4 ms·
I have never seen a command to retrieve all iptables tables or all iptables rules over all tables. What you usually find in documentation is the following:
by kirab 9y ago
I have never seen a command to retrieve all iptables tables or all iptables rules over all tables. What you usually find in documentation is the following:
iptables contains five tables:
raw is used only for configuring packets so that they are exempt from connection tracking.
filter is the default table, and is where all the actions typically associated with a firewall take place.
nat is used for network address translation (e.g. port forwarding).
mangle is used for specialized packet alterations.
security is used for Mandatory Access Control networking rules (e.g. SELinux -- see this article for more details).
My opinion: this is simple but pretty smart at the same time, therefore the perfect hacker tool. I can't even imagine a single sysadmin who searched for additional iptables tables before this leak.
To the dismissive people here: as a hacker you don't want complex attacking tools, they can be found much easier, because all the tools look for complex attacks (e.g. modified system files).
Hiding this well in plain sight in a place where no one and no tool ever looks is genius.
- sillysaurus3 9y agoReformatted for mobile users: iptables contains five tables: raw is used only for configuring packets so that they are exempt from connection tracking. filter is the default table, and is where all the actions typically associated with a firewall take place. nat is used for network address translation (e.g. port forwarding). mangle is used for specialized packet alterations. security is used for Mandatory Access Control networking rules (e.g. SELinux -- see this article for more details).
- okasaki 9y agoip(6)tables-save
- deleted 9y ago[deleted]
- kirab 9y agoI looked into the source code, it uses /proc/net/ip_tables_names to find the tables And that tbh doesn't seem very reliable, see what happened on a laptop which does not use iptables: $ cat /proc/net/ip_tables_names cat: /proc/net/ip_tables_names: No such file or directory $ iptables -L [...] $ cat /proc/net/ip_tables_names filter $ iptables -t nat -L [...] $ cat /proc/net/ip_tables_names nat filter This seems to only show loaded/active iptables tables. Which means that a table may exist but unless it is loaded you will not see it. But of course in our scenario the CIA would have activated some rules, so this table should appear there. Unless the CIA was also able to hide the table from that file, which may well be possible, since the table was added via a root kernel module...
- ams6110 9y agoI routinely create additional tables to help organize my filtering. Didn't think it was very unusual.
- kirab 9y agoAre you sure you are creating additional tables and not chains? See for example: https://askubuntu.com/a/316993 https://askubuntu.com/a/316993 The post further down there says that additional tables can only be created via the kernel, so if you're really creating additional tables could you please share your commands for doing so?
- canada_dry 9y agoELI5: how to check if there's another iptable (aside from the std ones)?