|
From: Bruce S. <bw...@ar...> - 2003-05-29 15:46:28
|
> >>># Prevent NetBIOS and Samba from leaking.
> >>>${IPTABLES} -t nat -A PREROUTING -p TCP --dport 137:139 -j DROP
> >>>${IPTABLES} -t nat -A PREROUTING -p UDP --dport 137:139 -j DROP
> >>>${IPTABLES} -t nat -A PREROUTING -p TCP --dport 445 -j DROP
> >>>${IPTABLES} -t nat -A PREROUTING -p UDP --dport 445 -j DROP
> >>
> >>Might want to consider Port 135 too.
> >
> > The script I "borrowed" has 135:139 on the TCP chain and 137:139 on UDP.
> >
> > How about using 135:139 on both lines?
>
> Would not do this as Port 136 is not related to Windows and there
> might be a valid service using it.
Even the tutorial script blocks 135:139
http://www.bec.at/support/iptables-tutorial/examplecode.html
136 must not be used very often, but I'll add the extra overhead not to
block it.
> So where are the ftp modules?
To be loaded in the next version of the script? :-)
I see the tutorial optionally loads "ipt_owner". What is that?
Should I load it too?
The kernel source code only says:
/* Kernel module to match various things tied to sockets associated with
locally generated outgoing packets. */
Whatever that means ...
- BS
|