par cyprien2 » 15 Jan 2007 12:09
Je me permet d'envoyer le résultat de iptables...
root@ipcop:~ # iptables -L
Chain INPUT (policy DROP)
target prot opt source destination
ipac~o all -- anywhere anywhere
BADTCP all -- anywhere anywhere
tcp -- anywhere anywhere tcp flags:SYN,RST,ACK/SYN limit: avg 10/sec burst 5
CUSTOMINPUT all -- anywhere anywhere
GUIINPUT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all -- anywhere anywhere state NEW
DROP all -- 127.0.0.0/8 anywhere state NEW
DROP all -- anywhere 127.0.0.0/8 state NEW
ACCEPT !icmp -- anywhere anywhere state NEW
ACCEPT all -- anywhere anywhere
DHCPBLUEINPUT all -- anywhere anywhere
IPSECRED all -- anywhere anywhere
IPSECBLUE all -- anywhere anywhere
WIRELESSINPUT all -- anywhere anywhere state NEW
REDINPUT all -- anywhere anywhere
XTACCESS all -- anywhere anywhere state NEW
LOG all -- anywhere anywhere limit: avg 10/min burst 5 LOG level warning prefix `INPUT '
Chain FORWARD (policy DROP)
target prot opt source destination
ipac~fi all -- anywhere anywhere
ipac~fo all -- anywhere anywhere
BADTCP all -- anywhere anywhere
TCPMSS tcp -- anywhere anywhere tcp flags:SYN,RST/SYN TCPMSS clamp to PMTU
CUSTOMFORWARD all -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all -- anywhere anywhere state NEW
DROP all -- 127.0.0.0/8 anywhere state NEW
DROP all -- anywhere 127.0.0.0/8 state NEW
ACCEPT all -- anywhere anywhere state NEW
ACCEPT all -- anywhere anywhere
WIRELESSFORWARD all -- anywhere anywhere state NEW
REDFORWARD all -- anywhere anywhere
PORTFWACCESS all -- anywhere anywhere state NEW
LOG all -- anywhere anywhere limit: avg 10/min burst 5 LOG level warning prefix `OUTPUT '
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
ipac~i all -- anywhere anywhere
CUSTOMOUTPUT all -- anywhere anywhere
Chain BADTCP (2 references)
target prot opt source destination
PSCAN tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/FIN,PSH,URG
PSCAN tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/NONE
PSCAN tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/FIN
PSCAN tcp -- anywhere anywhere tcp flags:SYN,RST/SYN,RST
PSCAN tcp -- anywhere anywhere tcp flags:FIN,SYN/FIN,SYN
NEWNOTSYN tcp -- anywhere anywhere tcp flags:!SYN,RST,ACK/SYN state NEW
Chain CUSTOMFORWARD (1 references)
target prot opt source destination
Chain CUSTOMINPUT (1 references)
target prot opt source destination
Chain CUSTOMOUTPUT (1 references)
target prot opt source destination
Chain DHCPBLUEINPUT (1 references)
target prot opt source destination
Chain DMZHOLES (0 references)
target prot opt source destination
Chain GUIINPUT (1 references)
target prot opt source destination
ACCEPT icmp -- anywhere anywhere icmp echo-request
Chain IPSECBLUE (1 references)
target prot opt source destination
Chain IPSECRED (1 references)
target prot opt source destination
Chain LOG_DROP (0 references)
target prot opt source destination
LOG all -- anywhere anywhere limit: avg 10/min burst 5 LOG level warning
DROP all -- anywhere anywhere
Chain LOG_REJECT (0 references)
target prot opt source destination
LOG all -- anywhere anywhere limit: avg 10/min burst 5 LOG level warning
REJECT all -- anywhere anywhere reject-with icmp-port-unreachable
Chain NEWNOTSYN (1 references)
target prot opt source destination
LOG all -- anywhere anywhere limit: avg 10/min burst 5 LOG level warning prefix `NEW not SYN? '
DROP all -- anywhere anywhere
Chain PORTFWACCESS (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere 192.168.1.20 tcp dpt:ssh
ACCEPT tcp -- anywhere 192.168.1.21 tcp dpt:5901
ACCEPT tcp -- anywhere 192.168.1.22 tcp dpt:5902
ACCEPT tcp -- anywhere 192.168.1.23 tcp dpt:5903
ACCEPT tcp -- anywhere 192.168.1.25 tcp dpt:5906
ACCEPT tcp -- anywhere 192.168.1.27 tcp dpt:5907
ACCEPT tcp -- anywhere 192.168.1.28 tcp dpt:5908
ACCEPT tcp -- anywhere 192.168.1.29 tcp dpt:5905
ACCEPT tcp -- anywhere 192.168.1.30 tcp dpt:5909
ACCEPT tcp -- anywhere 192.168.1.26 tcp dpt:5910
ACCEPT tcp -- anywhere 192.168.1.154 tcp dpt:5912
ACCEPT tcp -- anywhere 192.168.1.31 tcp dpt:5911
ACCEPT tcp -- anywhere 192.168.1.45 tcp dpt:http
ACCEPT tcp -- anywhere 192.168.1.45 tcp dpt:https
ACCEPT tcp -- anywhere 192.168.1.45 tcp dpt:ms-wbt-server
ACCEPT tcp -- anywhere 192.168.1.45 tcp dpt:pptp
ACCEPT tcp -- anywhere 192.168.1.9 tcp dpt:5919
ACCEPT tcp -- anywhere 192.168.1.7 tcp dpt:5917
ACCEPT tcp -- anywhere 192.168.1.6 tcp dpt:5916
ACCEPT tcp -- anywhere 192.168.1.5 tcp dpt:5915
ACCEPT tcp -- anywhere 192.168.1.10 tcp dpt:5920
ACCEPT tcp -- anywhere 192.168.1.33 tcp dpt:5933
ACCEPT tcp -- anywhere 192.168.1.48 tcp dpt:5948
ACCEPT tcp -- anywhere 192.168.1.200 tcp dpt:aol
ACCEPT tcp -- anywhere 192.168.1.34 tcp dpt:5937
ACCEPT tcp -- anywhere 192.168.1.145 tcp dpt:5900
ACCEPT tcp -- anywhere 192.168.1.35 tcp dpt:5935
Chain PSCAN (5 references)
target prot opt source destination
LOG tcp -- anywhere anywhere limit: avg 10/min burst 5 LOG level warning prefix `TCP Scan? '
LOG udp -- anywhere anywhere limit: avg 10/min burst 5 LOG level warning prefix `UDP Scan? '
LOG icmp -- anywhere anywhere limit: avg 10/min burst 5 LOG level warning prefix `ICMP Scan? '
LOG all -f anywhere anywhere limit: avg 10/min burst 5 LOG level warning prefix `FRAG Scan? '
DROP all -- anywhere anywhere
Chain REDFORWARD (1 references)
target prot opt source destination
Chain REDINPUT (1 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
Chain WIRELESSFORWARD (1 references)
target prot opt source destination
Chain WIRELESSINPUT (1 references)
target prot opt source destination
Chain XTACCESS (1 references)
target prot opt source destination
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:ident
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:rsh-spx
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:http
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:https
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:ms-wbt-server
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:pptp
ACCEPT udp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr udp dpt:5901
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5902
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5903
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5906
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5907
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5908
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5909
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5910
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5911
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5912
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5919
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5917
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5920
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5916
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5915
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5912
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:ssh
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:upnotifyp
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5933
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5948
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:upnotifyp
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5937
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5937
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5900
ACCEPT tcp -- anywhere ARennes-256-1-87-59.w90-32.abo.wanadoo.fr tcp dpt:5935
Chain ipac~fi (1 references)
target prot opt source destination
all -- anywhere anywhere
all -- anywhere anywhere
Chain ipac~fo (1 references)
target prot opt source destination
all -- anywhere anywhere
all -- anywhere anywhere
Chain ipac~i (1 references)
target prot opt source destination
all -- anywhere anywhere
all -- anywhere anywhere
Chain ipac~o (1 references)
target prot opt source destination
all -- anywhere anywhere
all -- anywhere anywhere