0

I have received an abuse from my server provider and one thing which is the same is that the target on destination IPs is the SMB (445) port . How can I block destination traffic to port 445 using iptables?

> ---------------------------------------------------------------------------
> Wed Sep  2 08:02:21 2020 TCP   MYSERVERIP 61019 =>   70.40.185.188 445 
> Wed Sep  2 08:02:36 2020 TCP   MYSERVERIP 62211 =>   70.40.185.193 445 
> Wed Sep  2 08:02:27 2020 TCP   MYSERVERIP 61649 =>   70.40.187.138 445 
> Wed Sep  2 08:02:47 2020 TCP   MYSERVERIP 63772 =>   91.218.57.126 445 
> Wed Sep  2 08:02:28 2020 TCP   MYSERVERIP 61821 =>     91.218.58.1 445 
> Wed Sep  2 08:02:20 2020 TCP   MYSERVERIP 60987 =>   91.218.120.55 445 
> Wed Sep  2 08:02:39 2020 TCP   MYSERVERIP 62910 =>  91.218.120.228 445 
> Wed Sep  2 08:02:37 2020 TCP   MYSERVERIP 62671 =>   91.227.14.171 445 
> Wed Sep  2 08:02:37 2020 TCP   MYSERVERIP 62721 =>   91.227.14.189 445 
> Wed Sep  2 08:02:44 2020 TCP   MYSERVERIP 63442 =>   91.227.22.209 445 
> Wed Sep  2 08:02:38 2020 TCP   MYSERVERIP 62786 =>   91.227.60.118 445 
> Wed Sep  2 08:02:40 2020 TCP   MYSERVERIP 62786 =>   91.227.60.118 445 
> Wed Sep  2 08:02:35 2020 TCP   MYSERVERIP 62476 =>   91.227.115.17 445 
> Wed Sep  2 08:02:38 2020 TCP   MYSERVERIP 62476 =>   91.227.115.17 445 
> Wed Sep  2 08:02:49 2020 TCP   MYSERVERIP 63678 =>    110.165.2.15 445 
> Wed Sep  2 08:02:48 2020 TCP   MYSERVERIP 63852 =>   110.165.3.103 445 
> Wed Sep  2 08:02:49 2020 TCP   MYSERVERIP 63970 =>   110.165.3.155 445 
> Wed Sep  2 08:02:31 2020 TCP   MYSERVERIP 62073 =>   110.165.4.204 445
Mr Pro
  • 33
  • 3
  • will this work ? iptables -A OUTPUT -p tcp --destination-port 445 -j DROP – Mr Pro Sep 02 '20 at 14:57
  • 2
    You should rather investigate what is doing those requests. Resolve the cause, not the symptoms. – Gerald Schneider Sep 02 '20 at 14:59
  • I will do so but I need to get my server back online first . will the mentioned command help? – Mr Pro Sep 02 '20 at 15:08
  • There is something inside your machine that either does something not good, or is harmless but you don't know it. Try (sudo or root) `netstat -apn` when the connections are active. Btw, samba sends some stuff to the smb port. – Déjà vu Sep 02 '20 at 15:13
  • it's a VPN server . Can a user be doing this with his VPN account? Or is it happening with the terminal? – Mr Pro Sep 02 '20 at 15:17

0 Answers0