[SOLVED] hosts.deny is blocking ssh

[SOLVED] hosts.deny is blocking ssh

Postby linuxdad » Jan 12th, '14, 15:33

Can someone please tell me what (is it msec) is resetting the /etc/hosts.deny file?

I removed the Deny entry:

#ALL:ALL EXCEPT 127.0.0.1:DENY

and found it had reappeared:

ALL:ALL EXCEPT 127.0.0.1:DENY

I am thinking that it's msec, but I don't want the hosts.deny file changed, as it removes my ability for remote access. GAH!
Last edited by linuxdad on Jan 14th, '14, 00:05, edited 1 time in total.
Albert E. Whale, CEH CHS CISA CISSP
President - Chief Security Officer
IT Security, Inc. - http://www.IT-Security-inc.com
Pittsburgh, PA
Email: Albert.Whale@IT-Security-inc.com
linuxdad
 
Posts: 123
Joined: Nov 17th, '13, 21:14

Re: hosts.deny is blocking ssh

Postby doktor5000 » Jan 12th, '14, 17:06

What security level did you set, either during install or later on via http://doc.mageia.org/mcc/3/en/content/msecgui.html
If you don't like msec, the regular scans and changes it does, simply remove it.

But you should probably take a look at the principle how this is thought to work. Deny everything except local connections,
and then allow specific connections via hosts.allow. Also maybe have a a look at https://wiki.mageia.org/en/Msec

AUTHORIZE_SERVICES Configure access to tcp_wrappers services (see hosts.deny(5)). If arg = yes, all services are authorized. If arg = local, only local ones are, and if arg = no, no services are authorized. In this case, To authorize the services you need, use /etc/hosts.allow (see hosts.allow(5)).
Cauldron is not for the faint of heart!
Caution: Hot, bubbling magic inside. May explode or cook your kittens!
----
Disclaimer: Beware of allergic reactions in answer to unconstructive complaint-type posts
User avatar
doktor5000
 
Posts: 18048
Joined: Jun 4th, '11, 10:10
Location: Leipzig, Germany

Re: hosts.deny is blocking ssh

Postby linuxdad » Jan 13th, '14, 03:33

What package needs to be removed to eliminate msec?

I have found the Security Level settings in MCC, and have given remote access. For now I can live with this. Let's see how this pans out.
Albert E. Whale, CEH CHS CISA CISSP
President - Chief Security Officer
IT Security, Inc. - http://www.IT-Security-inc.com
Pittsburgh, PA
Email: Albert.Whale@IT-Security-inc.com
linuxdad
 
Posts: 123
Joined: Nov 17th, '13, 21:14

Re: hosts.deny is blocking ssh

Postby doktor5000 » Jan 13th, '14, 23:02

linuxdad wrote:What package needs to be removed to eliminate msec?

Well, msec :D (and to be fair, msecgui too)
Code: Select all
urpme -a msec
Cauldron is not for the faint of heart!
Caution: Hot, bubbling magic inside. May explode or cook your kittens!
----
Disclaimer: Beware of allergic reactions in answer to unconstructive complaint-type posts
User avatar
doktor5000
 
Posts: 18048
Joined: Jun 4th, '11, 10:10
Location: Leipzig, Germany


Return to Networking

Who is online

Users browsing this forum: No registered users and 1 guest

cron