Results 1 to 4 of 4

Thread: IPTABLES problem or fault?

  1. #1
    Join Date
    Jul 2007
    Location
    Austria
    Posts
    1,336

    IPTABLES problem or fault?

    Well, I'm running vsftpd, lighttpd, ssh on my asus wl500gP in AP Mode, behind a fritzbox modem/router/voip. Ports 21,22 and 80 are forwarded to asus wl500gP. Everything works fine and stable.
    In order to get rid of my beloved script-kiddies and several hackers, I started iptables on my asus, because avoiding access from several ip's as well as brute force (with ipt_recent) should be easily possible. Everything works just perfect, even ipt_recent (thanks al37919!) - when I test it, it seems to work stable anytime.

    And in case that I missed something (I'm not an iptables expert), I wrote a script, just adding an IP to a block list when something is wrong with an access, like 3 times a message like "non existing user".

    Yesterday I recognized, that the complete subnet of a hacker is already blocked, furthermore my script realized that something is wrong and has blocked the ip again - but nothing happens!

    As you can see in an excerpt of my logfile, access from this ip is still possible, even after double blocking! And to show you, that everything is ok with iptables config, I've added the output of 'iptables -n -L'

    Does anybody know whats going on? What I am doing wrong?
    When I test it with my mobile modem, it works!
    How can an ip 220.x.x.x can come through, when its already blocked?

    Any help is appreciated.

    Newbiefan
    Attached Files Attached Files
    Alle HowTo's, all howto's

    RT-N16 1.9.2.7-rtn-r3121, Samba, VSFTP, Lightthpd, PHP, Perl, MySQL, Serendipity, Aria2web, HDD 640GB
    RT-N66U, 16GB MicroSD/ 2 Partitions, 2,5" HDD 1TB, running with Merlin's FW and Entware, 16 Mbit A1,
    Netgear DGND 3700V2, QNAP TS119PII 4 TB, QNAP TS209 2 TB Raid1, Backup Synology DS107+ 1 TB, HP CP1515n

  2. #2
    Join Date
    Dec 2007
    Location
    The Netherlands - Eindhoven
    Posts
    1,767
    what about your post-firewall script?

    I do have to admit I had the same problem with FTP, but I fixed that by turning on the anti brute force mode in the firewall (webadmin)

  3. #3
    Join Date
    Jul 2007
    Location
    Austria
    Posts
    1,336
    Quote Originally Posted by wpte
    what about your post-firewall script?
    Hi wpte!
    There is just one problem: in AP Mode there is no webif firewall.
    And I start my firewall-script after any services - will change it later - it's still under testing.

    Well, script kiddies are smart - hence I had to be better - and I've done it the tricky way. I really like the so called bad guys - they allow me to optimize my iptable-setup without paying even a cent - look, the best test situation which you can imagine free of charge!
    And I can tell you so far - I catched them - I'm able to block them whenever and however I want. And every day/night I get another info free of charge. When I've finished this setup (shortly), I'll write a howto about it. This setup is useable in any firewalled router mode as well as in ap mode, because it is based on the INPUT chain only.
    The only part what I do not know until now is the fact, that they can somehow "bypass" a reject list. Maybe they work with different flags, but in any case they do not have an invalid state. It is very interesting anyway
    and very useful, at least a lot of informations.
    The only point what makes me angry is sometimes my lowered bandwidth.
    Thanks anyway wpte, soon I'll do something......
    have a nice evening!
    newbiefan
    Alle HowTo's, all howto's

    RT-N16 1.9.2.7-rtn-r3121, Samba, VSFTP, Lightthpd, PHP, Perl, MySQL, Serendipity, Aria2web, HDD 640GB
    RT-N66U, 16GB MicroSD/ 2 Partitions, 2,5" HDD 1TB, running with Merlin's FW and Entware, 16 Mbit A1,
    Netgear DGND 3700V2, QNAP TS119PII 4 TB, QNAP TS209 2 TB Raid1, Backup Synology DS107+ 1 TB, HP CP1515n

  4. #4
    Join Date
    Jul 2007
    Location
    Austria
    Posts
    1,336

    IPTABLES PROBLEM SOLVED

    Sorry guys, it was my mistake - I missunderstood something.

    Just fyi:
    never user mac rules for sources ouside of your network!
    Alle HowTo's, all howto's

    RT-N16 1.9.2.7-rtn-r3121, Samba, VSFTP, Lightthpd, PHP, Perl, MySQL, Serendipity, Aria2web, HDD 640GB
    RT-N66U, 16GB MicroSD/ 2 Partitions, 2,5" HDD 1TB, running with Merlin's FW and Entware, 16 Mbit A1,
    Netgear DGND 3700V2, QNAP TS119PII 4 TB, QNAP TS209 2 TB Raid1, Backup Synology DS107+ 1 TB, HP CP1515n

Similar Threads

  1. [HowTo] Install and configure Oleg's firmware
    By wengi in forum WL-500gP Tutorials
    Replies: 957
    Last Post: 22-02-2013, 22:24
  2. Шейпер с приоретизацией по портам
    By indlg0 in forum Russian Discussion - РУССКИЙ (RU)
    Replies: 65
    Last Post: 18-01-2010, 11:35
  3. wl-700ge + kamikaze/x-wrt: wie ports fьr emule/bittorrent freigeben
    By nice in forum German Discussion - Deutsch (DE)
    Replies: 2
    Last Post: 31-05-2009, 12:24
  4. mldonkey- lowID problem and version issue
    By Nostry in forum WL-500gP Q&A
    Replies: 2
    Last Post: 10-04-2009, 17:53
  5. MSN blocking
    By sonice in forum WL-500gP Q&A
    Replies: 5
    Last Post: 16-01-2009, 17:37

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •