|
Author |
Message |
|
|
Posted Jan 27, 2009 at 12:30:39 AM
Subject: Firestarter
I have Firestarter set up to put all ports in stealth mode. I'm not sure how much to restrict outbound traffic. I have a desktop which is used for internet and E-mail. Currently I allow outbound traffic to BitTorent (ports 6881-6889), HTTP (port 80), HTTPS (Port 443), POP3 (port 110) and SMTP (port 25). Should I allow outbound traffic on any other ports for other services? I'm not sure about X-windows (ports 600-6015).
I have been using Ubuntu for a while but may be considered a novice.
Please let me know what you think?
|
Penguin
Joined Mar 28, 2008 Posts: 88
Other Topics
|
Posted:
Jan 28, 2009 10:33:46 AM
Subject: Firestarter
I tend to take the view of "only open what you need". So personally I'd leave it as is (with the 'torrent, HTTP/S, POP and SMTP [you might want IMAP later]), and then if you find that something's not working open up those ports for it.
So, basically, leave it as it is until something can't get on the internet, then open more ports.
As for the X-windows ports, unless you're planning on forwarding your X session over the LAN (not recommended) don't open them (I believe Ubuntu has X forwarding off by default anyway).
Hope that helps a bit, otherwise post back and we'll try and sort it for you...
Penguin
|
Joined Jul 26, 2008 Posts: 703
Location:
Other Topics
|
Posted:
Jan 28, 2009 7:31:26 PM
Subject: Firestarter
[quote]So personally I'd leave it as is (with the 'torrent, HTTP/S,POP and SMTP rokytnji)[/quote]
? How did I end up in this post Penguin?
|
Penguin
Joined Mar 28, 2008 Posts: 88
Other Topics
|
Posted:
Jan 28, 2009 8:48:01 PM
Subject: Firestarter
when I posted it it said [ you might want imap ]... For me it says Penguin, maybe a forum bug ?
If it does it again up there, it's "you might want imap" in []'s.
[Modified by: Penguin on January 28, 2009 08:49 PM]
[Modified by: Penguin on January 28, 2009 08:50 PM]
|
Binary Snake
Joined Jan 11, 2009 Posts: 197
Other Topics
|
Posted:
Jan 28, 2009 11:52:33 PM
Subject: Firestarter
[quote=Penguin]I tend to take the view of "only open what you need". So personally I'd leave it as is (with the 'torrent, HTTP/S, POP and SMTP [you might want IMAP later])[/quote]
Everyone who is logged, when he opens this post will see his username after SMTP, maybe the word imap which penguin used conflicts with a variable located in the web site source code.
Now all the users are network protocols, everyone will have his own RFC.
[Modified by: Binary Snake on January 29, 2009 12:53 AM]
|