• Home
  • About
  • Archives
  • DeoSHAPE
  • Sitemap
Subscribe: Posts | Comments | E-mail
  • CampusCan't Play Without ...
  • LinuxCan't Work Without ...
  • MusicCan't Code Without ...
  • PlaygroundFun stuff...
  • WorkCan't Life Without ...

Bosen’s Playground

Posts Tagged ‘SELinux’


Posted on September 7, 2008 - by Bosen

Making SELinux allow a nonstandard port

Kadang paling ampuh untuk menghindari portscan + bruteforce attack adalah dengan mengganti port standard ke port tidak standard. Tetapi, untuk sistem yang menggunakan SELinux (Fedora, RedHat, CentOS, etc) port tersebut harus di daftarin dulu, agar bisa di pakai.

Misal kita mau ganti SSHD maka prosesnya adalah:

# /usr/sbin/semanage port -l | grep ssh
ssh_port_t                     tcp      22
# /usr/sbin/semanage port -a -t ssh_port_t -p tcp 19882
# /usr/sbin/semanage port -l | grep ssh
ssh_port_t                     tcp      19882, 22

Hehehe gampang yak ?


Ad

  • Ad Ad Ad Ad
  • Recent Comments

    • seegeed on The Dawn of the Net
    • avicena on YouTube to MP3
    • Bosen on Case Study - Data Communications & Network
    • antang on Case Study - Data Communications & Network
    • Bosen on senada.or.id - mod_si_events
  • Tag Cloud

    • BlackBerry Case Study Cheat Sheets Converter Cronos e-books Fedora Firmware Flv2Mp3 Hardening Java Jokes Joombos Joomla komdat Linux MP3 Music network SELinux textbook Tips Tools
  • Live Feed

© 2005 Bosen’s Playground - PUSH Brain