Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 23rd April 2006, 05:35 AM
Zigzagcom Offline
Registered User
 
Join Date: Feb 2005
Location: CALIFORNIA, yeah
Age: 86
Posts: 1,657
Default firewall rules...

Over the last few weeks I have been teaching myself iptables. Lately I have been trying to find the source of the default firewall rules/configuration for Fedora Core.
Here it is:
Within the "system-config-securitylevel-1.6.16-1.i386.rpm_FILES", (which I extracted), is the script /system-config-securitylevel-1.6.16-1.i386.rpm_FILES/usr/share/system-config-securitylevel/system-config-securitylevel.py,
which points to /usr/sbin/lokkit. Viewing the file in "mc", I finally found the source.

Now I know, and thought I'd share my insignificant discovery with those that may have wondered too.
Attached Thumbnails
Click image for larger version

Name:	default_firewall_rules.png
Views:	97
Size:	36.9 KB
ID:	7974  
__________________
Ziggy

Last edited by Zigzagcom; 23rd April 2006 at 05:39 AM.
Reply With Quote
  #2  
Old 23rd April 2006, 03:15 PM
brandor's Avatar
brandor Offline
Registered User
 
Join Date: May 2005
Posts: 534
Aren't the default rules stored in a script in /etc/sysconfig?
Reply With Quote
  #3  
Old 23rd April 2006, 04:24 PM
Zigzagcom Offline
Registered User
 
Join Date: Feb 2005
Location: CALIFORNIA, yeah
Age: 86
Posts: 1,657
No, /etc/sysconfig/iptables is just a place holder. That is what drove me up the wall, trying to find the exact source of the rules. These rules are hard coded.
You could try an experiment. Make a backup, disable the firewall, flush iptables, rename /etc/sysconfig/iptables to whatever (or even delete it), then re-boot. Make sure that iptables doesn't run as a service on startup. After the re-boot, look for the iptables file. Then run system-config-securitylevel and enable the firewall again. Iptables is back, with the default rules. You can restore the old firewall rules from the backup.
__________________
Ziggy

Last edited by Zigzagcom; 23rd April 2006 at 04:34 PM.
Reply With Quote
  #4  
Old 23rd April 2006, 04:40 PM
jcliburn's Avatar
jcliburn Offline
Registered User
 
Join Date: Nov 2004
Location: Mississippi, USA
Posts: 1,180
Interesting. Good sleuthing. I'm curious whether running system-config-securitylevel and making *any* change to the firewall from the gui would invoke lokkit to rewrite the default /etc/sysconfig/iptables, then add whatever customization I specified in the gui. This would be *bad*, because I always hand customize my /etc/sysconfig/iptables directly without using the gui. Do you know if it works that way?
Reply With Quote
  #5  
Old 23rd April 2006, 04:44 PM
Zigzagcom Offline
Registered User
 
Join Date: Feb 2005
Location: CALIFORNIA, yeah
Age: 86
Posts: 1,657
Yes, that is exactly what happens, and there are quite a few warnings about doing hand edits or using other tools to manipulate the firewall and then using the Fedora config tool thereafter. The same can be said about system-config-httpd
__________________
Ziggy
Reply With Quote
Reply

Tags
default, firewall, rules

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
amule setup firewall rules Indian Using Fedora 1 2nd July 2009 02:52 PM
How to Add to Firewall Rules Bone Security and Privacy 3 3rd May 2006 06:32 PM
Firewall, with program based rules. ezzetabi Security and Privacy 1 15th March 2006 10:10 PM


Current GMT-time: 01:01 (Sunday, 19-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat