Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Port 113 security

From: Glynn Clements <glynn.clements(at)virgin.net>
Date: Thu Mar 06 2003 - 19:19:10 EST

Chris Santerre wrote:

> Currently I block port 113 (ident) on the firewall. I block everything and

Actually, this is probably because your in.identd is pidentd, which automatically spawns a pool of child processes:

  543 ?        S      0:00 identd -e -o
  547 ?        S      0:00  \_ identd -e -o
  548 ?        S      0:00      \_ identd -e -o
  549 ?        S      0:00      \_ identd -e -o
  550 ?        S      0:00      \_ identd -e -o

> Nothing big really. System is working great. Logs get
> filled a little much with DENY messages.

So don't log denied ident connections.

> So does evryone generally let these thru?

Yes. If I don't want to give out this information, I don't run identd.

Do you need help?X

If you block (DENY or REJECT) ident connections, the remote server will often wait for the ident request to time out before processing the client's request. If you allow the connection through, but don't run identd, the server will receive a TCP RST and resume processing the request.

A few servers (mostly IRC servers) insist upon a successful ident lookup. If you want to use such servers, you have to allow the connections and you have to process them. However, you don't have to give out meaningful information. I normally have pidentd give out UIDs rather than usernames; if someone reports a problem, the UID may help me, but it's meaningless to anyone else.

> Any exploits?

Well, I'm still using the pidentd from the RedHat 6.2 CD; they haven't felt the need to publish an update in that time (as opposed to 6 updates of OpenSSL and glibc, 5 for fetchmail, ...).

> is there a way to get rid of those in.identd processes if I leave it

Stop running it.

-- 
Glynn Clements 
Received on Mon Mar 10 14:16:39 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:20 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library