IP Tables network magic SysRq 0.5
Sponsored Links
IP Tables network magic SysRq 0.5 Ranking & Summary
File size:
0.025 MB
Platform:
Any Platform
License:
GPL (GNU General Public License)
Price:
Downloads:
1095
Date added:
2006-11-13
Publisher:
Marek Zelem
IP Tables network magic SysRq 0.5 description
IP Tables network magic SysRq is a new iptables target that allows you to do the same as the magic sysrq key on a keyboard does, but over the network.
Why to use the remote sysrq?
Sometimes a remote server hangs and only responds to icmp echo request (ping). Every administrator of such machine is very unhappy because (s)he must go there and press the reset button. It takes a long time and its inconvenient. So here is a solution. Use the Network Magic SysRq and you will be able to do more than just pressing a reset button. You can remotely sync disks, remount them read-only, then do a reboot. And everything comfortably and only in a few seconds.
Is it secure?
That depends. Let me explain: You can restrict who can do this by setting the iptables firewall. But unfortunately, for simplicity, the Network Magic SysRq is based on a single packet request. This packet is encrypted and password protected, but if somebody can sniff it (s)he will be able to repeat (but not to change) the query (so-called replay attack). The query is also protected by a timestamp. When the packet is generated, it is stamped by current date and time. Then on the server side that stamp is compared with the current time of the server and if it is within the tolerance the request is accepted. Together with some other information, the timestamp is protected by SHA1 hash. This means that the potential attacker has a limited time to repeat the sniffed packet. If anybody requires a better security than this, some secure encrypted tunnel can be used. (not depending on userspace, of course!
How to install it?
Just type make.
When everything is compiled type make install as root and after that run depmod -a. Now you can load the kernel module by the command modprobe ipt_SYSRQ.
You would also like to configure the server password and the tolerance. This can be set when installing the module into a kernel, by specifying the module parameters passwd for password and tolerance for tolerance in seconds. The default values are passwd="" and tolerance=43200.
Example:
modprobe ipt_SYSRQ passwd="my_very_secret_password" tolerance=3600
Module options can also be specified in file /etc/modules.conf.
Example:
options ipt_SYSRQ passwd="my_very_secret_password" tolerance=3600
What to do on a server?
After the module is loaded you are able to deploy it using the iptables command.
Some examples of usage:
iptables -I INPUT -p udp --dport 9 -j SYSRQ
or
iptables -I INPUT -i eth1 -s 192.168.1.2 -p udp --dport 9 -j SYSRQ
Note that UDP port 9 is used. This is the default port for send_sysrq program, which shouldnt do any harm, as it defaults to discard service.
What to do on the remote machine?
Copy the executable binary send_sysrq to the remote (client) machine. Alternatively, you can compile ipt_sysrq there yourselves. After uncompressing the source package, you just need to do a make send_sysrq.
Now you can use the client program send_sysrq to send the sysrq request.
Why to use the remote sysrq?
Sometimes a remote server hangs and only responds to icmp echo request (ping). Every administrator of such machine is very unhappy because (s)he must go there and press the reset button. It takes a long time and its inconvenient. So here is a solution. Use the Network Magic SysRq and you will be able to do more than just pressing a reset button. You can remotely sync disks, remount them read-only, then do a reboot. And everything comfortably and only in a few seconds.
Is it secure?
That depends. Let me explain: You can restrict who can do this by setting the iptables firewall. But unfortunately, for simplicity, the Network Magic SysRq is based on a single packet request. This packet is encrypted and password protected, but if somebody can sniff it (s)he will be able to repeat (but not to change) the query (so-called replay attack). The query is also protected by a timestamp. When the packet is generated, it is stamped by current date and time. Then on the server side that stamp is compared with the current time of the server and if it is within the tolerance the request is accepted. Together with some other information, the timestamp is protected by SHA1 hash. This means that the potential attacker has a limited time to repeat the sniffed packet. If anybody requires a better security than this, some secure encrypted tunnel can be used. (not depending on userspace, of course!
How to install it?
Just type make.
When everything is compiled type make install as root and after that run depmod -a. Now you can load the kernel module by the command modprobe ipt_SYSRQ.
You would also like to configure the server password and the tolerance. This can be set when installing the module into a kernel, by specifying the module parameters passwd for password and tolerance for tolerance in seconds. The default values are passwd="" and tolerance=43200.
Example:
modprobe ipt_SYSRQ passwd="my_very_secret_password" tolerance=3600
Module options can also be specified in file /etc/modules.conf.
Example:
options ipt_SYSRQ passwd="my_very_secret_password" tolerance=3600
What to do on a server?
After the module is loaded you are able to deploy it using the iptables command.
Some examples of usage:
iptables -I INPUT -p udp --dport 9 -j SYSRQ
or
iptables -I INPUT -i eth1 -s 192.168.1.2 -p udp --dport 9 -j SYSRQ
Note that UDP port 9 is used. This is the default port for send_sysrq program, which shouldnt do any harm, as it defaults to discard service.
What to do on the remote machine?
Copy the executable binary send_sysrq to the remote (client) machine. Alternatively, you can compile ipt_sysrq there yourselves. After uncompressing the source package, you just need to do a make send_sysrq.
Now you can use the client program send_sysrq to send the sysrq request.
IP Tables network magic SysRq 0.5 Screenshot
Advertisements
IP Tables network magic SysRq 0.5 Keywords
SysRq
IP Tables
IP
SysRq 0.5
to do the same
Magic SysRq key
Magic sysrq
network magic
sysrq key
iptables target
magic
network
tables
Iptables
tolerance
server
Bookmark IP Tables network magic SysRq 0.5
IP Tables network magic SysRq 0.5 Copyright
WareSeeker periodically updates pricing and software information of IP Tables network magic SysRq 0.5 full version from the publisher, so some information may be slightly out-of-date. You should confirm all information before relying on it. Software piracy is theft, Using crack, password, serial numbers, registration codes, key generators is illegal and prevent future development of IP Tables network magic SysRq 0.5 Edition. Download links are directly from our publisher sites, torrent files or links from rapidshare.com, yousendit.com or megaupload.com are not allowed
Featured Software
Want to place your software product here?
Please contact us for consideration.
Contact WareSeeker.com
Related Information
linux magic sysrq key
magic sysrq keys
linux magic sysrq
Netfilter/iptables
network magic license key
network magic keygen
config magic sysrq
network magic serial
sysrq keys
aol network magic
network magic serial key
network magic pro
dish network magic card
network magic premium
network magic key
network magic coupon
linux ip tables
network magic 2.0
Related Software
Ruby Iptables NEtwork Displayer project draws an SVG from a Linux IP table generated by "iptables-save". Free Download
iptables firewall script is an Linux firewall based on the iptables software. Free Download
ipt_sysrq is a new iptables target that allows you to do the same as the magic sysrq key on a keyboard does. Free Download
IP Tables State implements the state top feature from IP Filter for IP Tables. Free Download
Gtk-IPTables is a GTK-based frontend for iptables written in C. Free Download
Set up iptables NAT rules is an example IPTables 1.2.1 script for a multi-homed firewall. Free Download
Resets iptables to default values script resets the Linux firewall iptables to default values. Free Download
Network Ustadi is a Web interface for managing network services. Free Download
Latest Software
Popular Software
Favourite Software