<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Iptables for Blogger</title>
	<atom:link href="http://nullmind.com/2005/10/10/iptables-for-blogger/feed/" rel="self" type="application/rss+xml" />
	<link>http://nullmind.com/2005/10/10/iptables-for-blogger/</link>
	<description>Just another worthless blog</description>
	<lastBuildDate>Fri, 30 Dec 2011 19:13:09 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: nullmind</title>
		<link>http://nullmind.com/2005/10/10/iptables-for-blogger/comment-page-1/#comment-616</link>
		<dc:creator>nullmind</dc:creator>
		<pubDate>Fri, 21 Oct 2005 16:01:42 +0000</pubDate>
		<guid isPermaLink="false">http://nullmind.com/?p=148#comment-616</guid>
		<description>Unfortunately, yes ...

http://help.blogger.com/default/bin/answer.py?answer=105&amp;query=firewall&amp;topic=0&amp;type=f

The proble is that their FTP publishing uses PASV (Passive) mode, but you can allways try this aproach instead if you using iptables

http://nullmind.com/2005/04/27/iptables-w-proftpd/</description>
		<content:encoded><![CDATA[<p>Unfortunately, yes &#8230;</p>
<p><a href="http://help.blogger.com/default/bin/answer.py?answer=105&#038;query=firewall&#038;topic=0&#038;type=f" rel="nofollow">http://help.blogger.com/default/bin/answer.py?answer=105&#038;query=firewall&#038;topic=0&#038;type=f</a></p>
<p>The proble is that their FTP publishing uses PASV (Passive) mode, but you can allways try this aproach instead if you using iptables</p>
<p><a href="http://nullmind.com/2005/04/27/iptables-w-proftpd/" rel="nofollow">http://nullmind.com/2005/04/27/iptables-w-proftpd/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew Suares</title>
		<link>http://nullmind.com/2005/10/10/iptables-for-blogger/comment-page-1/#comment-615</link>
		<dc:creator>Andrew Suares</dc:creator>
		<pubDate>Fri, 21 Oct 2005 15:51:20 +0000</pubDate>
		<guid isPermaLink="false">http://nullmind.com/?p=148#comment-615</guid>
		<description>I was wondering, is it necessary to open a range of ports?</description>
		<content:encoded><![CDATA[<p>I was wondering, is it necessary to open a range of ports?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nullmind</title>
		<link>http://nullmind.com/2005/10/10/iptables-for-blogger/comment-page-1/#comment-614</link>
		<dc:creator>nullmind</dc:creator>
		<pubDate>Mon, 17 Oct 2005 11:22:04 +0000</pubDate>
		<guid isPermaLink="false">http://nullmind.com/?p=148#comment-614</guid>
		<description>yes .. but you assumign 2 things

1 - there are no other security measures in place

2 - that I gave a server IP were those rules are set (no, they not set on THIS server ;) )

becides, a smart hacker knows those ports need to be open for blogger to publish, so they can just look for any blogger site and try to spoof that IP .. thats why additional security measures need to be taken, stuff like hardened php, mod_security, latest OpenSSH etc .. all part of keeping a server secured .. one can never just rely on the firewall.</description>
		<content:encoded><![CDATA[<p>yes .. but you assumign 2 things</p>
<p>1 &#8211; there are no other security measures in place</p>
<p>2 &#8211; that I gave a server IP were those rules are set (no, they not set on THIS server <img src='http://nullmind.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  )</p>
<p>becides, a smart hacker knows those ports need to be open for blogger to publish, so they can just look for any blogger site and try to spoof that IP .. thats why additional security measures need to be taken, stuff like hardened php, mod_security, latest OpenSSH etc .. all part of keeping a server secured .. one can never just rely on the firewall.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: polarizer</title>
		<link>http://nullmind.com/2005/10/10/iptables-for-blogger/comment-page-1/#comment-613</link>
		<dc:creator>polarizer</dc:creator>
		<pubDate>Mon, 17 Oct 2005 10:30:31 +0000</pubDate>
		<guid isPermaLink="false">http://nullmind.com/?p=148#comment-613</guid>
		<description>Since it is public now because of your blog, one can spoof the ip with ease :O)</description>
		<content:encoded><![CDATA[<p>Since it is public now because of your blog, one can spoof the ip with ease :O)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nullmind</title>
		<link>http://nullmind.com/2005/10/10/iptables-for-blogger/comment-page-1/#comment-612</link>
		<dc:creator>nullmind</dc:creator>
		<pubDate>Mon, 17 Oct 2005 09:45:26 +0000</pubDate>
		<guid isPermaLink="false">http://nullmind.com/?p=148#comment-612</guid>
		<description>it will alloww only those two ip&#039;s to connect to any port on that range .. so unless blogger attacks you, you shoudl be ok  :)</description>
		<content:encoded><![CDATA[<p>it will alloww only those two ip&#8217;s to connect to any port on that range .. so unless blogger attacks you, you shoudl be ok  <img src='http://nullmind.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: polarizer</title>
		<link>http://nullmind.com/2005/10/10/iptables-for-blogger/comment-page-1/#comment-611</link>
		<dc:creator>polarizer</dc:creator>
		<pubDate>Mon, 17 Oct 2005 09:35:16 +0000</pubDate>
		<guid isPermaLink="false">http://nullmind.com/?p=148#comment-611</guid>
		<description>Ahh! I misunderstood your term &quot;post&quot;. Under this new point of view i think your rules a too generous, because it is allowed to connect to every port 0-1024, not only ftp pasv (tcp,21).

Check this[1] out for detailled instructions.

[1] http://slacksite.com/other/ftp.html#passive

polarizers 2cent
http://www.codixx.de/polarizer.html</description>
		<content:encoded><![CDATA[<p>Ahh! I misunderstood your term &#8220;post&#8221;. Under this new point of view i think your rules a too generous, because it is allowed to connect to every port 0-1024, not only ftp pasv (tcp,21).</p>
<p>Check this[1] out for detailled instructions.</p>
<p>[1] <a href="http://slacksite.com/other/ftp.html#passive" rel="nofollow">http://slacksite.com/other/ftp.html#passive</a></p>
<p>polarizers 2cent<br />
<a href="http://www.codixx.de/polarizer.html" rel="nofollow">http://www.codixx.de/polarizer.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: polarizer</title>
		<link>http://nullmind.com/2005/10/10/iptables-for-blogger/comment-page-1/#comment-610</link>
		<dc:creator>polarizer</dc:creator>
		<pubDate>Mon, 17 Oct 2005 09:33:48 +0000</pubDate>
		<guid isPermaLink="false">http://nullmind.com/?p=148#comment-610</guid>
		<description>Ahh! I misunderstood your term &quot;post&quot;. Under this new point of view i think your rules a too generous, because it is allowed to connect to every port</description>
		<content:encoded><![CDATA[<p>Ahh! I misunderstood your term &#8220;post&#8221;. Under this new point of view i think your rules a too generous, because it is allowed to connect to every port</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nullmind</title>
		<link>http://nullmind.com/2005/10/10/iptables-for-blogger/comment-page-1/#comment-618</link>
		<dc:creator>nullmind</dc:creator>
		<pubDate>Tue, 11 Oct 2005 18:18:16 +0000</pubDate>
		<guid isPermaLink="false">http://nullmind.com/?p=148#comment-618</guid>
		<description>these 2 rules will allow outbound port range 1024 to 65535 to be open for the ip&#039;s

66.102.15.83
216.34.7.186

Wich are the blogger publishing ip&#039;s .. this allows their FTP to login in PASV move .. PASV mode will open ports back on the range mentioned above.</description>
		<content:encoded><![CDATA[<p>these 2 rules will allow outbound port range 1024 to 65535 to be open for the ip&#8217;s</p>
<p>66.102.15.83<br />
216.34.7.186</p>
<p>Wich are the blogger publishing ip&#8217;s .. this allows their FTP to login in PASV move .. PASV mode will open ports back on the range mentioned above.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: polarizer</title>
		<link>http://nullmind.com/2005/10/10/iptables-for-blogger/comment-page-1/#comment-617</link>
		<dc:creator>polarizer</dc:creator>
		<pubDate>Tue, 11 Oct 2005 07:43:40 +0000</pubDate>
		<guid isPermaLink="false">http://nullmind.com/?p=148#comment-617</guid>
		<description>I do not unterstand, how this should work. As i assume your standard policy is DENY for your iptables chains. But in what way this 2 rules will affect your intention?

the polarizer</description>
		<content:encoded><![CDATA[<p>I do not unterstand, how this should work. As i assume your standard policy is DENY for your iptables chains. But in what way this 2 rules will affect your intention?</p>
<p>the polarizer</p>
]]></content:encoded>
	</item>
</channel>
</rss>

