At 20:25 21/12/1999 +1100, chesty wrote:
>> Is it safe to block the ICMP 'time exceeded' message in order to stop
>> 'traceroute' finding you?
>
>If your host is the end of the line, like a typical home dialup, 
>blocking time exceeded messages won't do anything, the only time
>blocking time exceeded messages might make a difference is on
>routers that forward traffic. When a router forwards traffic it

If you were to do this you would want to do it on outgoing traffic rather
than incoming, else your own traceroutes would be affected.


>If you were really paranoid you would have to block the default 
>range of udp ports that traceroute uses, but traceroute can be
>told to use other ports, so you would have to block all udp ports 
>to be safe. I prefer to just log incoming udp and icmp packets.

traceroute can be done on icmp or tcp as well as udp, the ease with which
this is accomplished differs (programming wise, my clue isn't high in this
regard) but the principle is the same.


Alexander Else
Internet Operations Technician
OzEmail / UUNET Asia Pacific Operations

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to