Linux One Liner – Security

Here are a few useful one liners for Linux Security. View current packet filtering rules. (i.e. what can and can’t access your computer.
<br /> $ iptables -L<br />

On older distros, iptables may not be in place. Try ipchains. A good reference and tools on iptables can be found at www.iptablesrocks.org .

Identity open ports on your installation using the Network exploration tool and security scanner.

<br /> $ nmap -p 1-65535 localhost<br />

On my computer this returned
<br /> Starting nmap 3.70 ( http://www.insecure.org/nmap/ ) at 2006-06-11 12:22 EST<br /> Interesting ports on lamda.arabx (127.0.0.1):<br /> (The 65525 ports scanned but not shown below are in state: closed)<br /> PORT STATE SERVICE<br /> 22/tcp open ssh<br /> 25/tcp open smtp<br /> 111/tcp open rpcbind<br /> 139/tcp open netbios-ssn<br /> 445/tcp open microsoft-ds<br /> 631/tcp open ipp<br /> 901/tcp open samba-swat<br /> 8005/tcp open unknown<br /> 32769/tcp open unknown<br /> 34315/tcp open unknown<br />

That’s a cause for a bit of concern. Will need to look into that more.

Looking into more detail, I know what runs samba-swat but let’s confirm.

<br /> $ fuser -n tcp 901<br />

This provides a confirmation and the Process id of the process using this port. A more susync output would be.
<br /> $ ps -ef | grep `fuser -n tcp 901 | tail -1 | cut -d: -f2` | grep -v grep<br />

This gives me.
<br /> root 3356 1 0 Jun10 ? 00:00:00 xinetd -stayalive -pidfile /var/run/xinetd.pid<br />

Which is exactly right, Samba Swat (the web interface for Samba) which you access at http://localhost:901 is configured using xinetd.

Now to investigate some ports I didn’t know were open.

Tagged with: General Linux One Liners

Related Posts

Sysbench Under the Covers

Sysbench is a popular open-source benchmarking tool designed to evaluate the performance of system components such as CPU, memory, disk I/O, and databases. It is commonly used for testing MySQL, PostgreSQL, and other databases under different load conditions.

Read more

Tracking new AWS Database Infrastructure Availability

AWS can drop 10+ articles a day just in the What’s New feed. You either need an eagle eye, or luck to keep up if you run multiple AWS database products across multiple regions and managing infrastructure.

Read more

Evaluating Readyset Caching for MySQL

Readyset is a database caching solution for MySQL and PostgreSQL . For applications that have increased load on your primary database, or use scale-out infrastructure to support a high-read workload, ReadySet can be a drop-in solution to address current performance issues.

Read more