Fedora :: Blacklist Program From Internet Access?
May 23, 2010In Fedora 12 how do I make it so a specific program can't talk to the internet?
View 14 RepliesIn Fedora 12 how do I make it so a specific program can't talk to the internet?
View 14 RepliesQuick explanation about what this thread is: by way of an article featured on linuxtoday, I learned about what appears to be an actively managed IP blacklist: [URL]
# This is a compiled list of dirty hosts associated with
# bruteforcing attempts, spam, botnets, RBN and the list
# continues to grow. The data is comprised of information
# compiled from Arbor Networks, Project Honeypot, FIRE
# (maliciousnetwork.org), Host Exploit, Shadowserver and
# a variety of other similarly based sites.
Quick explanation about what this thread is not: this is not intended to be a discussion about default deny vs. default allow (i.e. whitelists vs. blacklists), nor is this a call for enumerations of your own sshd hardening strategy. Please try to keep on point. That said, can anyone speak to the quality of the blacklist information noted above? And/or are there any suggestions for a readily available blacklist of "known better" quality? I plan to try including an actively maintained blacklist like this into a multi-layered approach for hardening an sshd bastion host.
I have seen several threads lately about slow internet connections here and elsewhere, but I haven't seen anyone post a reply about blacklisting ipv6 so I am curious as to why?Is ipv6 enabled only on certain distro's or is there some other reason that it's not mentioned?
<If anyone wants to try it, to see if it would work for them>
On Slackware 12.2 and Salix 13.0 just add "blacklist ipv6" to the /etc/modprobe.d/blacklist file. I'm not sure about non-slackware based distro's. Unfortunately, I don't know any way of doing it without rebooting.
Is there an Ubuntu program that gives access to Internet radio stations like iTunes?
iTunes radio setting on Mac has hundreds or thousands of internet radio stations that the user can select from and listen to. Is there such an app for Ubuntu? That would be easier than finding all their web sites and bookmarking them.
I wanted to know if there was a firewall program out there that can open specific ports when a program/process is run and disable the ports again when the program is closed.
View 2 Replies View RelatedThere is this active connection in firestarter: ec2-174-129-193-12.compute-1.amazonaws.com (Port 443 - Service HTTPS - program python)After doing ps aux | grep PID it shows: /usr/bin/python /usr/lib/ubuntuone-client/ubuntuone-syncdaemon...This comes up in the firewall in each login, how do I get rid of it and how did it get there in the first place? Another question is if there is a way to limit a program's access to the internet. For example KCalender.. The things I type up in there may be stored somewhere. How can I disable complete access to the internet for that program and any other program so they can't backup, share, check etc. ?
View 3 Replies View RelatedI have a linux box (fedora) with two ethernet cards eth1 and eth2. On eth1 I successfully configured a PPPOE internet connection. Such that from the server I can browse the internet. On eth2 I wired it to a wireless router essentially to provide the wireless cloud. On eth2 I also configured dhcp, such that the Linux box is both PPPOE and DHCP server.However my clients on the LAN cannot access the Internet.
On passing the routing command I get
Destination Gateway Iface
196.44.x.y 0.0.0.0 ppp0
192.168.1.0 0.0.0.0 eth2 (my subnet)
0.0.0.0 0.0.0.0 ppp0.
The router (functioning as a wireless access point mainly) has a fixed IP address of 192.168.1.2 and eth2 has IP address 192.168.1.1. The dhcp file running on Linux has been set with option router (Gateway) 192.168.1.1. I cannot figure out how to correctly set the routing table such that my clients on wireless can access the internet cloud. I googled and googled but no solid solution. Any suggestions?
The specs on my Pavilion DV6 says it has a 5650 Radeon HD card.lspci shows:01:05.0 VGA compatible controller: ATI Technologies Inc M880G [Mobility Radeon HD 4200]02:00.0 VGA compatible controller: ATI Technologies Inc Redwood [Radeon HD 5600 Series] (rev ff)TWO cards? Currently the first one shows up in the system information but, knowing it has a 5600 series card,I'm guessing the laptop has a cheaper model with a 4200 integrated card where mine has a 5650 added...thus both showing up. I need to figure out a way to ignore the 4200 card and use the second.
Both drivers are contained in the same package from Radeon. The system information shows VESA:M880G as the driver. How do I go about blacklisting the M880G driver so the other one ('Redwood', guessing from the content of the lspci output) can be loaded?Or am I completely wrong about what needs to happen here? I do not see anywhere in the bios where I can deactivate the 4200 chip.[edit] After checking the specs on the laptop (and it's other derivates), i twould seem that there is no 4200 series card on any of the cheaper machines....no sure hwat gives. I've downloaded some stuff on X and see if I can create a xorg.conf that will load the appropriate driver.
I'm likely going to remove the akmod proprietary drivers and go with the open source 'radeon' for a while to see how it goes.[/edit]EDIT 2:The thing thats going on here is 'hybrid graphics' which I had heard of in desktop but didn't realize that it was in laptops.There is currently work going on to get the configuration working properly. The 4200 card is supposed to run when on batteries and switching automatically to the 5650 when the power is plugged in.
I've been trying to get a cold backup of a 1TB database this weekend, started the whole process Friday and still have yet to get a single device backed up. I'm using rsync to copy files from my /u17 thru /u29 mounts, and the usb is formatted ext3. Each time the rsync would start off fine but after about 30 minutes it would fail with any number of errors but the most prevalent is "Read only file system", "broken pipe". Here are samples:
rsync: writefd_unbuffered failed to write 4 bytes: phase "unknown" [sender]: Broken pipe (32)
rsync: write failed on "<path to one of my .dbf files" failed: Read-only file system (30)
rsync: chown "<path>" failed: Read-only file system (30)
rsync: rename "<path of .dbf> -> <rename attempt>": Read-only file system (30)
rsync error: error in file IO (code 11) at receiver.c(305)
rsync: connection unexpectantly closed (16787 bytes received so far) [generator]
rsync error: error in rsync protocol data stream (code 12) at io.c (359)
I've unmounted and remounted a number of times and kicked off the rsync again and it goes about 30 minutes and I get the same errors. This was all as user 'root', so I tried to do the rsync as user 'oracle' and I get the same thing. After looking into the device as it is recognized, it is being picked up by multipath. Would the fact that a usb device is being managed by multipath be a problem? Currently it is mpath15. How would I add usb devices to the mpath blacklist? The usb is being assigned /dev/sdbj but I'm worried that it would change at a reboot. I've searched the web for all of these errors and still no answer.
Note: I've also just tried to do a copy using 'cp' and got the same "Read only file system" errors. I can sometimes touch a file and sometimes I can't. I want to try and get this backup done this weekend.
Fedora 15 latest updatesHP Mini 210 NetbookMy internet was working fine. Then all of a sudden it stopped working on my Fedora netbook. I also have an iMac and can connect that to the internet without any problem. So my Internet connection is working fine on the iMacHowever, when I put the cable in my Fedora netbook. I get the IP address through DHCP and DNS automatically. This is the same setting as my iMac. I also have a windows partition on my Fedora netbook. That works fine, so there is no hardware problems.I can ping the router ok. But cannot pingor browse any wReturns cannot find host name google.com. So I think there is something wrong with the DNS.resolv.conf doens't have any DNS address in there. As there are assigned using DHCP.
View 2 Replies View Relatededora 15 latest updates
HP Mini 210 Netbook
My internet was working fine. Then all of a sudden it stopped working on my Fedora netbook. I also have an iMac and can connect that to the internet without any problem. So my Internet connection is working fine on the iMac However, when I put the cable in my Fedora netbook. I get the IP address through DHCP and DNS automatically. This is the same setting as my iMac. I also have a windows partition on my Fedora netbook. That works fine, so there is no hardware problems.I can ping the router ok. But cannot ping [URL] or browse any websites.nslookup [URL]. Returns cannot find host name [URL]. So I think there is something wrong with the DNS.resolv.conf doens't have any DNS address in there. As there are assigned using DHCP.
I had a duplicate IP from another device on the network that would jut not let it go and was the same IP as my Fedora box that was working fine. After screwing around with the other device I finally just gave up and changed the IP on the Fedora box. Now I can't access the internet at all from the Fedora box. I looked in my routing tables in my router and the mac was showing as the mac of the other device. After some reboots here and there that is fix and the routers routing tables are now showing correctly. The Fedora box still can not resolve any domains or get online. Is there something somewhere inside the Fedora box that is still jacked up from the duplicate IP?
View 9 Replies View RelatedI just installed Fedora64 12 on my laptop. When I tried the Live CD all wen well. Now that I am running the full version I can only access internet pages linked to fedoraproject.org...?? not other pages work like google or yahoo or anything else. This is bizarre. How can I get access to the full internet?
View 9 Replies View RelatedI have an valid account,and I used pppoe-setup to set the dial correctly.After the configuration,I typed "ifup ppp0",nothing wrong happens(no news is good news?).Then I typed "pppoe-status",it said I've connected to the internet . I opened firefox,updated my system through yum ,they all said I haven't connected to the network!!!I've formated my harddisk and reinstall my system,but the problem is still.
View 4 Replies View RelatedI have installed fedora 11 64 bit on a new computer. I have no problems accessing the computers on my local network, but can not get past the gateway. The gateway is running windows XP with IP address 192.168.0.1 and is named "internet". When I boot the new computer in windows, there is no problem. Here is the output of some commands I saw in other posts with similar problems:
$ /sbin/ifconfig eth0
eth0 Link encap:Ethernet HWaddr 00:24:8C:7F:10:0C
inet addr:192.168.0.245 Bcast:192.168.0.255 Mask:255.255.255.0
inet6 addr: fe80::224:8cff:fe7f:100c/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
[Code]....
Firewall disabled.Static IP addys given to each laptop, but makes no diff when dhcp derived IP addys.using wlan Cannot ping either laptop from a windows box, bit windows box pings other computers.Can access internet from either laptop and Samba works too.I can ping one laptop if I plug the LAN wire into it. In fact I can ping either the wlan IP addy or the LAN addy this way. WHen I remove the Lan wire I can still ping the wlan on the laptop, but restarting screws it all up again.I see that iptables and other files change when I plug the LAN cvable in and then remove it again.
View 1 Replies View RelatedI installed Fedora 13 on my laptop today after deleting a badly screwed up Windows XP partition. Everything installed smoothly even my Broadcom drivers but I can't seem to figure out how to get Firefox to access the web with a URL.
I can ping Google, and can get to it in Firefox if I use the IP address from the ping, but going to [url] in Firefox will give me an error message about not being able to find the server at the web address. I was also able to update from the terminal with yum update just fine. I've tried searching Google for some answers, and maybe I just can't phrase my query right, but I found nothing that I could use to try and fix my problem.
I've attached a HardInfo report which I hope could be useful if you need to know what my hardware is (an HP Pavilion zv5000 laptop).
I've installed Fedora 13 on a Toshiba Satellite A40 laptop, and am trying to get the wired ethernet connection to work. Network Manager says it is connected, and the connection details (DHCP assigned IP, gateway, dns servers) all seem correct. However, I cannot browse the internet. Checking for updates fails also. I have tried pinging various sites and the results are inconsistent - sometimes it works, sometimes it times out with "unknown host". [URL]... I've searched around for similar issues and tried disbaling ipv6 both in Fedora and Firefox, but this doesn't help either.
View 10 Replies View Relatedhttp://kernel.org/pub/linux/kernel/p...d-AR8152.patch
I have zero internet access on my laptop via wired or wireless connection, and need to apply this patch, but have pretty much no idea where to start.Running vanilla FC13 x86_64. Whats the easiest way to go about this, considering its hard work for me to download packages and their dependencies at college (where I am posting from now) and installing them at home, it could take days.
I just installed fedora on a customers laptop of mine and just trying to get everything working. I hooked up a wireless PCMCIA linksys card and got connected to my wireless and went through the first 250+ updates, all that went fine, so I know I am getting internet access. Everytime I open firefox though I cannot connect to any websites, like I said I am a noob so my troubleshooting skills are very limited with linux, anything I can try etc.
View 4 Replies View RelatedAfter upgrading to F14 from F10, we seem to have access to the internet from our console, and no one is able to connect to server as well. We have static IP from comcast. And all the configurations on the eth0 looks fine. We are able to browse, if we set the server to dynamic ip. Also, we are able to connect another PC (laptop) with the static ip configuration, and browse fine. Read through many messages on this forum, cant get any clues,
View 3 Replies View RelatedI have a work network of about 20 boxes most of which are running Windows 7 and one of them is a file server using linux and another is Windows server 2003. Now the local IP is distributed by the router, and no regulation of internet access is done by any of the servers.What I need to do is restrict internet access to select domains, which would probably need DHCP through linux(I think, not really sure), and I need something simple like a 'blabla.conf' file with the allowed websites that I can edit. need to know how to regulate IP addresses through the linux box (all details if possible, I never tried to do that before), and how to restrict internet access also through linux.
View 4 Replies View Related when I try to connect to internet SELinux give my a preventing NetworkManager here is what its say:
Code:
Summary:
SELinux is preventing NetworkManager (NetworkManager_t) "getattr" to /dev/ppp
(ppp_device_t).
[Code]....
I see from the netspeed applet that my computer is downloading stuff almost constantly. Not a whole lot, 8b - 700b per second while apparently doing nothing. Some of this is just responding to broadcasts from the router, but surely not all. I would like to be able to determine which programs are accessing the internet over that wireless card, with a view to cutting down on my bandwidth usage. Is there a program that can tell me which ones are doing what at a given time?
View 5 Replies View RelatedOn one machine is upgraded from F7 to F10: no problems. On my second machine, I did a fresh install. I can connect to the internet via KPPP, but both Firefox & Konqueror fail to recognize that I'm online. I tried to create a network modem connection, but when I select "new" & "modem", then press the "forward" button, nothing happens.
View 5 Replies View RelatedI am building a CarPC which I'd like to have wireless internet access on. I have Verizon phone service so if there is a Verizon air card (not wireless card, an air card so I can have constant access without having to search for hot spots) that would work with Fedora 10 I would be very happy. I don't really know where to start and I can't find too much on Google, so I'm just looking for what options are available.
View 3 Replies View RelatedFedora 11 is completely unable to access the internet for some reason, and after some troubleshooting, I've determined the problem to my Motorola 2210 DSL modem. I know my connection is working fine, as it works perfectly in both Vista and 7. I've tried things such as grep 'Ethernet' /var/log/dmesg, filling in the information into the network settings manually, to no avail.
View 12 Replies View RelatedI just tried installing Google Earth on my fresh 64 bit Fedora 11 install using autoten, which I used earlier to install java and some codecs. I also used leighs guide to install 64 bit flash and remove nspluginwrapper. All was working fine. Then I decided to use autoten to install googleearth. It failed early giving an error saying:
First error was:
resolving dnmouse.org... failed: Name or service not known.
wget: unable to resolve host address `dnmouse.org'
Error getting repository data for googleearth, repository not found
# checking installation..
Size of report file is 0 lines
Error window opened up saying:
Google earth, was not installed correctly, please check you have an active connection. From this point on, Firefox cannot access the internet. I can ping google.com and dnmouse.com successfully. I did the update that included the new firefox 3.5, so accessing the internet and my connection is active. Konversation is working correctly. Just firefox is having the problem. Message: Firefox can't find the server at start.fedoraproject.org, or google, or redhat etc.
I renamed the .mozilla folder, and restarted firefox, no luck. My /etc/resolve.conf contains the correct nameservers. Also tried a reboot, no luck, still have active eth0 connection but no FF internet access.
I'm trying to set a kickstart DVD for automatically installing Fedora 10 without touching the existing data partitions on our systems. I've got a kickstart file that works great from a kickstart server however I'm having issues with creating an unattended kickstart DVD. I've attached a copy of the kickstart file from the DVD. For some reason even though all the packages we are installing are on the DVD, anaconda always attempts to connected to the internet to get repository information after completing the partitioning. I have changed the install type to 'cdrom' before anyone asks! I have removed my %pre and %post sections as these just copy in some config files and do not touch anything other than local paths.
View 3 Replies View RelatedBridged successfully but cannot access the Internet.I installed VMware in my Fc13,and installed XP sp3 in the VMware.I can access the Internet in XP,I set the network as Bridged with Fc13,but Fc cannot open a page,but I ping google.com,it can display: Code: Pinging google.com [64.233.183.104] with 32 bytes of data:
then nothing.I still cannot access the Internet in my Fc13.