Page 1 of 1

several iptables questions

PostPosted: Thu Nov 21, 2002 10:59 am
by truhla
hello...

i have experienced many problems with
iptables stealth-blocking rules (tested in co-operation with nmap :)

1) how to block nmap stealth FIN SCAN ??
i have tried

iptables -A INPUT -d dest_ip -p tcp -m stealth --tcp-flags FIN SYN -j DROP ,

but doesn't work... and also, how to disable XMASS or NULL scan ?

2) is it possible to block such an nmap RPC scan ?

thanks a lot for any help...

truhla
[/b]

PostPosted: Sat Nov 23, 2002 4:18 pm
by spender
the stealth module won't stop those kinds of scans..it simply drops syns coming to unserved tcp ports, and drops udp packets coming to unserved udp ports. I think the "unclean" module can help you out with those though.

-Brad