Sorry, I'm late in on this thread but....

----- Original Message -----
From: "John Clarke" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, 4 April 2000 11:11 AM
Subject: Re: [SLUG] Firewalling and Optus@Home


> On Tue, Apr 04, 2000 at 05:52:02AM +1000, Alexander Else wrote:
>
> > At 03:12 PM 4/3/00 +1000, John Clarke wrote:
> > >1.  Default policy is to deny all packets.  Then rules are added to
allow
> > >     certain packets through the firewall.  Note that we use DENY
rather
> > >     than REJECT so that the originator doesn't know that their packets
are
> > >     being discarded until they time out.
> >
> > I'll dispute this advice.  If i were going to write a serious scanner
I'd
> > take a dropped packet on a known port as sign of firewalling.  If i get
>

If I was OPTUS (or anybody) and I wanted to figure if you are running a
"server" (just cause windows doesn't have any inbuilt messaging or httpd
doesn't make everything else that does a server), one way is to scan 3128
and 3120 to look for squid.  If the packet was dropped, then that would mean
you have firewalling in place *AND* most probably have squid listening on
your internal network.

connection refused neither confirms or denies the hypothesis.  Therefore I
would agree with Alexander.

Ian.

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to