and then the soft and juicy center just "inside" the proxy
firewall layer.


> While agree with you view of controlling telnet or in appropriate
> protocols across a firewall as compared with using a more fine grained
> web proxy, i can still by pass the proxy via "httptunnel" for example.
>
> So both proxy and firewall can be equally subverted internally via out
> bound traffic to a rogue service listening on a http port.

Any good administrator and/or log analysis tool can detect basic
tunnel tools such as "httptunnel".

While it's still possible to bypass the proxy, it's no longer nearly
as trivial as it once was. Newer application proxies are doing true
Man In the Middle (MITM) against encrypted protocols such as SSL and
SSH, so even wrapping your protocol in TLS is no longer sufficient.

Squid doesn't have these particular features, yet.


> Second Point:
> also iptables could use its "string matching" to filter in appropriate
> sites that match content keywords or even based on a black-hole list.

While the difference between an "application proxy" and a "protocol
aware stateful inspection packet filter" is shrinking, there is still
a gap between the two types of products, generally the difference is
how much actual protocol awareness and state is in the security
gateway, and how high in the OSI stack the gateway can do rewriting
and remediation.

Also, I prefer a policy of "that which is not explicitly permitted is
denied by default, and repeated attempts to evade policy have swift
and non-trivial consequences."


> I guess I am still struggling to see any real benefits as of right now
> apart from the obvious web caching abilities but thats not what this
> discussion is about.

There are some specific benefits to using a non-transparent HTTP proxy
to funnel all HTTP protocol requests through a single specific port,
so applications which expect a browser to be able to establish a HTTP
session using non-standard TCP ports work without having to write a
custom filter rule for each, or just permit all possible outbound
ports.

For an extreme example of the benefits of application proxy over a
"smart" packet filter, take a look at the BalaBit Shell Control Box
(SCB), which intercepts and inspects SSH sessions, auditing behavior
and selectively enforcing policy, without the network administrator
needing to have any visibility into or control over the local policy
on the endpoint machines (the only other way I know of to have that
level of granularity and control over an encrypted tunnel).

Kevin

(P.S. Has anybody here actually deployed SCB?)


------------------------------

Message: 2
Date: Wed, 29 Aug 2007 20:56:47 +0100
From: "Rafael Palma Teixeira" <rpteixeira@gmail.com>
Subject: [fw-wiz] Stand Alone vs. Domain System
To: firewall-wizards@listserv.icsalabs.com
Message-ID:
<2aa15a220708291256q1f0be651m8a331d8a84519a75@mail.gmail.com>
Content-Type: text/plain; charset="iso-8859-1"

Hi List.
I need your thoughts on this one:
Assuming that a laptop will have a few corporate security features (HD
encryption, patch, AV and so forth) will it be safer for it to be in
standalone mode (avoiding domain SID and other information to be leaked) or
joined in a Windows domain (with all that goes along, groups policies and
stuff) ?

Thanks for your time.

R


--
What luck for the rulers that men do not think.
Adolf Hitler
-------------- next part --------------
An HTML attachment was scrubbed...
URL: https://listserv.icsalabs.com/pipermail/firewall-wizards/attachments/20070829/e69a642e/attachment-0001.html


------------------------------

_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


End of firewall-wizards Digest, Vol 17, Issue 1
***********************************************

Re: Iptables and FTP problem

you need to allow port 20 for the data connection.

phil


On 9/1/2007 4:52 AM, Mahdi Rahimi wrote:
> hello
> I have problem in our clients's outside ftp access via debian.
> My LAN users can't start data transfer to outside FTP servers, but they
> can establish connection to port 21 on the outside ftp server.
>
> I want to my LAN users use ftp clinets in ACTIVE mode.
> my rules:
>
> ***nat
> -A PREROUTING -i $LAN -s 192.168.1.0/26 -p tcp -m multiport --dport 21 -j
> ACCEPT
> -A POSTROUTING -s 192.168.1.0/26 -d 0/0 -o eth1 -j MASQUERADE
>
> ***filter
> -A FORWARD -i $LAN -o $EXT -s 192.168.1.0/26 -p tcp --dport 21 -m state
> --state NEW,ESTABLISHED,RELATED -j ACCEPT
> -A FORWARD -i $EXT -o $LAN -p tcp --sport 21 -m state --state
> ESTABLISHED,RELATED -j ACCEPT
>
> *************
> modprobe ip_conntrack_ftp , ip_conntrack, ip_nat_ftp
>
>
>
>
>


--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

Re: Iptables and FTP problem

-A FORWARD -i $LAN -o $EXT -m state --state NEW,ESTABLISHED,RELATED -p
tcp --dport 21 -j ACCEPT

-A FORWARD -i $EXT -o $LAN -m state --state ESTABLISHED,RELATED -p tcp
--sport 21 -j ACCEPT

I don't have data transfer with this rules!!!

-------------------------
rahimi{at}eaedu.net
rahimi_m{at}cse.shirazu.ac.ir


--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

Re: Iptables and FTP problem

my rule:
-A FORWARD -i $LAN -o $EXT -m state --state NEW,ESTABLISHED,RELATED -p
tcp --dport 21 -j ACCEPT
"don't work. because it try to connect via port 5050 an so to Server and
not 21 !!!!"

-A FORWARD -i $EXT -o $LAN -m state --state ESTABLISHED,RELATED -p tcp
-j ACCEPT
can't solve problem.

On Sat, September 1, 2007 20:56, Phil Dyer wrote:
> Nope. Your rule says to allow related,established on port 21. It doesn't
> apply to port 20. Add a log rule to see what's being dropped.
>
> You can remove the --sport 21 and just allow in ANY established,related
> and that should work.
>
> phil
>
> On 9/1/2007 7:36 AM, Mahdi Rahimi wrote:
>
>> thanks phil But i think the port 20 is in RELATED state and no
>> connection need to be established. module ip_conntrack_ftp must correct
>> this problem.
>
> [snip]
>
>
>>>> ***filter
>>>> -A FORWARD -i $LAN -o $EXT -s 192.168.1.0/26 -p tcp --dport 21 -m
>>>> state --state NEW,ESTABLISHED,RELATED -j ACCEPT
>>>> -A FORWARD -i $EXT -o $LAN -p tcp --sport 21 -m state --state
>>>> ESTABLISHED,RELATED -j ACCEPT
>>>>
>>>>
>>
>
>
> --
> To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
> with a subject of "unsubscribe". Trouble? Contact
> listmaster@lists.debian.org
>
>


-------------------------
rahimi{at}eaedu.net
rahimi_m{at}cse.shirazu.ac.ir


--
To UNSUBSCRIBE, email to debian-firewall-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org