store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed May 22, 2013 10:24 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 14 posts ] 
Author Message
 Post subject: Whitelist Just Me
Unread postPosted: Thu May 12, 2011 4:20 pm 
Offline
Forum Regular
Forum Regular

Joined: Wed Aug 04, 2010 2:52 pm
Posts: 256
I get locked out of my own server all the time. I send FP reports most of the time, which sometimes result in rule changes and other times result in "If this is normal behavior for your software, disable this rule."

Well, I'm using WordPress, Drupal, and PHPMyAdmin. These generate 100% of the lock-outs I've experienced.

A great way for ASL to work would be for me to visit a certain URL or push a button in the admin, and have ASL automatically whitelist my current IP address. Or use a token system so if my dynamic IP changes I'm still good to go.

What do you guys think?


Top
 Profile  
 
 Post subject: Re: Whitelist Just Me
Unread postPosted: Thu May 12, 2011 8:05 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Neat idea, we'll do some research to determine the feasibility as well as the security implications of such an approach.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Whitelist Just Me
Unread postPosted: Thu May 12, 2011 8:11 pm 
Offline
Forum Regular
Forum Regular

Joined: Wed Aug 04, 2010 2:52 pm
Posts: 256
Does anyone else have this issue or am I doing it wrong? :)
What I want to do is try to "fix the system" rather than end up frustrated and chuck the system. I love ASL, but it's frustrating to be locked out of my server with no real way of getting back in except waiting 30 minutes.


Top
 Profile  
 
 Post subject: Re: Whitelist Just Me
Unread postPosted: Thu May 12, 2011 9:28 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7425
Location: earth
Maybe something with portknocking?


Top
 Profile  
 
 Post subject: Re: Whitelist Just Me
Unread postPosted: Fri May 13, 2011 8:59 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Feature request 581 added. You can track it in the support portal under the Bugs tab.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Whitelist Just Me
Unread postPosted: Fri May 13, 2011 7:20 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1846
Wouldn't getting a static IP address be a better idea?

I'm assuming you have to use a mobile connection or some other type where getting a static IP is difficult.

You could rent a VPS (static IP), lock it down except for ssh (or OpenVPN if you prefer), then tunnel from there to your own servers, for example.

Faris.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Whitelist Just Me
Unread postPosted: Tue Aug 09, 2011 9:27 pm 
Offline
Forum Regular
Forum Regular

Joined: Wed Aug 04, 2010 2:52 pm
Posts: 256
faris,

Yes, getting a static IP address for my home PC, my laptop when I'm at a coffee shop, my office PC, and my wife's laptop just in case, and for my developers offsite wherever they are seems like a silly way to fix the problem.

I do typically just tunnel in from another server any time I need to access the server shunning me. This is too much to ask of other devs though :)


Top
 Profile  
 
 Post subject: Re: Whitelist Just Me
Unread postPosted: Wed Aug 10, 2011 7:09 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Good idea. Add this to the ASL 3.1 voting thread:

viewtopic.php?f=3&t=5245

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Whitelist Just Me
Unread postPosted: Wed Aug 10, 2011 9:00 pm 
Offline
Forum Regular
Forum Regular

Joined: Wed Aug 04, 2010 2:52 pm
Posts: 256
Does it equal #4?


Top
 Profile  
 
 Post subject: Re: Whitelist Just Me
Unread postPosted: Thu Aug 11, 2011 10:41 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Do you mean this candidate #4:

Atomicorp Candidate #4: Redirect blocked users to a web page that explains why they were blocked and provides options based on the policy set by the system owner (examp,e, give them a captcha and allow for spam, admin password and allow XSS rules, report as false positive, etc.) Also for cases where the system owner does not want them to disable the rule, or allow the event, give them information to reach out the system owner to resolve the issue. (the domain and/or system owner would be able to disable/enable this depending on the type of rule triggered)

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Whitelist Just Me
Unread postPosted: Thu Aug 11, 2011 6:37 pm 
Offline
Forum Regular
Forum Regular

Joined: Wed Aug 04, 2010 2:52 pm
Posts: 256
Yes - does that cover it in a more global way than just my little suggestion?


Top
 Profile  
 
 Post subject: Re: Whitelist Just Me
Unread postPosted: Thu Aug 11, 2011 9:17 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
I think so, but there is merit to the idea of a "temporary" or personal whitelist too I think. I think the key is to make sure you can either set a timeline for it or maybe someway to easily "disable it"... not sure of the most reliable way to do that. I prefer #4 because I think its more likely to add to a tailored policy for the system, but I'm wide open to ideas about usability.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Whitelist Just Me
Unread postPosted: Thu Aug 11, 2011 9:52 pm 
Offline
Forum Regular
Forum Regular

Joined: Wed Aug 04, 2010 2:52 pm
Posts: 256
I think if #4 were live, I'd be happy :)


Top
 Profile  
 
 Post subject: Re: Whitelist Just Me
Unread postPosted: Fri Aug 12, 2011 11:58 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
So a vote for #4! :-)

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 14 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group