<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" 
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:wfw="http://wellformedweb.org/CommentAPI/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:meneame="http://meneame.net/faq-es.php"
 >
<channel>
	<title>Menéame: comentarios [227148]</title>
	<link>http://www.meneame.net</link>
	<image><title>www.meneame.net</title><link>http://www.meneame.net</link><url>http://cdn.mnmstatic.net/img/mnm/eli-rss.png</url></image>
	<description>Sitio colaborativo de publicación y comunicación entre blogs</description>
	<pubDate>Tue, 09 Oct 2007 13:40:44 +0000</pubDate>
	<generator>http://blog.meneame.net/</generator>
	<language>es</language>
	<item>
		<meneame:comment_id>1034522</meneame:comment_id>
		<meneame:link_id>227148</meneame:link_id>
		<meneame:order>13</meneame:order>
		<meneame:user>--11594--</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>5</meneame:karma>
		<meneame:url>https://www.meneame.net/story/defendiendo-con-iptables</meneame:url>
		<title>#13 Defendiendo con iptables</title>
		<link>https://www.meneame.net/story/defendiendo-con-iptables/c013#c-13</link>
		<pubDate>Tue, 09 Oct 2007 13:40:44 +0000</pubDate>
		<dc:creator>--11594--</dc:creator>
		<guid>https://www.meneame.net/story/defendiendo-con-iptables/c013#c-13</guid>
		<description><![CDATA[<p>y que hay del port knocking? Queremos de saber</p><p>&#187;&nbsp;autor: <strong>--11594--</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>1032460</meneame:comment_id>
		<meneame:link_id>227148</meneame:link_id>
		<meneame:order>12</meneame:order>
		<meneame:user>aGaTHoS</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>6</meneame:karma>
		<meneame:url>https://www.meneame.net/story/defendiendo-con-iptables</meneame:url>
		<title>#12 Defendiendo con iptables</title>
		<link>https://www.meneame.net/story/defendiendo-con-iptables/c012#c-12</link>
		<pubDate>Mon, 08 Oct 2007 23:25:30 +0000</pubDate>
		<dc:creator>aGaTHoS</dc:creator>
		<guid>https://www.meneame.net/story/defendiendo-con-iptables/c012#c-12</guid>
		<description><![CDATA[<p>Esta bien, simple y completo, he perfeccionado mi firewall con un par de ideas del articulo, por cierto para el syn flood lo mejor es activar la proteccion mediante syn cookies en el kernel.<br />
<br />
<a class="tooltip c:227148-6" href="https://www.meneame.net/story/defendiendo-con-iptables/c06#c-6" rel="nofollow">#6</a> ni por asomo es tan simple, <a class="tooltip c:227148-3" href="https://www.meneame.net/story/defendiendo-con-iptables/c03#c-3" rel="nofollow">#3</a> t quedas corto, os suenan cosas como pie, ssp, pax, rbac, grsecurity, selinux?</p><p>&#187;&nbsp;autor: <strong>aGaTHoS</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>1031913</meneame:comment_id>
		<meneame:link_id>227148</meneame:link_id>
		<meneame:order>11</meneame:order>
		<meneame:user>el-brujo</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>7</meneame:karma>
		<meneame:url>https://www.meneame.net/story/defendiendo-con-iptables</meneame:url>
		<title>#11 Defendiendo con iptables</title>
		<link>https://www.meneame.net/story/defendiendo-con-iptables/c011#c-11</link>
		<pubDate>Mon, 08 Oct 2007 20:42:25 +0000</pubDate>
		<dc:creator>el-brujo</dc:creator>
		<guid>https://www.meneame.net/story/defendiendo-con-iptables/c011#c-11</guid>
		<description><![CDATA[<p>Intentando detener un DDoS<br />
<a href="http://foro.elhacker.net/index.php/topic,137442.0.html" title="foro.elhacker.net/index.php/topic,137442.0.html" rel="nofollow">foro.elhacker.net/index.php/topic,137442.0.html</a></p><p>&#187;&nbsp;autor: <strong>el-brujo</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>1030782</meneame:comment_id>
		<meneame:link_id>227148</meneame:link_id>
		<meneame:order>10</meneame:order>
		<meneame:user>--14775--</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>6</meneame:karma>
		<meneame:url>https://www.meneame.net/story/defendiendo-con-iptables</meneame:url>
		<title>#10 Defendiendo con iptables</title>
		<link>https://www.meneame.net/story/defendiendo-con-iptables/c010#c-10</link>
		<pubDate>Mon, 08 Oct 2007 14:31:19 +0000</pubDate>
		<dc:creator>--14775--</dc:creator>
		<guid>https://www.meneame.net/story/defendiendo-con-iptables/c010#c-10</guid>
		<description><![CDATA[<p>[Usuario deshabilitado]</p><p>&#187;&nbsp;autor: <strong>--14775--</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>1030487</meneame:comment_id>
		<meneame:link_id>227148</meneame:link_id>
		<meneame:order>9</meneame:order>
		<meneame:user>--50873--</meneame:user>
		<meneame:votes>1</meneame:votes>
		<meneame:karma>20</meneame:karma>
		<meneame:url>https://www.meneame.net/story/defendiendo-con-iptables</meneame:url>
		<title>#9 Defendiendo con iptables</title>
		<link>https://www.meneame.net/story/defendiendo-con-iptables/c09#c-9</link>
		<pubDate>Mon, 08 Oct 2007 13:24:14 +0000</pubDate>
		<dc:creator>--50873--</dc:creator>
		<guid>https://www.meneame.net/story/defendiendo-con-iptables/c09#c-9</guid>
		<description><![CDATA[<p>[Usuario deshabilitado]</p><p>&#187;&nbsp;autor: <strong>--50873--</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>1029815</meneame:comment_id>
		<meneame:link_id>227148</meneame:link_id>
		<meneame:order>8</meneame:order>
		<meneame:user>khepper</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>6</meneame:karma>
		<meneame:url>https://www.meneame.net/story/defendiendo-con-iptables</meneame:url>
		<title>#8 Defendiendo con iptables</title>
		<link>https://www.meneame.net/story/defendiendo-con-iptables/c08#c-8</link>
		<pubDate>Mon, 08 Oct 2007 10:46:24 +0000</pubDate>
		<dc:creator>khepper</dc:creator>
		<guid>https://www.meneame.net/story/defendiendo-con-iptables/c08#c-8</guid>
		<description><![CDATA[<p><a class="tooltip c:227148-3" href="https://www.meneame.net/story/defendiendo-con-iptables/c03#c-3" rel="nofollow">#3</a> Cada cosa a su sitio, una cosa es la seguridad pasiva y otra la activa. Evitar este tipo de ataques antes de entrar en la red evita problemas que son culpa tuya <br />
<br />
El problema de este tipo de documentos es que para entenderlos tienes que tener conocimientos de redes, saber como funciona la red y tener hardware que permita ser configurado para evitarlos, si tenemos un router de los que nos dan gratis por contratar un adsl no nos sirve de nada, claro que tampoco seremos objetivo de nadie. Pero para una empresa mediana o grande es imprescindible tener todos estos temas controlados, muchas no pueden permitirse el lujo que caer.<br />
<br />
Interesante, voy a leerlo, aunque de primeras ya veo que se salta algunas cosas <img data-src="https://cdn.mnmstatic.net/v_149/img/menemojis/36/wink.png" alt=";)" title=";)" width="18" height="18" src="https://cdn.mnmstatic.net/v_149/img/g.gif" class="emoji lazy" /></p><p>&#187;&nbsp;autor: <strong>khepper</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>1029278</meneame:comment_id>
		<meneame:link_id>227148</meneame:link_id>
		<meneame:order>7</meneame:order>
		<meneame:user>SirViente</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>8</meneame:karma>
		<meneame:url>https://www.meneame.net/story/defendiendo-con-iptables</meneame:url>
		<title>#7 Defendiendo con iptables</title>
		<link>https://www.meneame.net/story/defendiendo-con-iptables/c07#c-7</link>
		<pubDate>Mon, 08 Oct 2007 08:20:57 +0000</pubDate>
		<dc:creator>SirViente</dc:creator>
		<guid>https://www.meneame.net/story/defendiendo-con-iptables/c07#c-7</guid>
		<description><![CDATA[<p><a class="tooltip c:227148-6" href="https://www.meneame.net/story/defendiendo-con-iptables/c06#c-6" rel="nofollow">#6</a> No es tan sencillo, con eso no te proteges de ataques ICMP o floods al puerto 80 por ejemplo...  ni flood de Reseteos TCP.... simplemente cierras todos los puertos menos uno...<br />
<br />
Estas reglas del articulo, son complementarias a las tuyas (no sustitutivas) y sirven para que a parte de cerrar todos los puertos, filtres tambien estos ataques.</p><p>&#187;&nbsp;autor: <strong>SirViente</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>1029082</meneame:comment_id>
		<meneame:link_id>227148</meneame:link_id>
		<meneame:order>6</meneame:order>
		<meneame:user>neo22s</meneame:user>
		<meneame:votes>2</meneame:votes>
		<meneame:karma>22</meneame:karma>
		<meneame:url>https://www.meneame.net/story/defendiendo-con-iptables</meneame:url>
		<title>#6 Defendiendo con iptables</title>
		<link>https://www.meneame.net/story/defendiendo-con-iptables/c06#c-6</link>
		<pubDate>Mon, 08 Oct 2007 07:11:54 +0000</pubDate>
		<dc:creator>neo22s</dc:creator>
		<guid>https://www.meneame.net/story/defendiendo-con-iptables/c06#c-6</guid>
		<description><![CDATA[<p>He mirado el manual, es extenso y provoca dolor de cabeza! realmente es mas sencillo que todo eso.<br />
<br />
Relacionada: <a href="http://meneame.net/story/seguridad-linux-manejo-iptables" title="meneame.net/story/seguridad-linux-manejo-iptables" rel="nofollow">meneame.net/story/seguridad-linux-manejo-iptables</a><br />
<br />
Y como aquella vez dejo el mismo comentario: <br />
<br />
os pongo un script dejando el puerto 80 abierto solo <img data-src="https://cdn.mnmstatic.net/v_149/img/menemojis/36/smiley.png" alt=":-)" title=":-)" width="18" height="18" src="https://cdn.mnmstatic.net/v_149/img/g.gif" class="emoji lazy" /><br />
<br />
hacemos:<br />
<br />
vi /etc/init.d/wall<br />
<br />
<a href="/search?w=comments&#38;q=%23######################INICIO##############&#38;o=date">#######################INICIO##############</a>#############<br />
# descripción: FirewallIPT=/sbin/iptablescase &#34;$1&#34; in<br />
<br />
start)<br />
$IPT -A INPUT -i eth0 -m state –state ESTABLISHED,RELATED -j ACCEPT<br />
$IPT -A INPUT -i eth0 -p tcp –dport 80 -j ACCEPT<br />
$IPT -A INPUT -i eth0 -j REJECT<br />
exit 0<br />
;;<br />
<br />
stop)<br />
$IPT -F INPUT<br />
exit 0<br />
;;<br />
*)<br />
echo &#34;Usage: /etc/init.d/wall {start|stop}&#34; exit 1 ;;<br />
<br />
esac<br />
<a href="/search?w=comments&#38;q=%23###########FIN#####################&#38;o=date">############FIN#####################</a><br />
escape+:+x para gravar<br />
<br />
entonces picamos (para dar permisos al fichero):<br />
<br />
chmod 700 /etc/init.d/wall<br />
<br />
Ahora ya podemos hacer algo como:<br />
<br />
/etc/init.d/wall start<br />
o<br />
/etc/init.d/wall stop<br />
<br />
pero falta que se inicie con el arranque:<br />
<br />
update-rc.d /etc/init.d/wall defaults</p><p>&#187;&nbsp;autor: <strong>neo22s</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>1028900</meneame:comment_id>
		<meneame:link_id>227148</meneame:link_id>
		<meneame:order>5</meneame:order>
		<meneame:user>mimismo</meneame:user>
		<meneame:votes>1</meneame:votes>
		<meneame:karma>20</meneame:karma>
		<meneame:url>https://www.meneame.net/story/defendiendo-con-iptables</meneame:url>
		<title>#5 Defendiendo con iptables</title>
		<link>https://www.meneame.net/story/defendiendo-con-iptables/c05#c-5</link>
		<pubDate>Mon, 08 Oct 2007 02:31:06 +0000</pubDate>
		<dc:creator>mimismo</dc:creator>
		<guid>https://www.meneame.net/story/defendiendo-con-iptables/c05#c-5</guid>
		<description><![CDATA[<p><a class="tooltip c:227148-4" href="https://www.meneame.net/story/defendiendo-con-iptables/c04#c-4" rel="nofollow">#4</a> Aplicable a la mayoría de las noticias en portada, y no por eso deja de ser interesante.<br />
Muy útil <img data-src="https://cdn.mnmstatic.net/v_149/img/menemojis/36/smiley.png" alt=":-)" title=":-)" width="18" height="18" src="https://cdn.mnmstatic.net/v_149/img/g.gif" class="emoji lazy" /></p><p>&#187;&nbsp;autor: <strong>mimismo</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>1028826</meneame:comment_id>
		<meneame:link_id>227148</meneame:link_id>
		<meneame:order>4</meneame:order>
		<meneame:user>ruudbb</meneame:user>
		<meneame:votes>3</meneame:votes>
		<meneame:karma>16</meneame:karma>
		<meneame:url>https://www.meneame.net/story/defendiendo-con-iptables</meneame:url>
		<title>#4 Defendiendo con iptables</title>
		<link>https://www.meneame.net/story/defendiendo-con-iptables/c04#c-4</link>
		<pubDate>Mon, 08 Oct 2007 00:40:28 +0000</pubDate>
		<dc:creator>ruudbb</dc:creator>
		<guid>https://www.meneame.net/story/defendiendo-con-iptables/c04#c-4</guid>
		<description><![CDATA[<p>Me pregunto que porcentaje de la gente que meneó esto lo entiende.</p><p>&#187;&nbsp;autor: <strong>ruudbb</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>1028798</meneame:comment_id>
		<meneame:link_id>227148</meneame:link_id>
		<meneame:order>3</meneame:order>
		<meneame:user>guillersk</meneame:user>
		<meneame:votes>2</meneame:votes>
		<meneame:karma>14</meneame:karma>
		<meneame:url>https://www.meneame.net/story/defendiendo-con-iptables</meneame:url>
		<title>#3 Defendiendo con iptables</title>
		<link>https://www.meneame.net/story/defendiendo-con-iptables/c03#c-3</link>
		<pubDate>Mon, 08 Oct 2007 00:03:07 +0000</pubDate>
		<dc:creator>guillersk</dc:creator>
		<guid>https://www.meneame.net/story/defendiendo-con-iptables/c03#c-3</guid>
		<description><![CDATA[<p>Interesante para administradores de sistemas pero lo considero bastante inutil para un firewall corporativo si no se junta con antivirus + antispam + antiphishing + websense</p><p>&#187;&nbsp;autor: <strong>guillersk</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>1028785</meneame:comment_id>
		<meneame:link_id>227148</meneame:link_id>
		<meneame:order>2</meneame:order>
		<meneame:user>--1994--</meneame:user>
		<meneame:votes>1</meneame:votes>
		<meneame:karma>18</meneame:karma>
		<meneame:url>https://www.meneame.net/story/defendiendo-con-iptables</meneame:url>
		<title>#2 Defendiendo con iptables</title>
		<link>https://www.meneame.net/story/defendiendo-con-iptables/c02#c-2</link>
		<pubDate>Sun, 07 Oct 2007 23:48:56 +0000</pubDate>
		<dc:creator>--1994--</dc:creator>
		<guid>https://www.meneame.net/story/defendiendo-con-iptables/c02#c-2</guid>
		<description><![CDATA[<p>A favoritos, nunca sabes cuando lo puedes necesitar</p><p>&#187;&nbsp;autor: <strong>--1994--</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>1027252</meneame:comment_id>
		<meneame:link_id>227148</meneame:link_id>
		<meneame:order>1</meneame:order>
		<meneame:user>4PortHub</meneame:user>
		<meneame:votes>2</meneame:votes>
		<meneame:karma>11</meneame:karma>
		<meneame:url>https://www.meneame.net/story/defendiendo-con-iptables</meneame:url>
		<title>#1 Defendiendo con iptables</title>
		<link>https://www.meneame.net/story/defendiendo-con-iptables/c01#c-1</link>
		<pubDate>Sun, 07 Oct 2007 12:38:40 +0000</pubDate>
		<dc:creator>4PortHub</dc:creator>
		<guid>https://www.meneame.net/story/defendiendo-con-iptables/c01#c-1</guid>
		<description><![CDATA[<p>Plas, a leer.</p><p>&#187;&nbsp;autor: <strong>4PortHub</strong></p>]]></description>
	</item>

</channel>
</rss>
