Installiert nach dem HowTo von:
http://www.netsecond.net/howto/index.ph ... artlang=de
Folgende Schritte wurden unternommen:
1. /etc/init.d/rcportsentry stop
2. /etc/init.d/rc3.d/S08portsentry gelöscht
3. /etc/init.d/rc3.d/K17portsentry gelöscht
4. /etc/cron.d/filtermgr gelöscht
5. Alle Portsentry Dateien in /usr/ gelöscht
Wo könnte der Fehler liegen? Wie kann ich ihn beheben?
Folgende Meldung kommt in der Messages-Datei, wenn ich zum Test Scanne:
Code: Select all
Jan 4 02:12:37 server portsentry[8691]: attackalert: ERROR: cannot open ignore file. Blocking host anyway.
Jan 4 02:12:37 server portsentry[8691]: attackalert: TCP SYN/Normal scan from host: 217.167.118.221/217.167.118.221 to TCP port: 13
Jan 4 02:12:37 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:12:37 server portsentry[8691]: attackalert: Host 217.167.118.221 has been blocked via wrappers with string: "ALL: 217.167.
Jan 4 02:12:37 server portsentry[8691]: attackalert: External command run for host: 217.167.118.221 using command: "/usr/local/psio
Jan 4 02:12:37 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:12:37 server portsentry[8691]: adminalert: ERROR: Cannot open history file: /usr/local/psionic/portsentry/portsentry.histo
Jan 4 02:12:37 server portsentry[8691]: attackalert: ERROR: cannot open ignore file. Blocking host anyway.
Jan 4 02:12:38 server portsentry[8691]: attackalert: TCP SYN/Normal scan from host: 217.167.118.221/217.167.118.221 to TCP port: 13
Jan 4 02:12:38 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:12:38 server portsentry[8691]: attackalert: Host 217.167.118.221 has been blocked via wrappers with string: "ALL: 217.167.
Jan 4 02:12:38 server portsentry[8691]: attackalert: External command run for host: 217.167.118.221 using command: "/usr/local/psio
Jan 4 02:12:38 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:12:38 server portsentry[8691]: adminalert: ERROR: Cannot open history file: /usr/local/psionic/portsentry/portsentry.histo
Jan 4 02:12:38 server portsentry[8691]: attackalert: ERROR: cannot open ignore file. Blocking host anyway.
Jan 4 02:12:38 server portsentry[8691]: attackalert: TCP SYN/Normal scan from host: 217.167.118.221/217.167.118.221 to TCP port: 13
Jan 4 02:12:38 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:12:38 server portsentry[8691]: attackalert: Host 217.167.118.221 has been blocked via wrappers with string: "ALL: 217.167.
Jan 4 02:12:38 server portsentry[8691]: attackalert: External command run for host: 217.167.118.221 using command: "/usr/local/psio
Jan 4 02:12:38 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:12:38 server portsentry[8691]: adminalert: ERROR: Cannot open history file: /usr/local/psionic/portsentry/portsentry.histo
Jan 4 02:13:22 server portsentry[8691]: attackalert: ERROR: cannot open ignore file. Blocking host anyway.
Jan 4 02:13:23 server portsentry[8691]: attackalert: TCP SYN/Normal scan from host: adsl_lav178_187.datastream.com.mt/217.22.178.18
Jan 4 02:13:23 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:13:23 server portsentry[8691]: attackalert: Host 217.22.178.187 has been blocked via wrappers with string: "ALL: 217.22.17
Jan 4 02:13:23 server portsentry[8691]: attackalert: External command run for host: 217.22.178.187 using command: "/usr/local/psion
Jan 4 02:13:23 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:13:23 server portsentry[8691]: adminalert: ERROR: Cannot open history file: /usr/local/psionic/portsentry/portsentry.histo
Jan 4 02:13:41 server xinetd[5345]: libwrap refused connection to ftp (libwrap=vsftpd) from 127.0.0.1
Jan 4 02:14:00 server /USR/SBIN/CRON[5350]: (root) CMD (/usr/local/confixx/confixx_counterscript.pl)
Jan 4 02:14:40 server xinetd[5367]: libwrap refused connection to ftp (libwrap=vsftpd) from 127.0.0.1
Jan 4 02:14:46 server xinetd[5370]: libwrap refused connection to ftp (libwrap=vsftpd) from 127.0.0.1
Jan 4 02:16:00 server /USR/SBIN/CRON[5400]: (root) CMD (/usr/local/confixx/confixx_counterscript.pl)
Jan 4 02:17:27 server kernel: addrconf: valid lifetime 2592000 is too long; adjusted to 2147482.