03-21-2014
Quote:
Originally Posted by
randomxs
Why would someone continually try to access the https port for months on end 100s of times an hour when clearly they must see they are being denied access to the server?
Iptables is not perfect and even when you use DROP rather than REJECT a port scanner can tell that DROP is in use by doing a SYN scan. If a server is on the port the SYN will get an ACK, otherwise it gets a RST. So the bad guy knows that he is getting nailed by a DROP rule and there is a live server being protected by the DROP rule. So he sets up an infinite loop trying to connect.
He hopes you will someday have a problem, wonder if iptables is causing it, and try dropping iptables just for a few seconds. Or maybe you will change your configuration and do a quick "service iptables restart". Most iptable configs allow ESTABLISHED connections to persist so once he connects... he is in.
This User Gave Thanks to Perderabo For This Post:
9 More Discussions You Might Find Interesting
1. UNIX for Advanced & Expert Users
Please, can someone tell me why my SunBlade would be showing 2 different but similar MAC addresses on the same port on the Switch? The switch shows all other Workstations with 1 MAC on each port, but the SunBlade is showing 2. Thanks in advance for any insight.... (1 Reply)
Discussion started by: GoneCrazy
1 Replies
2. Solaris
Hello i'm newbie in solaris, anybody know how to change five port solaris 10?
exmpe: bge0, bge1, bge2, etc.
anybody can help me with the script implementasi... and logical how solaris work.
thank so much:b: (2 Replies)
Discussion started by: yanto85
2 Replies
3. Cybersecurity
Is there a software solution to stop intruders from changing my port addresses?
Causes IPmap to crash.
Platform is OS/X Leopard. (1 Reply)
Discussion started by: aleatory
1 Replies
4. IP Networking
Hi,
I am trying to configure a transparent squid cache. When I try to use the below option in squid.conf, squid listens on port 80 only for the IP address configured on the system's interface.
http_port 80 transparent
But I want squid to accept connections for any IP address on port 80.... (3 Replies)
Discussion started by: Learner32
3 Replies
5. Cybersecurity
Hi Pals
Consider a case where the network interface is there and it is connected to a network.
Only thing left here is I need to set a static ip/ip though dhcp (though ifconfig)
I heard that it is possible to listen even if the ip address is not set. So is there any possibility of an attack over... (1 Reply)
Discussion started by: sreejithc
1 Replies
6. Solaris
I am trying to install Sun Java Web Server using an ordinary user with no root/sudo rights.
I need to allow this web server to use ports 80 and 443. How can this be done?:confused: (1 Reply)
Discussion started by: emealogistics
1 Replies
7. UNIX for Advanced & Expert Users
hi
i want to open port 9100 and the connect server could not to connect to my application
this my results of netstat tulpn
Active Internet connections (w/o servers)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 localhost:9100 ... (3 Replies)
Discussion started by: mohammad alshar
3 Replies
8. HP-UX
Hello Experts,
I want to open the port 443 on my HP-UX system.
can you please help ?
Thanks in advance. (1 Reply)
Discussion started by: purushottamaher
1 Replies
9. IP Networking
Hi All,
Can you please help me in understanding the relationship between local and foreign address in the output of netstat -an.
Output 1
----------
162.103.162.37.50224 162.103.162.35.9511 49640 0 49640 0 ESTABLISHED
162.103.162.37.50263 162.103.162.35.9512 49640 0... (1 Reply)
Discussion started by: Girish19
1 Replies
SSLH(1p) User Contributed Perl Documentation SSLH(1p)
NAME
sslh - Switch incoming connection between SSH and SSL/HTTPS servers
SYNOPSIS
sslh [ -v ] [ -p [host:]port ] [ -t timeout ]
[ --ssh [host:]port ] [ --ssl [host:]port ]
DESCRIPTION
sslh is a simple script that lets you switch an incoming connection on a single port between distinct SSH and SSL/HTTPS servers.
sslh listens for connections on a port and is able to redirect them either to an HTTPS web server or a SSH server.
This lets one setup both a HTTPS web server and a SSH server and access them through the same host+port.
OPTIONS
The program follows the usual GNU command line syntax, with long options starting with two dashes.
-p, --port [host:]port
The port the proxy will listen to. If no port is given, 443 is used by default. If no host is given, "localhost" is used by default.
-s, --ssh [host:]port
The SSH server which the SSH connections must be forwarded to. If omitted, the default is localhost:22.
-l, --ssl, --https [host:]port
The HTTPS server which the HTTPS connections must be forwarded to. If omitted, the default is localhost:443.
-t, --timeout delay
Timeout in seconds before a silent incoming connection is considered as a SSH connection. The number can be fractional.
The default is 2seconds.
-v, --verbose
Verbose output. This option can be used several times for more verbose output.
EXAMPLE OF USE
Is this tool actually useful? Yes.
For example one can use it to access both a SSH server and a secure web server via a corporate proxy that only accepts to relay connections
to port 443. Creating a tunnel that passes SSH connection through a CONNECT-enabled web proxy is easy with connect-tunnel (also included in
the "Net::Proxy" distribution).
The proxy will let both SSH and HTTPS connections out (since they all point to port 443), and the home server will connect those incoming
connections to the appropriate server. This only requires to run the HTTPS server on a non standard port (not 443).
TECHNICAL NOTE
How can this proxy find out what kind of protocol is using a TCP connection to port 443, without being connected (yet) to the server? We
actually rely on a slight difference between the SSL and SSH protocols (found thanks to ethereal):
SSH Once the TCP connection is established, the server speaks first, presenting itself by saying something like:
SSH-2.0-OpenSSH_3.6.1p2 Debian 1:3.6.1p2-1
SSL With SSL, it's always the client that speaks first.
This means that sslh can be used with any pair of protocols/services that share this property (the client speaks first for one and the
server speaks first for the other).
AUTHORS
Original idea and C version
Frederic Ple "<sslh@wattoo.org>".
Perl versions
Philippe 'BooK' Bruhat "<book@cpan.org>".
SCRIPT HISTORY
Version 0.01 of the script was a quick hack designed in 2003 as a proof of concept.
Version 0.02 (and higher) are based on "Net::Proxy", and included with the "Net::Proxy" distribution. Version 0.02 didn't work, though.
Version 0.03 correctly initialised the "in" connector.
Version 0.04 lets the proxy listen on any address (instead of "localhost", which is still the default). Thanks to Dieter Voegtli for
spotting this.
SEE ALSO
Net::Proxy, Net::Proxy::Connector::dual.
COPYRIGHT
Copyright 2003-2006, Philippe Bruhat. All rights reserved.
LICENSE
This module is free software; you can redistribute it or modify it under the same terms as Perl itself.
perl v5.10.1 2009-10-18 SSLH(1p)