Portsentry restlos entfernen! Wie??
Posted: 2005-01-04 02:19
Habe auf einem Testrechner Suse 9.0 Portsentry 1.2 installiert. Nachdem ich bemerkt habe, dass es ein Fehler war und Portsentry nichts taugt, wollte ich es entfernen, doch irgendetwas habe ich wohl übersehen.
Installiert nach dem HowTo von:
http://www.netsecond.net/howto/index.ph ... artlang=de
Folgende Schritte wurden unternommen:
1. /etc/init.d/rcportsentry stop
2. /etc/init.d/rc3.d/S08portsentry gelöscht
3. /etc/init.d/rc3.d/K17portsentry gelöscht
4. /etc/cron.d/filtermgr gelöscht
5. Alle Portsentry Dateien in /usr/ gelöscht
Wo könnte der Fehler liegen? Wie kann ich ihn beheben?
Folgende Meldung kommt in der Messages-Datei, wenn ich zum Test Scanne:
Vielen Dank für die Hilfe!
Installiert nach dem HowTo von:
http://www.netsecond.net/howto/index.ph ... artlang=de
Folgende Schritte wurden unternommen:
1. /etc/init.d/rcportsentry stop
2. /etc/init.d/rc3.d/S08portsentry gelöscht
3. /etc/init.d/rc3.d/K17portsentry gelöscht
4. /etc/cron.d/filtermgr gelöscht
5. Alle Portsentry Dateien in /usr/ gelöscht
Wo könnte der Fehler liegen? Wie kann ich ihn beheben?
Folgende Meldung kommt in der Messages-Datei, wenn ich zum Test Scanne:
Code: Select all
Jan 4 02:12:37 server portsentry[8691]: attackalert: ERROR: cannot open ignore file. Blocking host anyway.
Jan 4 02:12:37 server portsentry[8691]: attackalert: TCP SYN/Normal scan from host: 217.167.118.221/217.167.118.221 to TCP port: 13
Jan 4 02:12:37 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:12:37 server portsentry[8691]: attackalert: Host 217.167.118.221 has been blocked via wrappers with string: "ALL: 217.167.
Jan 4 02:12:37 server portsentry[8691]: attackalert: External command run for host: 217.167.118.221 using command: "/usr/local/psio
Jan 4 02:12:37 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:12:37 server portsentry[8691]: adminalert: ERROR: Cannot open history file: /usr/local/psionic/portsentry/portsentry.histo
Jan 4 02:12:37 server portsentry[8691]: attackalert: ERROR: cannot open ignore file. Blocking host anyway.
Jan 4 02:12:38 server portsentry[8691]: attackalert: TCP SYN/Normal scan from host: 217.167.118.221/217.167.118.221 to TCP port: 13
Jan 4 02:12:38 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:12:38 server portsentry[8691]: attackalert: Host 217.167.118.221 has been blocked via wrappers with string: "ALL: 217.167.
Jan 4 02:12:38 server portsentry[8691]: attackalert: External command run for host: 217.167.118.221 using command: "/usr/local/psio
Jan 4 02:12:38 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:12:38 server portsentry[8691]: adminalert: ERROR: Cannot open history file: /usr/local/psionic/portsentry/portsentry.histo
Jan 4 02:12:38 server portsentry[8691]: attackalert: ERROR: cannot open ignore file. Blocking host anyway.
Jan 4 02:12:38 server portsentry[8691]: attackalert: TCP SYN/Normal scan from host: 217.167.118.221/217.167.118.221 to TCP port: 13
Jan 4 02:12:38 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:12:38 server portsentry[8691]: attackalert: Host 217.167.118.221 has been blocked via wrappers with string: "ALL: 217.167.
Jan 4 02:12:38 server portsentry[8691]: attackalert: External command run for host: 217.167.118.221 using command: "/usr/local/psio
Jan 4 02:12:38 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:12:38 server portsentry[8691]: adminalert: ERROR: Cannot open history file: /usr/local/psionic/portsentry/portsentry.histo
Jan 4 02:13:22 server portsentry[8691]: attackalert: ERROR: cannot open ignore file. Blocking host anyway.
Jan 4 02:13:23 server portsentry[8691]: attackalert: TCP SYN/Normal scan from host: adsl_lav178_187.datastream.com.mt/217.22.178.18
Jan 4 02:13:23 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:13:23 server portsentry[8691]: attackalert: Host 217.22.178.187 has been blocked via wrappers with string: "ALL: 217.22.17
Jan 4 02:13:23 server portsentry[8691]: attackalert: External command run for host: 217.22.178.187 using command: "/usr/local/psion
Jan 4 02:13:23 server portsentry[8691]: adminalert: ERROR: Cannot open blocked file: /usr/local/psionic/portsentry/portsentry.block
Jan 4 02:13:23 server portsentry[8691]: adminalert: ERROR: Cannot open history file: /usr/local/psionic/portsentry/portsentry.histo
Jan 4 02:13:41 server xinetd[5345]: libwrap refused connection to ftp (libwrap=vsftpd) from 127.0.0.1
Jan 4 02:14:00 server /USR/SBIN/CRON[5350]: (root) CMD (/usr/local/confixx/confixx_counterscript.pl)
Jan 4 02:14:40 server xinetd[5367]: libwrap refused connection to ftp (libwrap=vsftpd) from 127.0.0.1
Jan 4 02:14:46 server xinetd[5370]: libwrap refused connection to ftp (libwrap=vsftpd) from 127.0.0.1
Jan 4 02:16:00 server /USR/SBIN/CRON[5400]: (root) CMD (/usr/local/confixx/confixx_counterscript.pl)
Jan 4 02:17:27 server kernel: addrconf: valid lifetime 2592000 is too long; adjusted to 2147482.