Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ Dnxfirewall - A Pure Python Next Generation Firewall Built On Top Of Linux Kernel/Netfilter

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Dnxfirewall - A Pure Python Next Generation Firewall Built On Top Of Linux Kernel/Netfilter


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: feedproxy.google.com


DNX Firewall is an optimized/high performance collection of applications or services to convert a standard linux system into a zone based next generation firewall. All software is designed to run in conjunction with eachother, but with a modular design certain aspects can be completely removed with little effort. The primary security modules have DIRECT/INLINE control over all connections, streams, messages, that goes through the system. That being said, depending on the protocol, offloading to lower level control is present to maintain the highest possible throughput with full inspection enabled. There is an IPTable custom chain to allow for the administrator to hook into the packet flow without the ability to accidentally override dnx security modules. A low level "architecture, system design" video will be created at some point to show how this is possible with pure python.


Included Features
  • DNS Proxy
    • category based blocking (general, TLD, substring matching)
    • user added whitelist/blacklist or custom general category creation
    • native DNS over TLS conversion with optional UDP fallback
    • local dns server
    • software failover
    • 2 level record caching
  • IP Proxy (transparent) Bi directional
    • reprutation based host filtering
    • geolocation filter
    • lan restriction (disables internet access to the LAN for all IPs not whitelisted)
  • IPS/IDS (WAN/inbound)
    • Denial of service detection/prevention
    • Portscan detection/prevention
  • Lightweight DHCP Server (custom)
    • ip reservations
    • security alert integration
  • General Services
    • Log handling
    • Database management
    • Syslog client (UDP, TCP, TLS) IMPORTANT: currently in a beta/unstable state. this service will not be enabled by default and will require the service enabled to start on system start.
  • Additional Features
    • IPv6 disabled
    • prebuilt iptable rules
    • DNS over HTTPs blocks (dns bypass prevention)
    • DNS over TCP blocks (dns bypass prevention)
    • DNS over TLS blocks (dns bypass prevention)
    • all inbound connections to wan DROPPED by default
    • IPTABLES custom chain for admin hook into packet flow

Before Running

NEW: sqlite3 is now the default database in use (to simplify deployments). The environment variable "SQL_VERSION" located in dnx_configure/dnx_constants.py can be flipped to use postgresql. WARNING: switching the database used after initial configuration may cause problems.

  • [+] Edit data/config.json and data/dhcp_server.json to reflect your system [interfaces].
  • [+] Move all systemd service files into the systems systemd folder.
  • [+] Configure system interfaces. LAN needs to be Default Gateway of local network.
  • [+] Compile python-netfilterqueue for your current architecture/distro (link below).
      - ensure name is netfilter.so and placed in the dnxfirewall/netfilter folder
    • NOTE: in the future this step will be wrapped into the deployment script
  • [+] Compile dnx_iptools/binary_search.pyx for your current architecture/distro.
      - ensure name is binary_search.so and placed in the dnxfirewall/dnx_iptools folder
    • NOTE: in the future this step will be wrapped into the deployment script
  • [+] Run/ follow, in order, the corresponding deployment scripts [for the selected database] to automate system setup. look at comments in script files for more direction.

Non DNX code dependencies/sources!

https://github.com/kti/python-netfilterqueue | cython <-> python extension for binding to linux kernel [netfilter] | THIS IS AWESOME!

https://www.ip2location.com/free/visitor-blocker | geolocation ip filtering datasets

https://gitlab.com/ZeroDot1/CoinBlockerLists | cryptominer host set

https://squidblacklist.org | malicious and advertisement host sets

OPTIONAL: https://github.com/tlocke/pg8000 | pure python postgresql adapter


General Showcase Demo (outdated)

This video is extremely outdated, but still shows general functionality and some of the high level security implementations. an updated video will be created soon which will show the newly added modules: syslog client, standard logging, ips/ids, updated dns proxy functionality, updated ip proxy functionality, more.




...



๐Ÿ“Œ Dnxfirewall - A Pure Python Next Generation Firewall Built On Top Of Linux Kernel/Netfilter


๐Ÿ“ˆ 122.89 Punkte

๐Ÿ“Œ Linux Kernel up to 5.11.10 Netfilter Subsystem net/netfilter/x_tables.c denial of service


๐Ÿ“ˆ 44.16 Punkte

๐Ÿ“Œ CVE-2023-39192 | Linux Kernel Netfilter Xtables net/netfilter/xt_u32.c u32_mt_checkentry out-of-bounds (ZDI-23-1490)


๐Ÿ“ˆ 44.16 Punkte

๐Ÿ“Œ CVE-2023-39193 | Linux Kernel Netfilter Xtables net/netfilter/xt_sctp.c sctp_mt_check out-of-bounds (ZDI-23-1491)


๐Ÿ“ˆ 44.16 Punkte

๐Ÿ“Œ be quiet! FX mit Light Wings: Pure Base, Pure Loop und Pure Rock leuchten jetzt


๐Ÿ“ˆ 41.97 Punkte

๐Ÿ“Œ be quiet! FX mit Light Wings: Pure Base, Pure Loop und Pure Rock leuchten jetzt


๐Ÿ“ˆ 41.97 Punkte

๐Ÿ“Œ 25 Iptables Netfilter Firewall Examples For Linux


๐Ÿ“ˆ 30.15 Punkte

๐Ÿ“Œ [WIP] The Pure Bash Bible - Documenting pure bash ways to do various tasks.


๐Ÿ“ˆ 27.98 Punkte

๐Ÿ“Œ pure as in pure bash text editor


๐Ÿ“ˆ 27.98 Punkte

๐Ÿ“Œ Tineco PURE ONE S12 Pro EX und PURE ONE S12 im Test


๐Ÿ“ˆ 27.98 Punkte

๐Ÿ“Œ Linux Kernel 4.6.3 Netfilter Privilege Escalation


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Linux Kernel bis 4.5.2 Netfilter Subsystem erweiterte Rechte


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ [local] - Linux Kernel 4.6.3 - Netfilter Privilege Escalation (Metasploit)


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Linux Kernel 4.6.3 Netfilter Privilege Escalation


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Linux Kernel 4.6.3 Netfilter Privilege Escalation


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ [local] - Linux Kernel 4.6.3 - Netfilter Privilege Escalation (Metasploit)


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Linux Kernel 4.6.3 Netfilter Privilege Escalation


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Linux Kernel bis 4.5.2 Netfilter Subsystem erweiterte Rechte


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Linux Kernel up to 2.6.11.8 NetFilter ipt_recent.c denial of service


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Linux Kernel up to 4.15.7 Netfilter Subsystem arp_tables.c denial of service


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Linux Kernel up to 2.6.9 netfilter/iptables memory corruption


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Linux Kernel 2.6.16.12 Netfilter SCTP Chunk memory leak


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Linux Kernel 2.6.16.12 Netfilter SCTP Packet without Chunk infinite loop


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Linux Kernel bis 4.8 Netfilter Subsystem nf_conntrack_reasm.c IPv6 Fragments Pufferรผberlauf


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Vuln: Linux Kernel '/netfilter/xt_osf.c' Local Security Bypass Vulnerability


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Vuln: Linux Kernel 'net/netfilter/nfnetlink_cthelper.c' Local Security Bypass Vulnerability


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Vuln: Linux Kernel 'net/netfilter/xt_TCPMSS.c' Denial of Service Vulnerability


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ #0daytoday #Linux Kernel 4.4.0-21 (Ubuntu 16.04 x64) - netfilter target_offset Local Privilege Esca [#0day #Exploit]


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ [local] Linux Kernel < 4.4.0-21 (Ubuntu 16.04 x64) - 'netfilter target_offset' Local Privilege Escalation


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ [local] Linux Kernel < 4.4.0-21 (Ubuntu 16.04 x64) - 'netfilter target_offset' Local Privilege Escalation


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Linux Kernel < 4.4.0-21 (Ubuntu 16.04 x64) netfilter target_offset Local Privilege Escalation


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Linux Kernel 3.1.8 Netfilter nf_tables_api.c nft_flush_table denial of service


๐Ÿ“ˆ 25.5 Punkte

๐Ÿ“Œ Linux Kernel bis 4.5.2 Netfilter Subsystem erweiterte Rechte


๐Ÿ“ˆ 25.5 Punkte











matomo