Why would an attacker fine-tune a firewall?  Do you mean that this would 
be a fine way to fine-tune an attack on a firewall?

Sure, I guess it would - all you would have to do is port scan a machine 
over and over again, until you see those ports open up, then attack the 
machine thru those ports.

But since you can attack thru existing ports anyways (web, ftp, etc..) 
then who cares if additional ports are open once in a while or not?  If 
the individual admin is OK with the addtional risk, they why would you 
guys care?



-----Original Message-----
From: "Ed White" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Date: Sun, 11 Aug 2002 13:33:58 +0200
Subject: RE: Newbie Question (one of many to come)

> > I think it would be an EXCELLENT way for a corporate administrator to
> fine-tune their firewall
> > to their particular environment.
> 
> I think it would be an EXCELLENT way for an attacker to fine-tune their
> firewall to his particular environment.
> This is "Security" Through Obscurity.
> 
> Ed
> 


Reply via email to