Re: ct Re: NMAP probing of network ports

2005-09-16 Thread Bob Hall
On Fri, Sep 16, 2005 at 07:36:36AM -0500, Boris Karloff wrote: > It appears that when FreeBSD is sent an invalid packet > without the SYN or ACK bits set, it responds with a RESET > reply regardless of the ipfw rules. It appears this is one > of the things nmap is exploiting. > > Any suggestions o

Re: ct Re: NMAP probing of network ports

2005-09-16 Thread Boris Karloff
Thank you for your reply. As you can see from my first message, blackhole did not work. Harold On Fri, Sep 16, 2005 at 07:36:36AM -0500, Boris Karloff wrote: > It appears that when FreeBSD is sent an invalid packet > without the SYN or ACK bits set, it responds with a RESET > reply regardless of

Re: ct Re: NMAP probing of network ports

2005-09-16 Thread Boris Karloff
Thank you for your reply. Nmap is generating many tcp commands: arp who-has 192.168.0.x tell 192.168.0.5 where x is an incremented number from 0 through 255. The 192.168.0.5 address changes from scan to scan, so blocking the port 192.168.0.5 doesn't work. This behavior is similar to the W32.W

Re: ct Re: NMAP probing of network ports

2005-09-16 Thread Chris
On Fri, 16 Sep 2005, Boris Karloff wrote: Ain't you 'sposed to be dead?! Best regards, Chris Fact is solidified opinion. ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send an

Re: ct Re: NMAP probing of network ports

2005-09-16 Thread Chuck Swiger
Boris Karloff wrote: Thank you for your reply. Nmap is generating many tcp commands: arp who-has 192.168.0.x tell 192.168.0.5 where x is an incremented number from 0 through 255. The 192.168.0.5 address changes from scan to scan, so blocking the port 192.168.0.5 doesn't work. That's not a

Re: ct Re: NMAP probing of network ports

2005-09-16 Thread Alex Zbyslaw
Chris wrote: On Fri, 16 Sep 2005, Boris Karloff wrote: Ain't you 'sposed to be dead?! That's Bela Lugosi... --Alex ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any

Re: ct Re: NMAP probing of network ports

2005-09-18 Thread Boris Karloff
>Chris wrote: >> On Fri, 16 Sep 2005, Boris Karloff wrote: >> >> Ain't you 'sposed to be dead?! >That's Bela Lugosi... >--Alex Actually, so is Boris --- My e-mail provider is upgrading the mail server, and apparently someone either mistyped my name when moving my account, or one of the employ

Re: ct Re: NMAP probing of network ports

2005-09-19 Thread Alex Zbyslaw
Boris Karloff wrote: Chris wrote: On Fri, 16 Sep 2005, Boris Karloff wrote: Ain't you 'sposed to be dead?! That's Bela Lugosi... Actually, so is Boris --- Bela Lugosi famously died in the middle of filming Plan 9 from Outer Space (http://www.badmovies.org/movies/plannine