My Linux box is set with a very strong password (8 characters with capital/lower case letters with no vowels, numbers, and symbols) and it uses iptables. Can it be vulnerable?
This is the firewall configuration I have:
# Generated by iptables-save v1.4.8 on Sat Jul 10 10:14:52 2010<br /> *nat<br /> :PREROUTING ACCEPT [75044:8540159]<br /> :POSTROUTING ACCEPT [1360:169898]<br /> :OUTPUT ACCEPT [37035:3065074]<br /> -A POSTROUTING -o eth0 -j MASQUERADE<br /> COMMIT<br /> # Completed on Sat Jul 10 10:14:52 2010<br /> # Generated by iptables-save v1.4.8 on Sat Jul 10 10:14:52 2010<br /> *filter<br /> :INPUT DROP [45:5599]<br /> :FORWARD ACCEPT [0:0]<br /> :OUTPUT ACCEPT [13:2823]<br /> -A INPUT -p tcp -m tcp -m multiport --dports 22,25,53,80,3389,5060,5080,5900,5901,5902,10000 -j ACCEPT<br /> -A INPUT -p udp -m udp --dport 10000:20000 -j ACCEPT<br /> -A INPUT -p udp -m udp -m multiport --dports 5060,5080 -j ACCEPT<br /> -A INPUT -i lo -j ACCEPT<br /> -A INPUT -i eth1 -j ACCEPT<br /> -A INPUT -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT<br /> -A FORWARD -i eth1 -o eth0 -j ACCEPT<br /> -A FORWARD -i eth0 -o eth1 -m state --state RELATED,ESTABLISHED -j ACCEPT<br /> COMMIT<br /> # Completed on Sat Jul 10 10:14:52 2010<br /> # Generated by iptables-save v1.4.8 on Sat Jul 10 10:14:52 2010<br /> *mangle<br /> :PREROUTING ACCEPT [1585:191669]<br /> :INPUT ACCEPT [1338:146477]<br /> :FORWARD ACCEPT [246:44963]<br /> :OUTPUT ACCEPT [1102:222571]<br /> :POSTROUTING ACCEPT [1348:267534]<br /> :asterisk - [0:0]<br /> :common - [0:0]<br /> -A FORWARD -i eth1 -o eth0 -j MARK --set-xmark 0x3/0xffffffff<br /> -A FORWARD -i eth1 -o eth0 -j common<br /> -A FORWARD -i eth1 -o eth0 -j asterisk<br /> -A FORWARD -i eth1 -o eth0 -p icmp -j MARK --set-xmark 0x1/0xffffffff<br /> -A FORWARD -i eth0 -o eth1 -j MARK --set-xmark 0x3/0xffffffff<br /> -A FORWARD -i eth0 -o eth1 -j common<br /> -A FORWARD -i eth0 -o eth1 -j asterisk<br /> -A FORWARD -i eth0 -o eth1 -p icmp -j MARK --set-xmark 0x1/0xffffffff<br /> -A asterisk -p udp -m udp --sport 5060 -j MARK --set-xmark 0x1/0xffffffff<br /> -A asterisk -p udp -m udp --dport 5060 -j MARK --set-xmark 0x1/0xffffffff<br /> -A asterisk -p tcp -m tcp --dport 5036 -j MARK --set-xmark 0x1/0xffffffff<br /> -A asterisk -p udp -m udp --dport 5036 -j MARK --set-xmark 0x1/0xffffffff<br /> -A asterisk -p udp -m udp --dport 4569 -j MARK --set-xmark 0x1/0xffffffff<br /> -A asterisk -p udp -m udp --sport 10000:20000 -j MARK --set-xmark 0x1/0xffffffff<br /> -A common -p tcp -m tcp --dport 80 -j MARK --set-xmark 0x2/0xffffffff<br /> -A common -p tcp -m tcp --dport 8080 -j MARK --set-xmark 0x2/0xffffffff<br /> -A common -p tcp -m tcp --dport 443 -j MARK --set-xmark 0x2/0xffffffff<br /> -A common -p tcp -m tcp --dport 110 -j MARK --set-xmark 0x2/0xffffffff<br /> -A common -p tcp -m tcp --dport 119 -j MARK --set-xmark 0x2/0xffffffff<br /> -A common -p tcp -m tcp --dport 25 -j MARK --set-xmark 0x2/0xffffffff<br /> -A common -p udp -m udp --dport 53 -j MARK --set-xmark 0x2/0xffffffff<br /> -A common -p udp -m udp --dport 68 -j MARK --set-xmark 0x2/0xffffffff<br /> -A common -p udp -m udp --dport 22 -j MARK --set-xmark 0x2/0xffffffff<br /> -A common -p udp -m udp --dport 3389 -j MARK --set-xmark 0x2/0xffffffff<br /> COMMIT<br /> # Completed on Sat Jul 10 10:14:52 2010
Webmin is not installed. It allows you to access the core parts of your system, such as iptables and network interfaces, including server programs like Apache and OpenLDAP Server. It's not been used since I have my server setup without it and with config files backed up. It's the beauty of Linux. I run Ubuntu Server 10.10 Alpha 2. :)
Add comment