At 11:11 AM 4/4/00 +1000, you wrote:
>What's the difference between a dropped packet and an unreachable address?

Specific to this situation where it might be considered desirable to look 
like a standard windows 98 box, REJECTing a connection will make it appear 
that there's nothing listening on a port.  DENYing will just blackhole the 
packet.


>recipient, just that you haven't received a response.  A reject tells you
>immediately that there's no point in continuing on that port, so you don't
>need to waste any more time on it.  The more energy an attacker wastes

.....my point exactly.



>beating against your firewall, the more of their time they waste, and the
>more evidence you have to present to their ISP.  Sometimes the ISP will
>enforce their AUP ...

hah!  regardless of your intent in this thread, mine is to indicate ways 
that you might defeat O@H's scanning software.  You are going to protest to 
Optus that they are the ones attacking you?  Nah...


> > rejects from everything but 21 and 80 I'm going to start thinking 
> something
> > is up.
>
>I don't care what you think, I just don't want you getting access to any
>of my machines.  If your packets don't get to the target machine, there's
>no way you're going to be able to break in.

I don't care what an attacker thinks ordinarily.  In this case I want to 
hide amongst the unwashed masses, not stand up and say "lookey here, I've 
got a firewall!".  That point is easily argued against, but nevertheless 
it's something that *may* be considered in the minds of those (at optus) 
doing the scanning.


> > In this situation we're not just trying to block access to servers,
> > we're trying to hide even their existence.
>
>No we're not.  I'm not suggesting that people hide servers.  I'm

I think that this is where we differ on our opinions of what people may 
hope to gain from this discussion.  You're suggesting hiding, I'm 
suggesting hiding within a crowd.


> > The more you make it look like a windows box, the better.
>
>Complete with security holes?  I know, lets make it crash randomly,
>that'll fool them :-)

heh.


> > default DENY policy, but they may take that to mean that you're trying to
> > stop them scanning :)
>
>Almost.  You're not trying to stop their scans, you're trying to stop
>*everyone's* scans and other attacks.  It's called security.

Well thanks for the enlightenment :P


Alexander Else
http://cyberchrist.org

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to