Bonjour,
Après avoir fait un scan des ports afin de tester la sécurité de mon pc il me trouve 18 ports tcp fermés ( 22,25,79,110,113,119,139,143,389,443,1002,1004,1024,1025,1027,1028,1029,1030) il me trouve aussi Ports TCP masqués ( 21,23,80,135,445,1720,5000).Je voudrais savoir comment masqués la totalité des ports?,ton mon iptables (/etc/sysconfig/iptables) voila la régles que j'ai
[c]# Generated by iptables-save v1.3.5 on Sat Mar 22 06:37:07 2008
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
😮UTPUT DROP [0:0]
:LOG_DROP - [0:0]
-A INPUT -i lo -j ACCEPT
-A INPUT -s 192.168.0.0/255.255.255.0 -j ACCEPT
-A INPUT -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j DROP
-A INPUT -j LOG_DROP
-A FORWARD -j LOG_DROP
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -d 192.168.0.0/255.255.255.0 -j ACCEPT
-A OUTPUT -o eth0 -p udp -m udp --dport 53 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 53 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 139 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 445 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 80 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 443 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 143 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 993 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 110 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 25 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 465 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 20 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 21 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 22 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 119 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 389 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 636 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 1863 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 5222 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 6881:6889 -j ACCEPT
-A OUTPUT -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -p icmp -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -j LOG_DROP
-A LOG_DROP -j LOG --log-prefix "[IPTABLES DROP]:" --log-level 1
-A LOG_DROP -j DROP
COMMIT
# Completed on Sat Mar 22 06:37:07 2008
# Generated by iptables-save v1.3.5 on Sat Mar 22 06:37:07 2008
*nat
😛REROUTING ACCEPT [3:984]
😛OSTROUTING ACCEPT [5:407]
😮UTPUT ACCEPT [46:8889]
-A POSTROUTING -s 192.168.122.0/255.255.255.0 -j MASQUERADE
-A POSTROUTING -s 192.168.122.0/255.255.255.0 -j MASQUERADE
COMMIT
# Completed on Sat Mar 22 06:37:07 2008
[/c]
Après avoir fait un scan des ports afin de tester la sécurité de mon pc il me trouve 18 ports tcp fermés ( 22,25,79,110,113,119,139,143,389,443,1002,1004,1024,1025,1027,1028,1029,1030) il me trouve aussi Ports TCP masqués ( 21,23,80,135,445,1720,5000).Je voudrais savoir comment masqués la totalité des ports?,ton mon iptables (/etc/sysconfig/iptables) voila la régles que j'ai
[c]# Generated by iptables-save v1.3.5 on Sat Mar 22 06:37:07 2008
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
😮UTPUT DROP [0:0]
:LOG_DROP - [0:0]
-A INPUT -i lo -j ACCEPT
-A INPUT -s 192.168.0.0/255.255.255.0 -j ACCEPT
-A INPUT -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j DROP
-A INPUT -j LOG_DROP
-A FORWARD -j LOG_DROP
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -d 192.168.0.0/255.255.255.0 -j ACCEPT
-A OUTPUT -o eth0 -p udp -m udp --dport 53 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 53 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 139 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 445 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 80 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 443 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 143 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 993 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 110 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 25 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 465 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 20 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 21 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 22 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 119 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 389 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 636 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 1863 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 5222 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --dport 6881:6889 -j ACCEPT
-A OUTPUT -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -p icmp -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -j LOG_DROP
-A LOG_DROP -j LOG --log-prefix "[IPTABLES DROP]:" --log-level 1
-A LOG_DROP -j DROP
COMMIT
# Completed on Sat Mar 22 06:37:07 2008
# Generated by iptables-save v1.3.5 on Sat Mar 22 06:37:07 2008
*nat
😛REROUTING ACCEPT [3:984]
😛OSTROUTING ACCEPT [5:407]
😮UTPUT ACCEPT [46:8889]
-A POSTROUTING -s 192.168.122.0/255.255.255.0 -j MASQUERADE
-A POSTROUTING -s 192.168.122.0/255.255.255.0 -j MASQUERADE
COMMIT
# Completed on Sat Mar 22 06:37:07 2008
[/c]