<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[Linux-Noob Forums - Security and Firewalls]]></title>
		<link>https://www.linux-noob.com/forums/</link>
		<description><![CDATA[Linux-Noob Forums - https://www.linux-noob.com/forums]]></description>
		<pubDate>Fri, 01 May 2026 18:52:33 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[Prevent and block scan? (w00tw00t, tmUnblock.cgi etc)]]></title>
			<link>https://www.linux-noob.com/forums/thread-81.html</link>
			<pubDate>Fri, 26 Sep 2014 02:09:55 +0200</pubDate>
			<dc:creator><![CDATA[<a href="https://www.linux-noob.com/forums/member.php?action=profile&uid=4995">moon</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.linux-noob.com/forums/thread-81.html</guid>
			<description><![CDATA[<br />
Hi, I have often these lines in /var/log/apache2/access.log:<br />
<br />
 <br />
<br />
185.27.36.67 - - [25/Sep/2014:12:25:46 +0200] "POST /%70%68%70%70%61%74%68/%70%68%70?%2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+%2D%64+%64%69%73%61%62%6C%65%5F%66%75%6E%63%74%69%6F%6E%73%3D%22%22+%2D%64+%6F%70%65%6E%5F%62%61%73%65%64%69%72%3D%6E%6F%6E%65+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%6E HTTP/1.1" 404 393 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +<a href="http://www.google.com/bot.html)" target="_blank" rel="noopener" class="mycode_url">http://www.google.com/bot.html)"</a><br />
<br />
 <br />
<br />
58.241.61.162 - - [25/Sep/2014:12:30:57 +0200] "GET /w00tw00t.at.blackhats.romanian.anti-sec<img src="https://www.linux-noob.com/forums/images/smilies/smile.png" alt="Smile" title="Smile" class="smilie smilie_1" /> HTTP/1.1" 404 431 "-" "ZmEu"<br />
<br />
 <br />
<br />
58.241.61.162 - - [25/Sep/2014:12:30:58 +0200] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 404 421 "-" "ZmEu"<br />
<br />
 <br />
<br />
58.241.61.162 - - [25/Sep/2014:12:30:59 +0200] "GET /phpmyadmin/scripts/setup.php HTTP/1.1" 401 580 "-" "ZmEu"<br />
<br />
 <br />
<br />
58.241.61.162 - - [25/Sep/2014:12:31:00 +0200] "GET /pma/scripts/setup.php HTTP/1.1" 404 415 "-" "ZmEu"<br />
<br />
 <br />
<br />
58.241.61.162 - - [25/Sep/2014:12:31:00 +0200] "GET /myadmin/scripts/setup.php HTTP/1.1" 404 419 "-" "ZmEu"<br />
<br />
 <br />
<br />
58.241.61.162 - - [25/Sep/2014:12:31:05 +0200] "GET /MyAdmin/scripts/setup.php HTTP/1.1" 404 419 "-" "ZmEu"<br />
<br />
 <br />
<br />
211.24.56.24 - - [25/Sep/2014:14:53:55 +0200] "GET /tmUnblock.cgi HTTP/1.1" 400 431 "-" "-"<br />
<br />
 <br />
<br />
89.207.135.125 - - [25/Sep/2014:15:23:54 +0200] "GET /cgi-sys/defaultwebpage.cgi HTTP/1.0" 404 427 "-" "() { :;}; /bin/ping -c 1 198.101.206.138"<br />
<br />
 <br />
<br />
What is the best way to prevent this and block the scans?<br />
<br />
 <br />
<br />
Thank you very much in advance<br />
<br />
]]></description>
			<content:encoded><![CDATA[<br />
Hi, I have often these lines in /var/log/apache2/access.log:<br />
<br />
 <br />
<br />
185.27.36.67 - - [25/Sep/2014:12:25:46 +0200] "POST /%70%68%70%70%61%74%68/%70%68%70?%2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+%2D%64+%64%69%73%61%62%6C%65%5F%66%75%6E%63%74%69%6F%6E%73%3D%22%22+%2D%64+%6F%70%65%6E%5F%62%61%73%65%64%69%72%3D%6E%6F%6E%65+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%6E HTTP/1.1" 404 393 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +<a href="http://www.google.com/bot.html)" target="_blank" rel="noopener" class="mycode_url">http://www.google.com/bot.html)"</a><br />
<br />
 <br />
<br />
58.241.61.162 - - [25/Sep/2014:12:30:57 +0200] "GET /w00tw00t.at.blackhats.romanian.anti-sec<img src="https://www.linux-noob.com/forums/images/smilies/smile.png" alt="Smile" title="Smile" class="smilie smilie_1" /> HTTP/1.1" 404 431 "-" "ZmEu"<br />
<br />
 <br />
<br />
58.241.61.162 - - [25/Sep/2014:12:30:58 +0200] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 404 421 "-" "ZmEu"<br />
<br />
 <br />
<br />
58.241.61.162 - - [25/Sep/2014:12:30:59 +0200] "GET /phpmyadmin/scripts/setup.php HTTP/1.1" 401 580 "-" "ZmEu"<br />
<br />
 <br />
<br />
58.241.61.162 - - [25/Sep/2014:12:31:00 +0200] "GET /pma/scripts/setup.php HTTP/1.1" 404 415 "-" "ZmEu"<br />
<br />
 <br />
<br />
58.241.61.162 - - [25/Sep/2014:12:31:00 +0200] "GET /myadmin/scripts/setup.php HTTP/1.1" 404 419 "-" "ZmEu"<br />
<br />
 <br />
<br />
58.241.61.162 - - [25/Sep/2014:12:31:05 +0200] "GET /MyAdmin/scripts/setup.php HTTP/1.1" 404 419 "-" "ZmEu"<br />
<br />
 <br />
<br />
211.24.56.24 - - [25/Sep/2014:14:53:55 +0200] "GET /tmUnblock.cgi HTTP/1.1" 400 431 "-" "-"<br />
<br />
 <br />
<br />
89.207.135.125 - - [25/Sep/2014:15:23:54 +0200] "GET /cgi-sys/defaultwebpage.cgi HTTP/1.0" 404 427 "-" "() { :;}; /bin/ping -c 1 198.101.206.138"<br />
<br />
 <br />
<br />
What is the best way to prevent this and block the scans?<br />
<br />
 <br />
<br />
Thank you very much in advance<br />
<br />
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[squid proxy- aloow a site to go directl to internet,HELP!]]></title>
			<link>https://www.linux-noob.com/forums/thread-98.html</link>
			<pubDate>Mon, 27 May 2013 10:06:03 +0200</pubDate>
			<dc:creator><![CDATA[<a href="https://www.linux-noob.com/forums/member.php?action=profile&uid=1611">adam2k</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.linux-noob.com/forums/thread-98.html</guid>
			<description><![CDATA[<br />
hello, i need to make a site go directly to internet<br />
without squid. The reason i need this. Since a school purchased full features from a<br />
website. they opened the full features through their public ip.<br />
The issue when using squid proxy users cant access full featured only demo.<br />
if users configure their browser not to use squid proxy they can access full features<br />
in the site.<br />
i tried edit squid config and put these 2 lines but it didnt help, to allow this site<br />
to go directly to internet :<br />
<br />
acl direct-connect dstdomain *.sodmaya.co.il<br />
cache deny direct-connect<br />
<br />
acl sodmaya dstdomain .sodmaya.co.il<br />
always_direct allow sodmaya<br />
<br />
How can i solve this issue ? any ideas?<br />
<br />
 <br />
<br />
]]></description>
			<content:encoded><![CDATA[<br />
hello, i need to make a site go directly to internet<br />
without squid. The reason i need this. Since a school purchased full features from a<br />
website. they opened the full features through their public ip.<br />
The issue when using squid proxy users cant access full featured only demo.<br />
if users configure their browser not to use squid proxy they can access full features<br />
in the site.<br />
i tried edit squid config and put these 2 lines but it didnt help, to allow this site<br />
to go directly to internet :<br />
<br />
acl direct-connect dstdomain *.sodmaya.co.il<br />
cache deny direct-connect<br />
<br />
acl sodmaya dstdomain .sodmaya.co.il<br />
always_direct allow sodmaya<br />
<br />
How can i solve this issue ? any ideas?<br />
<br />
 <br />
<br />
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Not able to open tcp port in linux system]]></title>
			<link>https://www.linux-noob.com/forums/thread-158.html</link>
			<pubDate>Tue, 29 May 2012 13:30:33 +0200</pubDate>
			<dc:creator><![CDATA[<a href="https://www.linux-noob.com/forums/member.php?action=profile&uid=3942">gaurav_herein</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.linux-noob.com/forums/thread-158.html</guid>
			<description><![CDATA[<br />
I am using RHEL 5<br />
<br />
and my application is running in the system on port 11960. I need to connect to this port from application running on other system.<br />
<br />
but the port is closed for other system<br />
<br />
 <br />
<br />
below are the information for my system<br />
<br />
 <br />
<br />
 <br />
<br />
[root@ sysconfig]# iptables -L<br />
<br />
Chain INPUT (policy ACCEPT)<br />
<br />
target	 prot opt source			   destination<br />
<br />
ACCEPT	 tcp  --  anywhere			 anywhere			tcp spt:11960 state NEW,ESTABLISHED<br />
<br />
 <br />
<br />
Chain FORWARD (policy ACCEPT)<br />
<br />
target	 prot opt source			   destination<br />
<br />
 <br />
<br />
Chain OUTPUT (policy ACCEPT)<br />
<br />
target	 prot opt source			   destination<br />
<br />
 <br />
<br />
 <br />
<br />
 <br />
<br />
[root@ sysconfig]# netstat -nap | grep 11960<br />
<br />
tcp		0	  0 127.0.0.1:11960			 0.0.0.0:*				   LISTEN	  2155/cm<br />
<br />
 <br />
<br />
[root@ sysconfig]# nmap -p 11960 23.x.x.x<br />
<br />
 <br />
<br />
Starting Nmap 4.11 ( <a href="http://www.insecure.org/nmap/" target="_blank" rel="noopener" class="mycode_url">http://www.insecure.org/nmap/</a> ) at 2012-05-29 06:45 EDT<br />
<br />
Interesting ports on (23.x.x.x):<br />
<br />
PORT					 STATE	SERVICE<br />
<br />
11960/tcp 		   closed   unknown<br />
<br />
 <br />
<br />
[root@ sysconfig]# nmap -p 11960 127.0.0.1<br />
<br />
 <br />
<br />
Starting Nmap 4.11 ( <a href="http://www.insecure.org/nmap/" target="_blank" rel="noopener" class="mycode_url">http://www.insecure.org/nmap/</a> ) at 2012-05-29 06:45 EDT<br />
<br />
Interesting ports on localhost.localdomain (127.0.0.1):<br />
<br />
PORT					 STATE	SERVICE<br />
<br />
11960/tcp 		   open	 unknown<br />
<br />
 <br />
<br />
[root@domU-12-31-39-10-06-32 sysconfig]# tcptraceroute -p 11960 23.x.x.x<br />
<br />
traceroute to 23.x.x.x (23.x.x.x), 30 hops max, 40 byte packets<br />
<br />
1  ip-10-72-24-2.ec2.internal (10.72.24.2)  1.370 ms  1.322 ms  1.299 ms<br />
<br />
2  ip-10-1-6-69.ec2.internal (10.1.6.69)  0.505 ms ip-10-1-8-69.ec2.internal (10.1.8.69)  0.501 ms  0.680 ms<br />
<br />
3  ip-10-1-11-14.ec2.internal (10.1.11.14)  0.843 ms ip-10-1-7-14.ec2.internal (10.1.7.14)  0.833 ms ip-10-1-9-14.ec2.internal (10.1.9.14)  0.802 ms<br />
<br />
4  216.182.224.209 (216.182.224.209)  0.785 ms 216.182.224.76 (216.182.224.76)  16.203 ms 216.182.232.48 (216.182.232.48)  0.737 ms<br />
<br />
5  216.182.232.49 (216.182.232.49)  1.306 ms  1.285 ms 216.182.224.208 (216.182.224.208)  1.252 ms<br />
<br />
6  23.x.x.x  2.679 ms  2.654 ms  2.629 ms<br />
<br />
 <br />
<br />
Firewall is off<br />
<br />
 <br />
<br />
tried<br />
<br />
nc 23.x.x.x 11960<br />
<br />
 <br />
<br />
tried adding below when firewall was on<br />
<br />
iptables -A INPUT -i eth0 -p tcp --sport 11960 -m state --state NEW ESTABLISHED -j ACCEPT<br />
<br />
 <br />
<br />
tried flushing the iptables "iptables -F"<br />
<br />
 <br />
<br />
can anyone suggest what should i check or what is the problem with this port.<br />
<br />
is there anything that i need to add in /etc/services?<br />
<br />
 <br />
<br />
Regards,<br />
<br />
Gaurav<br />
<br />
]]></description>
			<content:encoded><![CDATA[<br />
I am using RHEL 5<br />
<br />
and my application is running in the system on port 11960. I need to connect to this port from application running on other system.<br />
<br />
but the port is closed for other system<br />
<br />
 <br />
<br />
below are the information for my system<br />
<br />
 <br />
<br />
 <br />
<br />
[root@ sysconfig]# iptables -L<br />
<br />
Chain INPUT (policy ACCEPT)<br />
<br />
target	 prot opt source			   destination<br />
<br />
ACCEPT	 tcp  --  anywhere			 anywhere			tcp spt:11960 state NEW,ESTABLISHED<br />
<br />
 <br />
<br />
Chain FORWARD (policy ACCEPT)<br />
<br />
target	 prot opt source			   destination<br />
<br />
 <br />
<br />
Chain OUTPUT (policy ACCEPT)<br />
<br />
target	 prot opt source			   destination<br />
<br />
 <br />
<br />
 <br />
<br />
 <br />
<br />
[root@ sysconfig]# netstat -nap | grep 11960<br />
<br />
tcp		0	  0 127.0.0.1:11960			 0.0.0.0:*				   LISTEN	  2155/cm<br />
<br />
 <br />
<br />
[root@ sysconfig]# nmap -p 11960 23.x.x.x<br />
<br />
 <br />
<br />
Starting Nmap 4.11 ( <a href="http://www.insecure.org/nmap/" target="_blank" rel="noopener" class="mycode_url">http://www.insecure.org/nmap/</a> ) at 2012-05-29 06:45 EDT<br />
<br />
Interesting ports on (23.x.x.x):<br />
<br />
PORT					 STATE	SERVICE<br />
<br />
11960/tcp 		   closed   unknown<br />
<br />
 <br />
<br />
[root@ sysconfig]# nmap -p 11960 127.0.0.1<br />
<br />
 <br />
<br />
Starting Nmap 4.11 ( <a href="http://www.insecure.org/nmap/" target="_blank" rel="noopener" class="mycode_url">http://www.insecure.org/nmap/</a> ) at 2012-05-29 06:45 EDT<br />
<br />
Interesting ports on localhost.localdomain (127.0.0.1):<br />
<br />
PORT					 STATE	SERVICE<br />
<br />
11960/tcp 		   open	 unknown<br />
<br />
 <br />
<br />
[root@domU-12-31-39-10-06-32 sysconfig]# tcptraceroute -p 11960 23.x.x.x<br />
<br />
traceroute to 23.x.x.x (23.x.x.x), 30 hops max, 40 byte packets<br />
<br />
1  ip-10-72-24-2.ec2.internal (10.72.24.2)  1.370 ms  1.322 ms  1.299 ms<br />
<br />
2  ip-10-1-6-69.ec2.internal (10.1.6.69)  0.505 ms ip-10-1-8-69.ec2.internal (10.1.8.69)  0.501 ms  0.680 ms<br />
<br />
3  ip-10-1-11-14.ec2.internal (10.1.11.14)  0.843 ms ip-10-1-7-14.ec2.internal (10.1.7.14)  0.833 ms ip-10-1-9-14.ec2.internal (10.1.9.14)  0.802 ms<br />
<br />
4  216.182.224.209 (216.182.224.209)  0.785 ms 216.182.224.76 (216.182.224.76)  16.203 ms 216.182.232.48 (216.182.232.48)  0.737 ms<br />
<br />
5  216.182.232.49 (216.182.232.49)  1.306 ms  1.285 ms 216.182.224.208 (216.182.224.208)  1.252 ms<br />
<br />
6  23.x.x.x  2.679 ms  2.654 ms  2.629 ms<br />
<br />
 <br />
<br />
Firewall is off<br />
<br />
 <br />
<br />
tried<br />
<br />
nc 23.x.x.x 11960<br />
<br />
 <br />
<br />
tried adding below when firewall was on<br />
<br />
iptables -A INPUT -i eth0 -p tcp --sport 11960 -m state --state NEW ESTABLISHED -j ACCEPT<br />
<br />
 <br />
<br />
tried flushing the iptables "iptables -F"<br />
<br />
 <br />
<br />
can anyone suggest what should i check or what is the problem with this port.<br />
<br />
is there anything that i need to add in /etc/services?<br />
<br />
 <br />
<br />
Regards,<br />
<br />
Gaurav<br />
<br />
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[squid/dansguardian problem]]></title>
			<link>https://www.linux-noob.com/forums/thread-290.html</link>
			<pubDate>Thu, 27 Oct 2011 15:10:36 +0200</pubDate>
			<dc:creator><![CDATA[<a href="https://www.linux-noob.com/forums/member.php?action=profile&uid=3499">inittux</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.linux-noob.com/forums/thread-290.html</guid>
			<description><![CDATA[<br />
I'm trying to setup a squid proxy server in combination with dansguardian internet filter on my pc. I used this <a href="http://linux.jamesjpn.com/how-to/dansguardian-install.html" target="_blank" rel="noopener" class="mycode_url">guide</a> and I am able to<br />
<br />
configure it all. Only problem I'm having is as soon as I change the IP tables(see below) I'm don't have internet access anymore.<br />
<br />
 <br />
<br />
iptables -t nat -A OUTPUT -p tcp --dport 80 -m owner --uid-owner squid -j ACCEPT<br />
<br />
iptables -t nat -A OUTPUT -p tcp --dport 3128 -m owner --uid-owner squid -j ACCEPT<br />
<br />
iptables -t nat -A OUTPUT -p tcp --dport 80 -j REDIRECT --to-ports 8080<br />
<br />
iptables -t nat -A OUTPUT -p tcp --dport 3128 -j REDIRECT --to-ports 8080<br />
<br />
iptables-save &gt; /etc/sysconfig/iptables<br />
<br />
 <br />
<br />
I am able to restore it using the iptables.old file.  I setup the whole configuration and all works without prolems.<br />
<br />
So I have a feeling it has to do with the iptables. I can't find anything strange in the squid logs or the dansguardian logs.<br />
<br />
Will continue to play around with it, hopefully I'll figure it out.<br />
<br />
]]></description>
			<content:encoded><![CDATA[<br />
I'm trying to setup a squid proxy server in combination with dansguardian internet filter on my pc. I used this <a href="http://linux.jamesjpn.com/how-to/dansguardian-install.html" target="_blank" rel="noopener" class="mycode_url">guide</a> and I am able to<br />
<br />
configure it all. Only problem I'm having is as soon as I change the IP tables(see below) I'm don't have internet access anymore.<br />
<br />
 <br />
<br />
iptables -t nat -A OUTPUT -p tcp --dport 80 -m owner --uid-owner squid -j ACCEPT<br />
<br />
iptables -t nat -A OUTPUT -p tcp --dport 3128 -m owner --uid-owner squid -j ACCEPT<br />
<br />
iptables -t nat -A OUTPUT -p tcp --dport 80 -j REDIRECT --to-ports 8080<br />
<br />
iptables -t nat -A OUTPUT -p tcp --dport 3128 -j REDIRECT --to-ports 8080<br />
<br />
iptables-save &gt; /etc/sysconfig/iptables<br />
<br />
 <br />
<br />
I am able to restore it using the iptables.old file.  I setup the whole configuration and all works without prolems.<br />
<br />
So I have a feeling it has to do with the iptables. I can't find anything strange in the squid logs or the dansguardian logs.<br />
<br />
Will continue to play around with it, hopefully I'll figure it out.<br />
<br />
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[I have something that kind of worries me]]></title>
			<link>https://www.linux-noob.com/forums/thread-315.html</link>
			<pubDate>Thu, 22 Sep 2011 20:11:30 +0200</pubDate>
			<dc:creator><![CDATA[<a href="https://www.linux-noob.com/forums/member.php?action=profile&uid=3499">inittux</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.linux-noob.com/forums/thread-315.html</guid>
			<description><![CDATA[<br />
I found a log file that kind of worries me, it's not my website log file but /var/log/secure. Is this something to worry about? Looks like someone is trying to break in:<br />
<br />
(and I got quite a few more ip's trying to do the same thing or something similar)<br />
<br />
 <br />
<br />
 <br />
<br />
Sep 18 03:46:12 localhost sshd[9004]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
Sep 18 03:46:41 localhost sshd[9005]: Address 96.44.148.170 maps to 96.44.148.170.static.quadranet.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!<br />
<br />
Sep 18 03:46:41 localhost sshd[9005]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=96.44.148.170  user=root<br />
<br />
Sep 18 03:46:43 localhost sshd[9005]: Failed password for root from 96.44.148.170 port 60604 ssh2<br />
<br />
Sep 18 03:46:43 localhost sshd[9006]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
Sep 18 03:47:11 localhost sshd[9007]: Address 96.44.148.170 maps to 96.44.148.170.static.quadranet.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!<br />
<br />
Sep 18 03:47:11 localhost sshd[9007]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=96.44.148.170  user=root<br />
<br />
Sep 18 03:47:12 localhost sshd[9007]: Failed password for root from 96.44.148.170 port 35961 ssh2<br />
<br />
Sep 18 03:47:12 localhost sshd[9008]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
Sep 18 03:47:41 localhost sshd[9009]: Address 96.44.148.170 maps to 96.44.148.170.static.quadranet.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!<br />
<br />
Sep 18 03:47:41 localhost sshd[9009]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=96.44.148.170  user=root<br />
<br />
Sep 18 03:47:43 localhost sshd[9009]: Failed password for root from 96.44.148.170 port 39572 ssh2<br />
<br />
Sep 18 03:47:43 localhost sshd[9010]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
Sep 18 03:48:12 localhost sshd[9011]: Address 96.44.148.170 maps to 96.44.148.170.static.quadranet.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!<br />
<br />
Sep 18 03:48:12 localhost sshd[9011]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=96.44.148.170  user=root<br />
<br />
Sep 18 03:48:14 localhost sshd[9011]: Failed password for root from 96.44.148.170 port 43168 ssh2<br />
<br />
Sep 18 03:48:14 localhost sshd[9012]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
Sep 18 03:48:42 localhost sshd[9013]: Address 96.44.148.170 maps to 96.44.148.170.static.quadranet.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!<br />
<br />
Sep 18 03:48:42 localhost sshd[9013]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=96.44.148.170  user=root<br />
<br />
Sep 18 03:48:44 localhost sshd[9013]: Failed password for root from 96.44.148.170 port 46797 ssh2<br />
<br />
Sep 18 03:48:44 localhost sshd[9014]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
Sep 18 03:49:13 localhost sshd[9015]: Address 96.44.148.170 maps to 96.44.148.170.static.quadranet.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!<br />
<br />
Sep 18 03:49:13 localhost sshd[9015]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=96.44.148.170  user=root<br />
<br />
Sep 18 03:49:14 localhost sshd[9015]: Failed password for root from 96.44.148.170 port 50417 ssh2<br />
<br />
Sep 18 03:49:15 localhost sshd[9016]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
Sep 18 03:49:44 localhost sshd[9017]: Address 96.44.148.170 maps to 96.44.148.170.static.quadranet.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!<br />
<br />
Sep 18 03:49:44 localhost sshd[9017]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=96.44.148.170  user=root<br />
<br />
Sep 18 03:49:46 localhost sshd[9017]: Failed password for root from 96.44.148.170 port 54091 ssh2<br />
<br />
Sep 18 03:49:46 localhost sshd[9018]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
]]></description>
			<content:encoded><![CDATA[<br />
I found a log file that kind of worries me, it's not my website log file but /var/log/secure. Is this something to worry about? Looks like someone is trying to break in:<br />
<br />
(and I got quite a few more ip's trying to do the same thing or something similar)<br />
<br />
 <br />
<br />
 <br />
<br />
Sep 18 03:46:12 localhost sshd[9004]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
Sep 18 03:46:41 localhost sshd[9005]: Address 96.44.148.170 maps to 96.44.148.170.static.quadranet.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!<br />
<br />
Sep 18 03:46:41 localhost sshd[9005]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=96.44.148.170  user=root<br />
<br />
Sep 18 03:46:43 localhost sshd[9005]: Failed password for root from 96.44.148.170 port 60604 ssh2<br />
<br />
Sep 18 03:46:43 localhost sshd[9006]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
Sep 18 03:47:11 localhost sshd[9007]: Address 96.44.148.170 maps to 96.44.148.170.static.quadranet.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!<br />
<br />
Sep 18 03:47:11 localhost sshd[9007]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=96.44.148.170  user=root<br />
<br />
Sep 18 03:47:12 localhost sshd[9007]: Failed password for root from 96.44.148.170 port 35961 ssh2<br />
<br />
Sep 18 03:47:12 localhost sshd[9008]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
Sep 18 03:47:41 localhost sshd[9009]: Address 96.44.148.170 maps to 96.44.148.170.static.quadranet.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!<br />
<br />
Sep 18 03:47:41 localhost sshd[9009]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=96.44.148.170  user=root<br />
<br />
Sep 18 03:47:43 localhost sshd[9009]: Failed password for root from 96.44.148.170 port 39572 ssh2<br />
<br />
Sep 18 03:47:43 localhost sshd[9010]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
Sep 18 03:48:12 localhost sshd[9011]: Address 96.44.148.170 maps to 96.44.148.170.static.quadranet.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!<br />
<br />
Sep 18 03:48:12 localhost sshd[9011]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=96.44.148.170  user=root<br />
<br />
Sep 18 03:48:14 localhost sshd[9011]: Failed password for root from 96.44.148.170 port 43168 ssh2<br />
<br />
Sep 18 03:48:14 localhost sshd[9012]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
Sep 18 03:48:42 localhost sshd[9013]: Address 96.44.148.170 maps to 96.44.148.170.static.quadranet.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!<br />
<br />
Sep 18 03:48:42 localhost sshd[9013]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=96.44.148.170  user=root<br />
<br />
Sep 18 03:48:44 localhost sshd[9013]: Failed password for root from 96.44.148.170 port 46797 ssh2<br />
<br />
Sep 18 03:48:44 localhost sshd[9014]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
Sep 18 03:49:13 localhost sshd[9015]: Address 96.44.148.170 maps to 96.44.148.170.static.quadranet.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!<br />
<br />
Sep 18 03:49:13 localhost sshd[9015]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=96.44.148.170  user=root<br />
<br />
Sep 18 03:49:14 localhost sshd[9015]: Failed password for root from 96.44.148.170 port 50417 ssh2<br />
<br />
Sep 18 03:49:15 localhost sshd[9016]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
Sep 18 03:49:44 localhost sshd[9017]: Address 96.44.148.170 maps to 96.44.148.170.static.quadranet.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!<br />
<br />
Sep 18 03:49:44 localhost sshd[9017]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=96.44.148.170  user=root<br />
<br />
Sep 18 03:49:46 localhost sshd[9017]: Failed password for root from 96.44.148.170 port 54091 ssh2<br />
<br />
Sep 18 03:49:46 localhost sshd[9018]: Received disconnect from 96.44.148.170: 11: Bye Bye<br />
<br />
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Security warning: crond]]></title>
			<link>https://www.linux-noob.com/forums/thread-373.html</link>
			<pubDate>Thu, 05 May 2011 15:02:09 +0200</pubDate>
			<dc:creator><![CDATA[<a href="https://www.linux-noob.com/forums/member.php?action=profile&uid=3048">Dungeon-Dave</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.linux-noob.com/forums/thread-373.html</guid>
			<description><![CDATA[<br />
I've recently performed some analysis on a phpmyadmin-related vulnerability that downloads a bot onto an unsuspecting machine. I won't go into details, but sufficient to say that the bot masquerades as a "crond" process - looking at a normal process listing it is able to hide inconspicuously.<br />
<br />
 <br />
<br />
(I've witnessed this behaviour before, when the bot tried to masquerade as a httpd process - but was running /usr/local/bin/httpd rather than /usr/sbin/httpd so was more quickly spotted.)<br />
<br />
 <br />
<br />
On my servers, there should be only one crond process, root-owned. This bot tries to run under the apache account (httpd) or a normal user account for those that use suPHP. I wouldn't advise people to stop any crond process without properly analysing what those processes do, but a combination of "lsof -p PID" and "netstat -apn" ought to uncover any nefarious activity.<br />
<br />
 <br />
<br />
Just be warned! Thought I'd give people a heads-up here.<br />
<br />
]]></description>
			<content:encoded><![CDATA[<br />
I've recently performed some analysis on a phpmyadmin-related vulnerability that downloads a bot onto an unsuspecting machine. I won't go into details, but sufficient to say that the bot masquerades as a "crond" process - looking at a normal process listing it is able to hide inconspicuously.<br />
<br />
 <br />
<br />
(I've witnessed this behaviour before, when the bot tried to masquerade as a httpd process - but was running /usr/local/bin/httpd rather than /usr/sbin/httpd so was more quickly spotted.)<br />
<br />
 <br />
<br />
On my servers, there should be only one crond process, root-owned. This bot tries to run under the apache account (httpd) or a normal user account for those that use suPHP. I wouldn't advise people to stop any crond process without properly analysing what those processes do, but a combination of "lsof -p PID" and "netstat -apn" ought to uncover any nefarious activity.<br />
<br />
 <br />
<br />
Just be warned! Thought I'd give people a heads-up here.<br />
<br />
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Issue connecting to mysql port 3306]]></title>
			<link>https://www.linux-noob.com/forums/thread-536.html</link>
			<pubDate>Fri, 11 Dec 2009 23:45:26 +0100</pubDate>
			<dc:creator><![CDATA[<a href="https://www.linux-noob.com/forums/member.php?action=profile&uid=3452">JeffJustCollect</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.linux-noob.com/forums/thread-536.html</guid>
			<description><![CDATA[<br />
I've been trying to create a connection to mysql on a Linux server from Windows XP with MySQL ODBC 3.51 Driver. After setting all of my credentials to test the connection I get the following error.  "[MySQL][ODBC 3.51 Driver]Host is not allowed to connect to this MySQL server".  After looking up the error most references I found were to firewalls so for testing I disabled my local firewall and retried but got the same error message.  I wanted to make sure that the port was open on Linux so I ran netstat -nap on the server and it showed mysql was running on the expected port and listening.  I also went to this site to check my port. <a href="http://www.yougetsignal.com/tools/open-ports/" target="_blank" rel="noopener" class="mycode_url">http://www.yougetsignal.com/tools/open-ports/</a> and it stated that the port was open.<br />
<br />
 <br />
<br />
The mysql database is working fine when you are running queries locally but trying to connect from outside of the server is when you run into issues.  I don't really know what other steps to take in debugging the problem; any ideas or suggestions would be appreciated.  Thanks and let me know if you need any more details about the problem.<br />
<br />
 <br />
<br />
-Jeff<br />
<br />
]]></description>
			<content:encoded><![CDATA[<br />
I've been trying to create a connection to mysql on a Linux server from Windows XP with MySQL ODBC 3.51 Driver. After setting all of my credentials to test the connection I get the following error.  "[MySQL][ODBC 3.51 Driver]Host is not allowed to connect to this MySQL server".  After looking up the error most references I found were to firewalls so for testing I disabled my local firewall and retried but got the same error message.  I wanted to make sure that the port was open on Linux so I ran netstat -nap on the server and it showed mysql was running on the expected port and listening.  I also went to this site to check my port. <a href="http://www.yougetsignal.com/tools/open-ports/" target="_blank" rel="noopener" class="mycode_url">http://www.yougetsignal.com/tools/open-ports/</a> and it stated that the port was open.<br />
<br />
 <br />
<br />
The mysql database is working fine when you are running queries locally but trying to connect from outside of the server is when you run into issues.  I don't really know what other steps to take in debugging the problem; any ideas or suggestions would be appreciated.  Thanks and let me know if you need any more details about the problem.<br />
<br />
 <br />
<br />
-Jeff<br />
<br />
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Smoothwall stuck]]></title>
			<link>https://www.linux-noob.com/forums/thread-812.html</link>
			<pubDate>Sat, 04 Oct 2008 14:47:30 +0200</pubDate>
			<dc:creator><![CDATA[<a href="https://www.linux-noob.com/forums/member.php?action=profile&uid=3131">ifykh</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.linux-noob.com/forums/thread-812.html</guid>
			<description><![CDATA[<br />
Dear admin,<br />
<br />
 <br />
<br />
i am using smoothwall aprox. last 8 months &amp; that period I never feel any problem in it. but last few weeks I feel a problem frequently &amp; that is the smoothwall stucks. &amp; a problem I discover or u can say that the solution I adopt is change IP address of its RED interface &amp; its working again properly. but my point of view its not a solution.<br />
<br />
Nowadays, in our country, we face lot of power failure problem. that why my smoothwall server abnormly shut down 10 to 12 times daily. but this practice also starts a long time ago &amp; i never felt this problem.<br />
<br />
If u have any solution of this problem, kindly reply me.<br />
<br />
 <br />
<br />
thanx in advance.<br />
<br />
 <br />
<br />
 <br />
<br />
ifykh<br />
<br />
]]></description>
			<content:encoded><![CDATA[<br />
Dear admin,<br />
<br />
 <br />
<br />
i am using smoothwall aprox. last 8 months &amp; that period I never feel any problem in it. but last few weeks I feel a problem frequently &amp; that is the smoothwall stucks. &amp; a problem I discover or u can say that the solution I adopt is change IP address of its RED interface &amp; its working again properly. but my point of view its not a solution.<br />
<br />
Nowadays, in our country, we face lot of power failure problem. that why my smoothwall server abnormly shut down 10 to 12 times daily. but this practice also starts a long time ago &amp; i never felt this problem.<br />
<br />
If u have any solution of this problem, kindly reply me.<br />
<br />
 <br />
<br />
thanx in advance.<br />
<br />
 <br />
<br />
 <br />
<br />
ifykh<br />
<br />
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Default Passwords]]></title>
			<link>https://www.linux-noob.com/forums/thread-820.html</link>
			<pubDate>Thu, 25 Sep 2008 09:05:13 +0200</pubDate>
			<dc:creator><![CDATA[<a href="https://www.linux-noob.com/forums/member.php?action=profile&uid=3049">Jab</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.linux-noob.com/forums/thread-820.html</guid>
			<description><![CDATA[<br />
I recently started a job at a small accounting firm and I'm the only person in the IT department. The person who setup our mail server has left the company. I know a little about linux and I learn something new everyday. I was going through the logs today I noticed that someone was trying to login into one or more of the default user accounts to read or send mail. I'm not sure if they were successful. So my question is what is the worst that can happen if I change all the passwords on the default accounts. I don't imagine the world will end but if I change some of the passwords and something stops working (like the email) I'll have 50 people crapping on my head.<br />
<br />
 <br />
<br />
I think my system has been compromised:<br />
<br />
 <br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>Users logging in through sshd:    root:<br />
<br />
       10.10.2.57 (J_Bailey_Desktop): 2 times<br />
<br />
    spam:<br />
<br />
       58.213.125.25: 1 time</blockquote>
 <br />
<br />
I have no idea what the password for the spam account is and spam's shell is set to bin/false so how could this have happened? I have disabled login for this account and added a rule to the firewall to reject packets from that IP address.<br />
<br />
 <br />
<br />
Below you can see most of the accounts were tried 19 times except spam which was tried 10 times.<br />
<br />
 <br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>--------------------- Dovecot Begin ------------------------  <br />
<br />
 Dovecot disconnects:<br />
<br />
    Logged out: 299 Time(s)<br />
<br />
    no reason: 2 Time(s)<br />
<br />
 <br />
<br />
 **Unmatched Entries**<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;adm&gt;, method=PLAIN,<br />
<br />
rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;admin&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;guest&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;notice&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;office&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;qwerty&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;spam&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 10 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;support&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;temp&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;test&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;users&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;webmaster&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;website&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 38 Time(s)<br />
<br />
 <br />
<br />
 ---------------------- Dovecot End -------------------------</blockquote>
 <br />
<br />
I only have an A+ and a N+, this is starting to get a bit much for me. Any help would be appreciated.<br />
<br />
]]></description>
			<content:encoded><![CDATA[<br />
I recently started a job at a small accounting firm and I'm the only person in the IT department. The person who setup our mail server has left the company. I know a little about linux and I learn something new everyday. I was going through the logs today I noticed that someone was trying to login into one or more of the default user accounts to read or send mail. I'm not sure if they were successful. So my question is what is the worst that can happen if I change all the passwords on the default accounts. I don't imagine the world will end but if I change some of the passwords and something stops working (like the email) I'll have 50 people crapping on my head.<br />
<br />
 <br />
<br />
I think my system has been compromised:<br />
<br />
 <br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>Users logging in through sshd:    root:<br />
<br />
       10.10.2.57 (J_Bailey_Desktop): 2 times<br />
<br />
    spam:<br />
<br />
       58.213.125.25: 1 time</blockquote>
 <br />
<br />
I have no idea what the password for the spam account is and spam's shell is set to bin/false so how could this have happened? I have disabled login for this account and added a rule to the firewall to reject packets from that IP address.<br />
<br />
 <br />
<br />
Below you can see most of the accounts were tried 19 times except spam which was tried 10 times.<br />
<br />
 <br />
<br />
<blockquote class="mycode_quote"><cite>Quote:</cite>--------------------- Dovecot Begin ------------------------  <br />
<br />
 Dovecot disconnects:<br />
<br />
    Logged out: 299 Time(s)<br />
<br />
    no reason: 2 Time(s)<br />
<br />
 <br />
<br />
 **Unmatched Entries**<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;adm&gt;, method=PLAIN,<br />
<br />
rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;admin&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;guest&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;notice&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;office&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;qwerty&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;spam&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 10 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;support&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;temp&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;test&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;users&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;webmaster&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 19 Time(s)<br />
<br />
    dovecot: pop3-login: Aborted login (1 authentication attempts): user=&lt;website&gt;,<br />
<br />
method=PLAIN, rip=200.73.3.50, lip=192.168.4.200: 38 Time(s)<br />
<br />
 <br />
<br />
 ---------------------- Dovecot End -------------------------</blockquote>
 <br />
<br />
I only have an A+ and a N+, this is starting to get a bit much for me. Any help would be appreciated.<br />
<br />
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Setup Openafs with kerberos on ubuntu heron]]></title>
			<link>https://www.linux-noob.com/forums/thread-938.html</link>
			<pubDate>Wed, 28 May 2008 23:23:30 +0200</pubDate>
			<dc:creator><![CDATA[<a href="https://www.linux-noob.com/forums/member.php?action=profile&uid=2893">majikins</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.linux-noob.com/forums/thread-938.html</guid>
			<description><![CDATA[<br />
Hi<br />
<br />
 <br />
<br />
I've been reading up a lot on setting up a file server for linux desktops - I also have a mac.  There are a lot of how to's on NFS but I can't find any for Openafs and kerberos.  Can someone pls provide or point me in the right direction?<br />
<br />
 <br />
<br />
Thank you.<br />
<br />
]]></description>
			<content:encoded><![CDATA[<br />
Hi<br />
<br />
 <br />
<br />
I've been reading up a lot on setting up a file server for linux desktops - I also have a mac.  There are a lot of how to's on NFS but I can't find any for Openafs and kerberos.  Can someone pls provide or point me in the right direction?<br />
<br />
 <br />
<br />
Thank you.<br />
<br />
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[DEBIAN SSL BUG]]></title>
			<link>https://www.linux-noob.com/forums/thread-946.html</link>
			<pubDate>Sun, 18 May 2008 20:14:55 +0200</pubDate>
			<dc:creator><![CDATA[<a href="https://www.linux-noob.com/forums/member.php?action=profile&uid=1450">Varjagy</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.linux-noob.com/forums/thread-946.html</guid>
			<description><![CDATA[<br />
As we have read, there is now a weakness in the random number generator used by OpenSSL.<br />
<br />
 <br />
<br />
I suggest users of any Debian and Debian based system read <a href="http://www.debian.org/security/key-rollover/" target="_blank" rel="noopener" class="mycode_url">here</a>.<br />
<br />
]]></description>
			<content:encoded><![CDATA[<br />
As we have read, there is now a weakness in the random number generator used by OpenSSL.<br />
<br />
 <br />
<br />
I suggest users of any Debian and Debian based system read <a href="http://www.debian.org/security/key-rollover/" target="_blank" rel="noopener" class="mycode_url">here</a>.<br />
<br />
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[wild iptable issues]]></title>
			<link>https://www.linux-noob.com/forums/thread-951.html</link>
			<pubDate>Sat, 10 May 2008 07:10:47 +0200</pubDate>
			<dc:creator><![CDATA[<a href="https://www.linux-noob.com/forums/member.php?action=profile&uid=2864">papermate</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.linux-noob.com/forums/thread-951.html</guid>
			<description><![CDATA[<br />
Hey all, this being my first post please go easy on me:<br />
<br />
 <br />
<br />
I have the following problem,  I want to route all requests to port 80 to port 8171 and 443 to 8143 (both internally from within my box and externally from other computers).   The following is the configuration information on the iptables status:<br />
<br />
 <br />
<br />
Table: filter<br />
<br />
Chain INPUT (policy ACCEPT)<br />
<br />
num  target     prot opt source               destination<br />
<br />
 <br />
<br />
Chain FORWARD (policy ACCEPT)<br />
<br />
num  target     prot opt source               destination<br />
<br />
 <br />
<br />
Chain OUTPUT (policy ACCEPT)<br />
<br />
num  target     prot opt source               destination<br />
<br />
 <br />
<br />
Table: nat<br />
<br />
Chain PREROUTING (policy ACCEPT)<br />
<br />
num  target     prot opt source               destination<br />
<br />
1    REDIRECT   tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:80 redir ports 8171<br />
<br />
2    REDIRECT   tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:443 redir ports 8143<br />
<br />
 <br />
<br />
Chain POSTROUTING (policy ACCEPT)<br />
<br />
num  target     prot opt source               destination<br />
<br />
 <br />
<br />
Chain OUTPUT (policy ACCEPT)<br />
<br />
num  target     prot opt source               destination<br />
<br />
1    REDIRECT   tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:80 redir ports 8171<br />
<br />
2    REDIRECT   tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:443 redir ports 8143<br />
<br />
 <br />
<br />
 <br />
<br />
 <br />
<br />
Here is my configuration:<br />
<br />
 <br />
<br />
 <br />
<br />
# Generated by iptables-save v1.3.5 on Thu May  8 18:29:01 2008<br />
<br />
*nat<br />
<br />
<img src="https://www.linux-noob.com/forums/images/smilies/tongue.png" alt="Tongue" title="Tongue" class="smilie smilie_5" />REROUTING ACCEPT [22:3658]<br />
<br />
<img src="https://www.linux-noob.com/forums/images/smilies/tongue.png" alt="Tongue" title="Tongue" class="smilie smilie_5" />OSTROUTING ACCEPT [64:4788]<br />
<br />
:OUTPUT ACCEPT [57:4368]<br />
<br />
-A PREROUTING -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 8171<br />
<br />
-A PREROUTING -p tcp -m tcp --dport 443 -j REDIRECT --to-ports 8143<br />
<br />
-A OUTPUT -o lo -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 8171<br />
<br />
-A OUTPUT -o lo -p tcp -m tcp --dport 443 -j REDIRECT --to-ports 8143<br />
<br />
COMMIT<br />
<br />
# Completed on Thu May  8 18:29:01 2008<br />
<br />
# Generated by iptables-save v1.3.5 on Thu May  8 18:29:01 2008<br />
<br />
*filter<br />
<br />
:INPUT ACCEPT [21858:11609795]<br />
<br />
:FORWARD ACCEPT [0:0]<br />
<br />
:OUTPUT ACCEPT [22001:18526588]<br />
<br />
COMMIT<br />
<br />
# Completed on Thu May  8 18:29:01 2008<br />
<br />
 <br />
<br />
 <br />
<br />
Now the configuration for port 80 works fine and routs to 8171 when accessed from the box itself or from an outside computer.  When I access 443 from an outside computer it correctly forwards to 8143.  But when I try and access 443 from the box itself, it doesn't seem to route.  What is wrong with my config???<br />
<br />
]]></description>
			<content:encoded><![CDATA[<br />
Hey all, this being my first post please go easy on me:<br />
<br />
 <br />
<br />
I have the following problem,  I want to route all requests to port 80 to port 8171 and 443 to 8143 (both internally from within my box and externally from other computers).   The following is the configuration information on the iptables status:<br />
<br />
 <br />
<br />
Table: filter<br />
<br />
Chain INPUT (policy ACCEPT)<br />
<br />
num  target     prot opt source               destination<br />
<br />
 <br />
<br />
Chain FORWARD (policy ACCEPT)<br />
<br />
num  target     prot opt source               destination<br />
<br />
 <br />
<br />
Chain OUTPUT (policy ACCEPT)<br />
<br />
num  target     prot opt source               destination<br />
<br />
 <br />
<br />
Table: nat<br />
<br />
Chain PREROUTING (policy ACCEPT)<br />
<br />
num  target     prot opt source               destination<br />
<br />
1    REDIRECT   tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:80 redir ports 8171<br />
<br />
2    REDIRECT   tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:443 redir ports 8143<br />
<br />
 <br />
<br />
Chain POSTROUTING (policy ACCEPT)<br />
<br />
num  target     prot opt source               destination<br />
<br />
 <br />
<br />
Chain OUTPUT (policy ACCEPT)<br />
<br />
num  target     prot opt source               destination<br />
<br />
1    REDIRECT   tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:80 redir ports 8171<br />
<br />
2    REDIRECT   tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:443 redir ports 8143<br />
<br />
 <br />
<br />
 <br />
<br />
 <br />
<br />
Here is my configuration:<br />
<br />
 <br />
<br />
 <br />
<br />
# Generated by iptables-save v1.3.5 on Thu May  8 18:29:01 2008<br />
<br />
*nat<br />
<br />
<img src="https://www.linux-noob.com/forums/images/smilies/tongue.png" alt="Tongue" title="Tongue" class="smilie smilie_5" />REROUTING ACCEPT [22:3658]<br />
<br />
<img src="https://www.linux-noob.com/forums/images/smilies/tongue.png" alt="Tongue" title="Tongue" class="smilie smilie_5" />OSTROUTING ACCEPT [64:4788]<br />
<br />
:OUTPUT ACCEPT [57:4368]<br />
<br />
-A PREROUTING -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 8171<br />
<br />
-A PREROUTING -p tcp -m tcp --dport 443 -j REDIRECT --to-ports 8143<br />
<br />
-A OUTPUT -o lo -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 8171<br />
<br />
-A OUTPUT -o lo -p tcp -m tcp --dport 443 -j REDIRECT --to-ports 8143<br />
<br />
COMMIT<br />
<br />
# Completed on Thu May  8 18:29:01 2008<br />
<br />
# Generated by iptables-save v1.3.5 on Thu May  8 18:29:01 2008<br />
<br />
*filter<br />
<br />
:INPUT ACCEPT [21858:11609795]<br />
<br />
:FORWARD ACCEPT [0:0]<br />
<br />
:OUTPUT ACCEPT [22001:18526588]<br />
<br />
COMMIT<br />
<br />
# Completed on Thu May  8 18:29:01 2008<br />
<br />
 <br />
<br />
 <br />
<br />
Now the configuration for port 80 works fine and routs to 8171 when accessed from the box itself or from an outside computer.  When I access 443 from an outside computer it correctly forwards to 8143.  But when I try and access 443 from the box itself, it doesn't seem to route.  What is wrong with my config???<br />
<br />
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[please help........opening ports]]></title>
			<link>https://www.linux-noob.com/forums/thread-959.html</link>
			<pubDate>Tue, 29 Apr 2008 13:41:25 +0200</pubDate>
			<dc:creator><![CDATA[<a href="https://www.linux-noob.com/forums/member.php?action=profile&uid=2852">thehappyappy</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.linux-noob.com/forums/thread-959.html</guid>
			<description><![CDATA[<br />
Please can somebody help me. I'm trying to open ports 999, 1982 and 1983 but am not having much luck. I followed the post <a href="http://&lt;___base_url___&gt;/index.php?showtopic=472" target="_blank" rel="noopener" class="mycode_url">how to open ports</a> and haven't been successful. I was told to make sure that your server TCP ports: 999, 1982, 1983 are fully open inbound and outbound and that destination IP address for those ports is 72.232.181.106.<br />
<br />
I've been trying for ages to get these ports open, but haven't had any luck.<br />
<br />
]]></description>
			<content:encoded><![CDATA[<br />
Please can somebody help me. I'm trying to open ports 999, 1982 and 1983 but am not having much luck. I followed the post <a href="http://&lt;___base_url___&gt;/index.php?showtopic=472" target="_blank" rel="noopener" class="mycode_url">how to open ports</a> and haven't been successful. I was told to make sure that your server TCP ports: 999, 1982, 1983 are fully open inbound and outbound and that destination IP address for those ports is 72.232.181.106.<br />
<br />
I've been trying for ages to get these ports open, but haven't had any luck.<br />
<br />
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Syslog-ng triggers]]></title>
			<link>https://www.linux-noob.com/forums/thread-1029.html</link>
			<pubDate>Fri, 08 Feb 2008 17:18:30 +0100</pubDate>
			<dc:creator><![CDATA[<a href="https://www.linux-noob.com/forums/member.php?action=profile&uid=2744">crc_error</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.linux-noob.com/forums/thread-1029.html</guid>
			<description><![CDATA[<br />
I am looking for a way to get syslog-ng to trigger an event. <br />
<br />
To be more specific: If I recieve a syslog-message with some speciel text e.g "thingy". I want the syslog-server to send an email.<br />
<br />
Is this something that can be done using only syslog-ng and sendmail???<br />
<br />
]]></description>
			<content:encoded><![CDATA[<br />
I am looking for a way to get syslog-ng to trigger an event. <br />
<br />
To be more specific: If I recieve a syslog-message with some speciel text e.g "thingy". I want the syslog-server to send an email.<br />
<br />
Is this something that can be done using only syslog-ng and sendmail???<br />
<br />
]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[OpenSSL In Fedora 8]]></title>
			<link>https://www.linux-noob.com/forums/thread-1063.html</link>
			<pubDate>Sat, 22 Dec 2007 19:43:45 +0100</pubDate>
			<dc:creator><![CDATA[<a href="https://www.linux-noob.com/forums/member.php?action=profile&uid=1624">metalx</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.linux-noob.com/forums/thread-1063.html</guid>
			<description><![CDATA[<br />
I'm trying to setup a radius server for some wireless clients,  I want to use certificates for authentication.  So I need to create a root certificate but I can't find the CA.pl script on Fedora 8.  Does anyone know if it's called something else or if I have to download it because I've been looking for it for some time and I can't find it. I used the Fedora 8 live CD for my install if that makes any difference.<br />
<br />
 <br />
<br />
Thanks in advance for any help.<br />
<br />
]]></description>
			<content:encoded><![CDATA[<br />
I'm trying to setup a radius server for some wireless clients,  I want to use certificates for authentication.  So I need to create a root certificate but I can't find the CA.pl script on Fedora 8.  Does anyone know if it's called something else or if I have to download it because I've been looking for it for some time and I can't find it. I used the Fedora 8 live CD for my install if that makes any difference.<br />
<br />
 <br />
<br />
Thanks in advance for any help.<br />
<br />
]]></content:encoded>
		</item>
	</channel>
</rss>