RE: IPMI & portrange



On 26-Sep-2006 Danny Braniss wrote:
This keeps bitting me every other upgrade, IPMI on some
hosts, if enabled, will steal packets to port 623 or 664, so
the current solution is either set net.inet.ip.portrange.lowlast
to 664, (for some reason this does not seem to work if done via
loader.conf) or change it in sys/netinet/in.h.

So, is there some way to blacklist some ports, instead
of increasing portrange.lowlast?

You could use your favorite scripting language to create a socket,
bind it to the port, listen on it, and just sit there doing nothing
-- for each port you want to blacklist. That would keep the ports
from being used by anything else.

John
_______________________________________________
freebsd-net@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: SSO fails when machine is connected to network
    ... I added an entry to both the hosts and lmhosts files and I ... (this message came when I tried to delete the receive port to add it again) ... I have a named workgroup using the name of the machine. ... network adapter or add another explicit loopback) that is not 127.0.0.1. ...
    (microsoft.public.biztalk.server)
  • Re: Question on keeping Fedora 7 secure while connected to Internet
    ... to disable relaying from untrusted hosts). ... Telnet is available to two specific hosts only, ... The password guessing programs all ... attack port 22 so using a different port makes you invisible to them. ...
    (comp.os.linux.security)
  • Re: Discovering Live Hosts
    ... 1)You hint that your targets may be behind a firewall. ... until you actually connect to each and every port. ... Some hosts support no ... initial target pool is large. ...
    (Pen-Test)
  • RE: Subseven Scans
    ... A Sequentially Distributed RECON probe for SubSeven V 2.1 port 27374 started ... The analyses proved that 23 seperate hosts were used for the attack. ... >RK> For more information on this free incident handling, management ...
    (Incidents)
  • Re: Port 80 open without WebServer
    ... i will nmap from certain hosts to new boxes I have put on the big bad net ... and port 80 will sometimes be open. ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
    (Security-Basics)