Transparent proxy to a port which is not open and you will get perfect
results

just trans proxy ports 1-1024 to port 50000 say

all will just say connection refused


On Tue, 4 Apr 2000, Alexander Else wrote:

> At 03:12 PM 4/3/00 +1000, John Clarke wrote:
> >1.  Default policy is to deny all packets.  Then rules are added to allow
> >     certain packets through the firewall.  Note that we use DENY rather
> >     than REJECT so that the originator doesn't know that their packets are
> >     being discarded until they time out.
> 
> I'll dispute this advice.  If i were going to write a serious scanner I'd 
> take a dropped packet on a known port as sign of firewalling.  If i get 
> rejects from everything but 21 and 80 I'm going to start thinking something 
> is up.  In this situation we're not just trying to block access to servers, 
> we're trying to hide even their existence.  The more you make it look like 
> a windows box, the better.  If they run fingerprinting against the machine 
> they'll still pick it up as linux, but the more luserfied it seems, the 
> less likely they're going to suspect that something's up.  You could set a 
> default DENY policy, but they may take that to mean that you're trying to 
> stop them scanning :)
> 
> 
> >2.  Allow all packets on the loopback interface and any local ethernets.
> >3.  Allow any packet in from ppp0 with the ACK bit set.
> 
> Doesn't Optus@Home rely on you using ethernet to connect to the cable modem?
> 
> 
> 
> Alexander Else
> http://cyberchrist.org
> 
> --
> SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> To unsubscribe send email to [EMAIL PROTECTED] with
> unsubscribe in the text
> 

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to